braindb is an AI agent skill, created by chair4ce and published at openclaw/skills. ClawSecure audited braindb across 14 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 31 findings concentrate in Data Exfiltration, Malicious Code and Command Injection, including Suspicious Pattern: from 'child_process' and Suspicious Pattern: execSync(. 14 were rated high or critical severity.
Is braindb safe?
ClawSecure audited braindb and assigned a security score of 0/100 (High Risk), identifying 31 findings across Data Exfiltration and Malicious Code. Review the findings below before installing.
What did ClawSecure find in braindb?
ClawSecure identified 31 findings in braindb, concentrated in Data Exfiltration, Malicious Code and Command Injection. 14 were rated high or critical severity. The most severe include Suspicious Pattern: from 'child_process' and Suspicious Pattern: execSync(.
How was braindb audited?
ClawSecure ran braindb through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 14 files from openclaw/skills.
What does a score of 0 mean?
ClawSecure assigned braindb a security score of 0/100, placing it in the High Risk range. This is driven by 31 findings led by Data Exfiltration that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for braindb
ClawSecure detected 31 security findings in braindb, spanning Data Exfiltration, Malicious Code, Command Injection and Policy Violation.
- critical · Suspicious Pattern: from 'child_process'. Command Injection finding detected in
execution-awareness.js:22. - critical · Suspicious Pattern: execSync(. Command Injection finding detected in
execution-awareness.js:56. - critical · Suspicious Pattern: execSync(. Command Injection finding detected in
execution-awareness.js:60. - critical · Suspicious Pattern: execSync(. Command Injection finding detected in
execution-awareness.js:156. - high · Only 66% of skill content could be analyzed. 4 of 14 filesβ¦. Policy Violation finding.
- high · Suspicious Pattern: fs.readFileSync(. Data Exfiltration finding detected in
migrate.cjs:628. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
README.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
SKILL.md. - high · Attempts to access sensitive file: SOUL.md. Malicious Code finding detected in
install.sh. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
install.sh. - high · Attempts to access sensitive file: SOUL.md. Malicious Code finding detected in
migrate.cjs. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
migrate.cjs.
Showing the 12 highest-severity of 31 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for braindb
Audit external network connections
Harden command execution
Resolve policy violations
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI AgentsβBeyond Static Scans: Why ClawSecure Verifies Agentic IntentβRelated AI Agent Security Audits
Scanned on April 7, 2026. braindb is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.