Muguozi1 Openclaw Security Auditor

PassAudited by ClawScan on May 10, 2026.

Overview

This is mainly an instruction-only security review checklist with no credential, install, persistence, or network behavior; the main caution is that its quality/test claims are overstated by placeholder tests.

This skill appears safe to install from an agentic-security perspective because it is instruction-only and does not request credentials or execute setup steps. Use it as general security-review guidance, but do not rely on its quality badges or placeholder tests as proof that the skill itself has been thoroughly validated.

Findings (1)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

A user may over-trust the skill’s maturity or validation level even though the included tests and examples are placeholders.

Why it was flagged

The documentation claims full test coverage and high quality, while the included scripts/test.py contains TODO placeholders and automatically prints pass results. This is a trust/quality caution rather than evidence of malicious runtime behavior.

Skill content
| **测试覆盖** | 100/100 | ✅ 优秀 |
Recommendation

Treat the skill as an unverified checklist, not a certified security tool; ask the publisher to replace placeholder tests/examples and substantiate quality badges.