← Back to Scanner

proactive-agent Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

proactive-agent is an AI agent skill, created by ClawHub Skill. ClawSecure audited proactive-agent across 15 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 19 findings concentrate in Malicious Code, Prompt Injection and Permissions Manifest, including Pattern 'ignore previous instructions...' detected in asset… and Pattern 'Ignore previous instructions...' detected in asset…. 16 were rated high or critical severity.

Is proactive-agent safe?

ClawSecure audited proactive-agent and assigned a security score of 0/100 (High Risk), identifying 19 findings across Malicious Code and Prompt Injection. Review the findings below before installing.

What did ClawSecure find in proactive-agent?

ClawSecure identified 19 findings in proactive-agent, concentrated in Malicious Code, Prompt Injection and Permissions Manifest. 16 were rated high or critical severity. The most severe include Pattern 'ignore previous instructions...' detected in asset… and Pattern 'Ignore previous instructions...' detected in asset….

How was proactive-agent audited?

ClawSecure ran proactive-agent through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 15 files.

What does a score of 0 mean?

ClawSecure assigned proactive-agent a security score of 0/100, placing it in the High Risk range. This is driven by 19 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for proactive-agent

ClawSecure detected 19 security findings in proactive-agent, spanning Malicious Code, Prompt Injection, Permissions Manifest and Policy Violation.

Showing the 12 highest-severity of 19 findings. The full interactive list appears below.

3-Layer Audit Protocol

Security Recommendations for proactive-agent

Audit external network connections
proactive-agent connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Investigate prompt injection vectors
Prompt injection is one of the most critical threats to AI agents. Attackers can embed malicious instructions in content the agent processes, causing unintended actions. Review every point where proactive-agent processes external content and add input validation and output filtering.
Add a config.json permissions manifest
A config.json file declares what an agent component can access: file system, network, shell execution and more. Without it, users have no visibility into what the component can do before installing. This is the single most impactful security improvement for any AI agent skill.

Related Security Research

ClawHavoc Explained: The Malware Family Targeting AI AgentsBeyond Static Scans: Why ClawSecure Verifies Agentic Intent

Related AI Agent Security Audits

byterover-cliScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100explain-code-for-developerScore 0/100

Scanned on February 26, 2026. proactive-agent is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan