← Back to Scanner

x-publisher Security Audit Report

🔭 Continuously monitored by ClawSecure Watchtower
Source:
SHA-256:

x-publisher is an AI agent skill, created by alphafactor and published at openclaw/skills. ClawSecure audited x-publisher across 4 files through the 3-Layer Audit Protocol covering all ten OWASP ASI Top 10 categories, assigning a security score of 85/100 (Safe). The 5 findings concentrate in Policy Violation, Data Exfiltration and Command Injection, including Script iterates through environment variables in... and Code block in SKILL.md at line 232 contains potentially dangerous.... None were rated high or critical severity.

Is x-publisher safe?

ClawSecure audited x-publisher and assigned a security score of 85/100 (Safe), identifying 5 findings across Policy Violation and Data Exfiltration. Review the findings below before installing.

What did ClawSecure find in x-publisher?

ClawSecure identified 5 findings in x-publisher, concentrated in Policy Violation, Data Exfiltration and Command Injection. The most severe include Script iterates through environment variables in... and Code block in SKILL.md at line 232 contains potentially dangerous....

How was x-publisher audited?

ClawSecure ran x-publisher through its 3-Layer Audit Protocol with full OWASP ASI Top 10 coverage, scanning 4 files from openclaw/skills.

What does a score of 85 mean?

ClawSecure assigned x-publisher a security score of 85/100, placing it in the Safe range. Scores of 80 or above qualify for ClawSecure Verified status; the 5 findings detected are lower-severity. ClawSecure derives this score with a weighted deduction model (critical -20, high -10, medium -5, low -2 from a base of 100).

Audit Findings for x-publisher

ClawSecure detected 5 security findings in x-publisher, spanning Policy Violation, Data Exfiltration, Command Injection and Permissions Manifest.

Each finding is expandable in the interactive list below.

3-Layer Audit Protocol

Security Recommendations for x-publisher

Resolve policy violations
x-publisher trips ClawSecure policy checks. Review each flagged pattern against your security policy and remediate or document an accepted exception before production use.
Audit external network connections
x-publisher sends data to external endpoints. Confirm each destination is expected and authorized, and remove any callback that exfiltrates data. ClawSecure monitors for known exfiltration and C2 endpoints.
Harden command execution
x-publisher constructs or runs system commands. Validate that commands are built only from trusted inputs, never pass user-controlled strings directly to a shell, and restrict execution to an allow-list of expected commands.
Add a config.json permissions manifest
A config.json file declares what an agent component can access: file system, network, shell execution and more. Without it, users have no visibility into what the component can do before installing. This is the single most impactful security improvement for any AI agent skill.

Related Security Research

OWASP ASI Top 10 Explained: The Complete Guide to AI Agent Security StandardsUnderstanding Our 3-Layer Audit ProtocolClawHavoc Explained: The Malware Family Targeting AI Agents

Related AI Agent Security Audits

songseeScore 95/100goplacesScore 95/100gogcliScore 95/100ui-ux-pro-max-skillScore 75/100clawdhubScore 75/100

Scanned on March 12, 2026. x-publisher is one of thousands of agents audited by ClawSecure from the community-curated awesome-openclaw-skills list and the openclaw/skills repository.

Start Your Free Scan