maishou is an AI agent skill, created by al-one and published at openclaw/skills. ClawSecure audited maishou across 3 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 80/100 (Safe). The 5 findings concentrate in Unauthorized Tool Use, Social Engineering and Policy Violation, including Skill code uses network libraries but doesn't declare network... and Skill performs actions not reflected in its description. None were rated high or critical severity.
Is maishou safe?
ClawSecure audited maishou and assigned a security score of 80/100 (Safe), identifying 5 findings across Unauthorized Tool Use and Social Engineering. Review the findings below before installing.
What did ClawSecure find in maishou?
ClawSecure identified 5 findings in maishou, concentrated in Unauthorized Tool Use, Social Engineering and Policy Violation. The most severe include Skill code uses network libraries but doesn't declare network... and Skill performs actions not reflected in its description.
How was maishou audited?
ClawSecure ran maishou through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 3 files from openclaw/skills.
What does a score of 80 mean?
ClawSecure assigned maishou a security score of 80/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 5 findings detected are lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for maishou
ClawSecure detected 5 security findings in maishou, spanning Unauthorized Tool Use, Social Engineering, Policy Violation and Data Exfiltration.
- medium · Skill code uses network libraries but doesn't declare network.... Unauthorized Tool Use finding detected in
/tmp/url-scans/368f8f3c1bd516f7/SKILL.md. - medium · Skill performs actions not reflected in its description. Social Engineering finding detected in
SKILL.md. - medium · Pattern detected: aiohttp.ClientSession(. Data Exfiltration finding detected in
scripts/main.py:116. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- info · Skill manifest does not include a 'license' field. Specifying a license.... Policy Violation finding detected in
SKILL.md.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for maishou
Resolve policy violations
Audit external network connections
Add a config.json permissions manifest
Pin dependencies to exact versions
1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.Related Security Research
OWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security Standards→Understanding Our 3-Layer Audit Protocol→ClawHavoc Explained: The Malware Family Targeting AI Agents→Related AI Agent Security Audits
Scanned on March 19, 2026. maishou is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.