CowAgent is an AI agent skill, created by zhayujie and published at zhayujie/CowAgent. ClawSecure audited CowAgent across 74 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 0/100 (High Risk). The 13 findings concentrate in Malicious Code, Code Injection and Permissions Manifest, including Attempts to access sensitive file: MEMORY.md and Attempts to access sensitive file: MEMORY.md. 12 were rated high or critical severity.
Is CowAgent safe?
ClawSecure audited CowAgent and assigned a security score of 0/100 (High Risk), identifying 13 findings across Malicious Code and Code Injection. Review the findings below before installing.
What did ClawSecure find in CowAgent?
ClawSecure identified 13 findings in CowAgent, concentrated in Malicious Code, Code Injection and Permissions Manifest. 12 were rated high or critical severity. The most severe include Attempts to access sensitive file: MEMORY.md and Attempts to access sensitive file: MEMORY.md.
How was CowAgent audited?
ClawSecure ran CowAgent through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 74 files from zhayujie/CowAgent.
What does a score of 0 mean?
ClawSecure assigned CowAgent a security score of 0/100, placing it in the High Risk range. This is driven by 13 findings led by Malicious Code that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for CowAgent
ClawSecure detected 13 security findings in CowAgent, spanning Malicious Code, Code Injection and Permissions Manifest.
- high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
README.md. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
admin.py. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
backup.py. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
executor.py. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
prompts.py. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
manager.py. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
service.py. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
summarizer.py. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
builder.py. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
workspace.py. - high · Attempts to access sensitive file: MEMORY.md. Malicious Code finding detected in
artifact.py. - high · Potentially dangerous code pattern detected: system\(. Code Injection finding detected in
config.py.
Showing the 12 highest-severity of 13 findings. The full interactive list appears below.
3-Layer Audit Protocol
Security Recommendations for CowAgent
Audit external network connections
Eliminate dynamic code execution
Add a config.json permissions manifest
Related Security Research
ClawHavoc Explained: The Malware Family Targeting AI Agents→Beyond Static Scans: Why ClawSecure Verifies Agentic Intent→Related AI Agent Security Audits
Scanned on September 14, 2026. CowAgent is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.