aegis-auditDeep behavioral security audit for AI agent skills and MCP tools. Performs deterministic static analysis (AST + Semgrep + 15 specialized scanners), cryptographic lockfile generation, and optional LLM-powered intent analysis. Use when installing, reviewing, or approving any skill, tool, plugin, or MCP server — especially before first use. Replaces basic safety summaries with full CWE-mapped, OWASP-tagged, line-referenced security reports.
Install via ClawdBot CLI:
clawdbot install sanguineseal/aegis-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/Aegis-Scan/aegis-scanAudited Apr 16, 2026 · audit v1.0
Generated Mar 20, 2026
Large organizations deploying AI agents for internal workflows use Aegis Audit to vet third-party skills before integration, ensuring compliance with security policies and preventing data exfiltration risks. It helps IT teams generate cryptographic lockfiles for approved skills, enabling tamper detection and audit trails during software updates.
Platforms hosting AI agent skills, like public registries or marketplaces, integrate Aegis Audit to automatically scan uploaded packages for malicious code, providing risk scores and CWE-mapped reports to users. This builds trust by offering transparent security assessments before download, reducing the spread of compromised tools.
Software development teams use Aegis Audit in CI/CD pipelines to scan custom-built AI skills for security vulnerabilities during pull requests, catching issues like unauthorized network access or file system operations early. The deterministic static analysis ensures consistent reports across environments, speeding up code reviews.
Universities and research labs teaching AI agent development employ Aegis Audit to help students analyze skill behaviors safely, using offline scanning to avoid exposing sensitive code. It serves as a learning tool for understanding security best practices and intent analysis without external data transmission.
Digital agencies using MCP tools with clients' data implement Aegis Audit to verify the security of third-party MCP servers before deployment, ensuring they don't leak sensitive information. The lockfile feature allows agencies to maintain verified versions and detect unauthorized modifications in production environments.
Offer Aegis Audit as a free open-source tool for basic scanning and lockfile generation, with premium features like advanced LLM analysis, team dashboards, and enterprise support available via subscription. Revenue comes from paid tiers targeting businesses needing enhanced security insights and compliance reporting.
License Aegis Audit's scanning engine to AI agent platforms, skill marketplaces, and development tools as an embedded security module, charging based on usage volume or per-seat fees. This model leverages partnerships to reach a broader user base while providing recurring revenue from platform integrations.
Provide consulting services for organizations to implement Aegis Audit in their security workflows, including custom rule development, audit training, and compliance assistance. Revenue is generated through one-time project fees and ongoing retainer agreements for security oversight and updates.
💬 Integration Tip
Integrate Aegis Audit into CI/CD pipelines using the --json flag for automated reporting and consider using the MCP server for real-time security checks within development environments like Cursor.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou...
Safe command execution for OpenClaw Agents with automatic danger pattern detection, risk assessment, user approval workflow, and audit logging. Use when agen...
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...