← Back to Scanner

skill-defender Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

skill-defender is an AI agent skill, created by itsclawdbro and published at openclaw/skills. ClawSecure audited skill-defender across 5 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 25 findings concentrate in Prompt Injection, Tool Chaining Abuse and Code Injection, including Pattern detected: ignore all previous instructions and Pattern detected: do not tell the user. 14 were rated high or critical severity.

Is skill-defender safe?

ClawSecure audited skill-defender and assigned a security score of 0/100 (High Risk), identifying 25 findings across Prompt Injection and Tool Chaining Abuse. Review the findings below before installing.

What did ClawSecure find in skill-defender?

ClawSecure identified 25 findings in skill-defender, concentrated in Prompt Injection, Tool Chaining Abuse and Code Injection. 14 were rated high or critical severity. The most severe include Pattern detected: ignore all previous instructions and Pattern detected: do not tell the user.

How was skill-defender audited?

ClawSecure ran skill-defender through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 5 files from openclaw/skills.

What does a score of 0 mean?

ClawSecure assigned skill-defender a security score of 0/100, placing it in the High Risk range. This is driven by 25 findings led by Prompt Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for skill-defender

ClawSecure detected 25 security findings in skill-defender, spanning Prompt Injection, Tool Chaining Abuse, Code Injection and Malicious Code.

Showing the 12 highest-severity of 25 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for skill-defender

Investigate prompt injection vectors
Prompt injection is one of the most critical threats to AI agents. Attackers can embed malicious instructions in content the agent processes, causing unintended actions. Review every point where skill-defender processes external content and add input validation and output filtering.
Eliminate dynamic code execution
skill-defender evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Audit external network connections
skill-defender connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.

Related Security Research

The Sleeper Agent Problem: Why a Clean Scan Today Does Not Guarantee Safety TomorrowOWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security Standards

Related AI Agent Security Audits

awesome-openclaw-skillsScore 0/100claude-memScore 15/100understand-anythingScore 0/100memUScore 0/100botcoin-minerScore 0/100

Scanned on February 7, 2026. skill-defender is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan