← Back to Scanner

UpChangeAnalyzer Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

UpChangeAnalyzer is an AI agent skill. ClawSecure audited UpChangeAnalyzer across 7 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 39/100 (High Risk). The 16 findings concentrate in Policy Violation, Obfuscation and Supply Chain Attack, including Archive file found:… and File 'ATP_Margin_V4.7.3.1.4_更新说明及影响域分析.xlsx' extension…. None were rated high or critical severity.

Is UpChangeAnalyzer safe?

ClawSecure audited UpChangeAnalyzer and assigned a security score of 39/100 (High Risk), identifying 16 findings across Policy Violation and Obfuscation. Review the findings below before installing.

What did ClawSecure find in UpChangeAnalyzer?

ClawSecure identified 16 findings in UpChangeAnalyzer, concentrated in Policy Violation, Obfuscation and Supply Chain Attack. The most severe include Archive file found:… and File 'ATP_Margin_V4.7.3.1.4_更新说明及影响域分析.xlsx' extension….

How was UpChangeAnalyzer audited?

ClawSecure ran UpChangeAnalyzer through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 7 files.

What does a score of 39 mean?

ClawSecure assigned UpChangeAnalyzer a security score of 39/100, placing it in the High Risk range. This is driven by 16 findings led by Policy Violation that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for UpChangeAnalyzer

ClawSecure detected 16 security findings in UpChangeAnalyzer, spanning Policy Violation, Obfuscation, Supply Chain Attack and Permissions Manifest.

Showing the 12 highest-severity of 16 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for UpChangeAnalyzer

Resolve policy violations
UpChangeAnalyzer trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.
Review obfuscated or hidden code
UpChangeAnalyzer contains obfuscated or hidden content that resists review. Inspect encoded, minified or hidden files to confirm they are not concealing unexpected behavior before installing.
Add a config.json permissions manifest
A config.json file declares what an agent component can access: file system, network, shell execution and more. Without it, users have no visibility into what the component can do before installing. This is the single most impactful security improvement for any AI agent skill.

Related Security Research

OWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security StandardsUnderstanding Our 3-Layer Audit Protocol

Related AI Agent Security Audits

decodo-scraperScore 36/100evolverScore 25/100evolverScore 25/100evolverScore 25/100evolverScore 25/100

Scanned on June 12, 2026. UpChangeAnalyzer is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan