agentauditAutomatic security gate that checks packages against a vulnerability database before installation. Use before any npm install, pip install, yarn add, or pack...
Install via ClawdBot CLI:
clawdbot install starbuck100/agentauditGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
Report → https://github.com/starbuck100/agentaudit-skill/issuesContains telemetry, tracking, or analytics calls not mentioned in documentation
Generated Mar 11, 2026
Development teams in regulated industries like finance or healthcare use AgentAudit to enforce mandatory security checks before any package installation, ensuring compliance with internal security policies and preventing vulnerable dependencies from entering the codebase. It integrates into CI/CD pipelines to automate vulnerability scanning during build processes, reducing manual oversight and speeding up secure deployments.
DevOps engineers leverage AgentAudit to secure containerized environments by gating package installations in Dockerfiles or Kubernetes deployments, preventing security breaches from malicious or outdated packages. It helps maintain a secure supply chain by automatically auditing dependencies before they are deployed to production servers, minimizing downtime and attack surfaces.
Maintainers of open-source projects use AgentAudit to vet contributions and dependencies, ensuring that pull requests do not introduce vulnerabilities and that the project remains trustworthy for its community. It automates security reviews during development, helping maintain high security standards without requiring extensive manual audits for every update.
Educational institutions and coding bootcamps implement AgentAudit to teach secure coding practices, allowing students to safely experiment with package installations while learning about vulnerability management and security gates. It provides hands-on experience with real-world security tools in a controlled setting, preparing learners for industry standards.
Developers building AI agents or chatbots with platforms like Claude Code or Cursor use AgentAudit to secure their skill ecosystems, preventing the installation of untrusted packages that could compromise agent functionality or user data. It ensures that only audited dependencies are used, enhancing reliability and security in AI-driven applications.
Offer a free tier for basic vulnerability checks with limited queries, and charge for premium features like advanced analytics, custom detection patterns, and enterprise support. Revenue is generated through subscription plans based on usage volume and team size, targeting small to large development teams.
Sell annual licenses to large organizations for on-premises deployment or enhanced security features, including integration with existing security tools and dedicated support. Revenue comes from one-time or recurring license fees, with additional charges for training and customization services.
Provide professional services to help companies integrate AgentAudit into their development workflows, offering custom audits, security training, and ongoing maintenance. Revenue is generated through hourly or project-based consulting fees, complementing the core product with tailored solutions.
💬 Integration Tip
Set the AGENTAUDIT_HOME environment variable to the skill's installation path for consistent script access across platforms, and test the gate script with sample packages to verify functionality before full deployment.
Scored May 16, 2026
Telemetry collection enabled by default (sendPotentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://agentaudit.devUses known external API (expected, informational)
api.github.comAI Analysis
The skill's external API calls (GitHub Issues, agentaudit.dev) are consistent with its stated purpose of vulnerability checking and reporting, though not all endpoints are documented. The 'ignore previous instructions' pattern appears in a security rule context, not as prompt poisoning. No credential harvesting or data exfiltration patterns are present in the provided content.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...