x-publisher Security Audit Report
x-publisher is an AI agent skill, created by alphafactor and published at openclaw/skills. ClawSecure audited x-publisher across 4 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 85/100 (Safe). The 5 findings concentrate in Policy Violation, Data Exfiltration and Command Injection, including Script iterates through environment variables in... and Code block in SKILL.md at line 232 contains potentially dangerous.... None were rated high or critical severity.
Is x-publisher safe?
ClawSecure audited x-publisher and assigned a security score of 85/100 (Safe), identifying 5 findings across Policy Violation and Data Exfiltration. Review the findings below before installing.
What did ClawSecure find in x-publisher?
ClawSecure identified 5 findings in x-publisher, concentrated in Policy Violation, Data Exfiltration and Command Injection. The most severe include Script iterates through environment variables in... and Code block in SKILL.md at line 232 contains potentially dangerous....
How was x-publisher audited?
ClawSecure ran x-publisher through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 4 files from openclaw/skills.
What does a score of 85 mean?
ClawSecure assigned x-publisher a security score of 85/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 5 findings detected are lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).
Audit Findings for x-publisher
ClawSecure detected 5 security findings in x-publisher, spanning Policy Violation, Data Exfiltration, Command Injection and Permissions Manifest.
- medium · Script iterates through environment variables in.... Data Exfiltration finding detected in
/tmp/url-scans/871b17fa2ff9ee4e/scripts/x_publisher.py. - medium · Code block in SKILL.md at line 232 contains potentially dangerous.... Command Injection finding detected in
SKILL.md:232. - medium · Missing config.json - agent may not be properly configured. Permissions Manifest finding.
- info · Skill name 'X-Publisher' is invalid. Agent skills require lowercase.... Policy Violation finding detected in
SKILL.md. - info · Skill manifest does not include a 'license' field. Specifying a license.... Policy Violation finding detected in
SKILL.md.
Each finding is expandable in the interactive list below.
3-Layer Audit Protocol
Security Recommendations for x-publisher
Resolve policy violations
Audit external network connections
Harden command execution
Add a config.json permissions manifest
Related Security Research
OWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security Standards→Understanding Our 3-Layer Audit Protocol→ClawHavoc Explained: The Malware Family Targeting AI Agents→Related AI Agent Security Audits
Scanned on March 12, 2026. x-publisher is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.