ClawTrust LogoClawTrust
claw skill security audit

claw skill security audit

by kylehuan · v1.0.0

Research
ClawHub
8.6
/ 10
1 evaluations
1.8k Downloads

Overview

Perform structured, read‑only security audits of codebases and OpenClaw SKILL.md files, focusing on concrete vulnerabilities and prompt‑safety issues.

Key Advantages

1.Well‑defined, explicit methodology for code and SKILL.md security review
2.Strong focus on instruction‑/prompt‑injection, data exfiltration, privilege escalation, and LLM tool safety
3.Read‑only tooling (ls -R, grep, read-file) greatly reduces risk of unintended side effects
4.Clear severity rubric (Critical/High/Medium/Low) aligned with practical impact
5.High‑fidelity reporting rules to minimize speculative or low‑value findings

Use Cases

  • Security review of OpenClaw SKILL.md files before publishing or enabling them in production agents
  • Static security review of application codebases for injection flaws, hardcoded secrets, and broken access control
  • Focused audit of LLM-related logic: prompt construction, tool invocation, and execution of LLM outputs
  • Privacy assessment of how PII and sensitive data flow through logs and external APIs
  • Governance checks on third‑party or community skills for data exfiltration or privilege-escalation risks

Evaluation Scores

8.6
/ 10
Reliability
8.4
Functionality
8.6
Usability
8.0
Safety
9.6
Performance
8.0
Compatibility
8.3

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.6/103/19/2026
▼
OS: darwin-arm64LLM: openai/gpt-5-nano
### Quick judgment A strong, well‑scoped security auditing skill specialized for static analysis of codebases and OpenClaw SKILL.md files. It emphasizes concrete, evidence‑based findings and avoids speculative or purely theoretical issues. Best suited as a security review assistant and governance layer around skills and LLM integrations, not as a full replacement for professional penetration testing or dynamic security tools. ### Key risks / limitations - **Static-only viewpoint:** Relies on read‑only filesystem access and source inspection; it cannot perform dynamic testing, fuzzing, or live exploitation validation. - **Coverage limits:** While it covers many common vulnerability classes (injection, access control, secrets, privacy, prompt/LLM safety), it may miss highly framework‑specific issues, complex business‑logic flaws, or vulnerabilities hidden in binary/dependency artifacts. - **Potential for false negatives/positives:** As with any SAST-style approach, some subtle issues may be missed, and some reported risks may require human validation in context. ### Recommended scenarios - Vetting **OpenClaw SKILL.md** files for instruction injection, data exfiltration, or privilege-escalation patterns before enabling skills on shared or production agents. - Running a **security pass on codebases** when a user explicitly requests vulnerability assessment, SAST-style scanning, or security hardening input. - Reviewing **LLM-related integration code** (prompt construction, tool wiring, exec paths) to catch prompt injection, unsafe eval/exec, or untrusted-output-to-dangerous-sink flows. - Performing **privacy impact checks** on how sensitive fields (email, password, ssn, phone, apiKey) are logged or sent to third parties in application code or agent workflows.

Comments (0)

Post a Comment

No comments yet. Be the first!