← Back to Scanner

chaos-mind Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

chaos-mind is an AI agent skill, created by hargabyte and published at hargabyte/chaos-mind. ClawSecure audited chaos-mind across 15 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 19 findings concentrate in Command Injection, Code Injection and Unauthorized Tool Use, including Pattern detected: sudo systemctl and Pattern detected: sudo systemctl. 14 were rated high or critical severity.

Is chaos-mind safe?

ClawSecure audited chaos-mind and assigned a security score of 0/100 (High Risk), identifying 19 findings across Command Injection and Code Injection. Review the findings below before installing.

What did ClawSecure find in chaos-mind?

ClawSecure identified 19 findings in chaos-mind, concentrated in Command Injection, Code Injection and Unauthorized Tool Use. 14 were rated high or critical severity. The most severe include Pattern detected: sudo systemctl and Pattern detected: sudo systemctl.

How was chaos-mind audited?

ClawSecure ran chaos-mind through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 15 files from hargabyte/chaos-mind.

What does a score of 0 mean?

ClawSecure assigned chaos-mind a security score of 0/100, placing it in the High Risk range. This is driven by 19 findings led by Command Injection that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for chaos-mind

ClawSecure detected 19 security findings in chaos-mind, spanning Command Injection, Code Injection, Unauthorized Tool Use and Policy Violation.

Showing the 12 highest-severity of 19 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for chaos-mind

Harden command execution
chaos-mind constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Eliminate dynamic code execution
chaos-mind evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.
Resolve policy violations
chaos-mind trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.

Related Security Research

Why Generic Scanners Fail at AI Agent SecurityUnderstanding Our 3-Layer Audit Protocol

Related AI Agent Security Audits

memUScore 0/100understand-anythingScore 0/10062ac696296b54aadScore 0/1006bc837afc1a86e89Score 0/10062ac696296b54aadScore 0/100

Scanned on May 2, 2026. chaos-mind is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan