reflect is an AI agent skill, created by ClawHub Skill. ClawSecure audited reflect across 21 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 70/100 (Medium Risk). The 5 findings concentrate in Malicious Code, Code Injection and Skill Discovery Abuse, including Attempts to access sensitive file: MEMORY.md and Potentially dangerous code pattern detected: eval\(. 2 were rated high or critical severity.
Is reflect safe?
ClawSecure audited reflect and assigned a security score of 70/100 (Medium Risk), identifying 5 findings across Malicious Code and Code Injection. Review the findings below before installing.
What did ClawSecure find in reflect?
ClawSecure identified 5 findings in reflect, concentrated in Malicious Code, Code Injection and Skill Discovery Abuse. 2 were rated high or critical severity. The most severe include Attempts to access sensitive file: MEMORY.md and Potentially dangerous code pattern detected: eval\(.
How was reflect audited?
ClawSecure ran reflect through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 21 files.
What does a score of 70 mean?
ClawSecure assigned reflect a security score of 70/100, placing it in the Medium Risk range. This reflects 5 findings led by Malicious Code that warrant review before production use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for reflect
ClawSecure detected 5 security findings in reflect, spanning Malicious Code, Code Injection, Skill Discovery Abuse and Permissions Manifest.
- high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
SKILL.md. - high · Potentially dangerous code pattern detected: eval\(. Code Injection finding detected in
signal_patterns.md. - medium · Detects protocol manipulation via capability inflation inβ¦. Skill Discovery Abuse finding detected in
SKILL.md:52. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- info · Missing License Declaration. Policy Violation finding detected in
SKILL.md.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for reflect
Audit external network connections
Eliminate dynamic code execution
Add a config.json permissions manifest
Resolve policy violations
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI AgentsβBeyond Static Scans: Why ClawSecure Verifies Agentic IntentβWhy Generic Scanners Fail at AI Agent SecurityβRelated AI Agent Security Audits
Scanned on February 26, 2026. reflect is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.