Back to Enderfga/openclaw-claude-code
critical
openclaw-claude-code / claude-code-skill
https://skillshield.getunbound.ai/skill/25358High Risk & Threats
Control Claude Code via MCP protocol. Execute commands, read/write files, search code, and use all Claude Code tools programmatically with agent team support.
Findings (9)
Findings Preview
DS-004
Autonomous execution without user approval
Skill is explicitly designed for autonomous agent execution. Lines 26, 50, 105-106, 120 document modes that auto-approve operations ('acceptEdits', 'bypassPermissions'). The skill enables Claude agents to execute complex multi-step tasks without user confirmation at each step. Line 120 explicitly documents 'bypassPermissions' mode that 'Skip all prompts (dangerous!)'.
Category Breakdown
Data Exfiltration
5
Malware & Persistence
0
Prompt Injection
100
Destructive Actions
5
Excessive Permissions
5
Supply Chain
25
Obfuscation
100