← Back to Scanner

9c0a7c48db776b22 Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

9c0a7c48db776b22 is an AI agent skill, created by junegunn and published at junegunn/fzf. ClawSecure audited 9c0a7c48db776b22 across 98 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 35/100 (Critical). The 9 findings concentrate in ReDoS, Malicious Code and Code Injection, including Attempts to access sensitive file: .ssh/ and Attempts to access sensitive file: .ssh/. 4 were rated high or critical severity.

Is 9c0a7c48db776b22 safe?

ClawSecure audited 9c0a7c48db776b22 and assigned a security score of 35/100 (Critical), identifying 9 findings across ReDoS and Malicious Code. Review the findings below before installing.

What did ClawSecure find in 9c0a7c48db776b22?

ClawSecure identified 9 findings in 9c0a7c48db776b22, concentrated in ReDoS, Malicious Code and Code Injection. 4 were rated high or critical severity. The most severe include Attempts to access sensitive file: .ssh/ and Attempts to access sensitive file: .ssh/.

How was 9c0a7c48db776b22 audited?

ClawSecure ran 9c0a7c48db776b22 through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 98 files from junegunn/fzf.

What does a score of 35 mean?

ClawSecure assigned 9c0a7c48db776b22 a security score of 35/100, placing it in the Critical range. This is driven by 9 findings led by ReDoS that should be addressed before use. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for 9c0a7c48db776b22

ClawSecure detected 9 security findings in 9c0a7c48db776b22, spanning ReDoS, Malicious Code, Code Injection and Permissions Manifest.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for 9c0a7c48db776b22

Fix ReDoS-prone patterns
9c0a7c48db776b22 contains regular expressions vulnerable to catastrophic backtracking (ReDoS). Replace vulnerable patterns, bound input length, and prefer linear-time matching so a crafted input cannot hang the agent.
Audit external network connections
9c0a7c48db776b22 connects to external endpoints. Verify every outbound connection goes to a trusted destination. Unauthorized callbacks are a primary indicator of ClawHavoc malware and data exfiltration. ClawSecure's proprietary engine monitors for known malicious endpoints including C2 infrastructure.
Eliminate dynamic code execution
9c0a7c48db776b22 evaluates code at runtime (for example eval or dynamic exec). Remove dynamic evaluation of untrusted input, and where code generation is unavoidable, sandbox it and validate every input.

Related Security Research

Why Generic Scanners Fail at AI Agent SecurityUnderstanding Our 3-Layer Audit Protocol

Related AI Agent Security Audits

claude-memScore 45/100fzfScore 25/100open-webuiScore 35/100perplexity-web-mcpScore 50/100keepScore 45/100

Scanned on May 22, 2026. 9c0a7c48db776b22 is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan