← Back to Scanner

tapp Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

tapp is an AI agent skill, created by TODAQmicro and published at TODAQmicro/openclaw-tapp. ClawSecure audited tapp across 5 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 98/100 (Safe). The finding concentrates in Verification, including No GitHub source URL - cannot verify agent origin. None were rated high or critical severity.

Is tapp safe?

ClawSecure audited tapp and assigned a security score of 98/100 (Safe), identifying 1 finding across Verification. Review the finding below before installing.

What did ClawSecure find in tapp?

ClawSecure identified 1 finding in tapp, concentrated in Verification. The most severe is No GitHub source URL - cannot verify agent origin.

How was tapp audited?

ClawSecure ran tapp through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 5 files from TODAQmicro/openclaw-tapp.

What does a score of 98 mean?

ClawSecure assigned tapp a security score of 98/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 1 finding detected is lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for tapp

ClawSecure detected 1 security finding in tapp, spanning Verification.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for tapp

Pin dependencies to exact versions
Unpinned dependencies allow supply-chain attacks where a compromised version is pulled in automatically. Use exact version numbers in package.json (for example 1.2.3 instead of ^1.2.3) to keep unauthorized code out of your dependency tree. ClawSecure checks every dependency against known CVE databases.
Add a config.json permissions manifest
A config.json file declares what permissions an agent component needs: file system access, network requests, shell execution and more. Without it, users have no visibility into what the component can do before installing. Adding a permissions manifest is the single most impactful security improvement for any AI agent skill.

Related Security Research

Best AI Agent Security Tools in 2026: How to ChooseAI Agent Security: The Complete 2026 GuideUnderstanding Our 3-Layer Audit Protocol

Related AI Agent Security Audits

tappScore 88/100sparkbtcbot-skillScore 90/100clippyScore 90/100stock-market-apiScore 95/100gtsec-smart-stock-selection (1)Score 95/100

Scanned on March 20, 2026. tapp is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan