agent-safetyOutbound safety for autonomous AI agents — scans YOUR output before it leaves the machine. Git pre-commit hooks that automatically block commits containing A...
Install via ClawdBot CLI:
clawdbot install compass-soul/agent-safetyGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdCalls external URL not in known-safe list
https://github.com/openclaw/openclawAI Analysis
The skill's core purpose is defensive security scanning, and the external call to the official OpenClaw GitHub repository appears to be for version checking, which is consistent with its stated health check function. However, accessing system files like /etc/passwd during scans, while potentially legitimate for security checks, introduces a low-level risk if misconfigured or exploited.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 20, 2026
Developers working on public GitHub repositories use the pre-commit hook to automatically block commits containing API keys or secrets before pushing code. This prevents accidental exposure of sensitive data in version control, ensuring compliance with security policies and reducing breach risks.
Healthcare organizations employ the pre-publish scan to check reports or datasets for PII like SSNs and email addresses before sharing externally. This automated enforcement helps maintain HIPAA compliance by preventing unauthorized disclosure of patient information during data transfers.
Financial firms run periodic health checks to monitor system security, such as firewall status and disk usage, while using pre-commit hooks to scan code for credit card patterns. This ensures secure handling of financial data and prevents leaks in development workflows.
DevOps teams integrate the pre-publish scan into CI/CD pipelines to automatically validate artifacts before deployment. It detects secrets like AWS keys in configuration files, blocking unsafe releases and enhancing security in automated software delivery processes.
Offer the safety tools as a cloud-based service with tiered pricing based on scan volume or repository count. Revenue is generated through monthly subscriptions, targeting enterprises needing scalable security enforcement for their development teams.
Sell on-premise licenses for large organizations requiring full control over data. This includes custom integrations and support services, with revenue from one-time license fees and annual maintenance contracts for updates and technical assistance.
Provide basic scanning and pre-commit hooks for free to attract individual developers, while charging for advanced features like detailed reporting, priority support, or integration with proprietary systems. Revenue comes from upgrades to premium tiers.
💬 Integration Tip
Start by installing the pre-commit hook on a test repository to familiarize with the blocking and review processes, then expand to all active repos for consistent enforcement.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...