6bc837afc1a86e89 Security Audit Report
6bc837afc1a86e89 is an AI agent skill, created by NevaMind-AI and published at NevaMind-AI/memU. ClawSecure audited 6bc837afc1a86e89 across 75 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 12 findings concentrate in Malicious Code, Code Injection and Permissions Manifest, including Attempts to access sensitive file: MEMORY.md and Attempts to access sensitive file: MEMORY.md. 10 were rated high or critical severity.
Is 6bc837afc1a86e89 safe?
ClawSecure audited 6bc837afc1a86e89 and assigned a security score of 0/100 (High Risk), identifying 12 findings across Malicious Code and Code Injection. Review the findings below before installing.
What did ClawSecure find in 6bc837afc1a86e89?
ClawSecure identified 12 findings in 6bc837afc1a86e89, concentrated in Malicious Code, Code Injection and Permissions Manifest. 10 were rated high or critical severity. The most severe include Attempts to access sensitive file: MEMORY.md and Attempts to access sensitive file: MEMORY.md.
How was 6bc837afc1a86e89 audited?
ClawSecure ran 6bc837afc1a86e89 through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 75 files from NevaMind-AI/memU.
What does a score of 0 mean?
ClawSecure assigned 6bc837afc1a86e89 a security score of 0/100, placing it in the High Risk range. This is driven by 12 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for 6bc837afc1a86e89
ClawSecure detected 12 security findings in 6bc837afc1a86e89, spanning Malicious Code, Code Injection, Permissions Manifest and ReDoS.
- high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
SKILL.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
AGENTS.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
README.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
0004-workspace-memorize-and-memory-file-system.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
0006-from-memory-item-category-to-tracked-workspace-memorization.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
0007-three-independent-memory-lines-wiki-graph.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
0008-two-integration-surfaces-hooks-and-api.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
architecture.md. - high · Potentially dangerous code pattern detected: curl.*\|.*sh. Code Injection finding detected in
CONTRIBUTING.md. - high · Potentially dangerous code pattern detected: eval\(. Code Injection finding detected in
langgraph_demo.py. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- medium · ReDoS vulnerability: Nested quantifiers (potential catastrophic.... ReDoS finding detected in
0007-three-independent-memory-lines-wiki-graph.md:68.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for 6bc837afc1a86e89
Audit external network connections
Eliminate dynamic code execution
Add a config.json permissions manifest
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on July 7, 2026. 6bc837afc1a86e89 is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.