agentsecAudit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before runnin...
Install via ClawdBot CLI:
clawdbot install markeljan/agentsecGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://agentsec.shAudited Apr 30, 2026 · audit v1.0
Generated Oct 6, 2026
A developer installs a third-party AI agent skill from ClawHub or GitHub and wants to verify it doesn't contain prompt injection, data exfiltration, or unsafe tool usage before running it locally. They run `npx agentsec` to scan the skill directory and receive a text report highlighting OWASP violations.
A platform engineering team integrates agentsec into their GitHub Actions pipeline so that every pull request modifying agent skills is automatically scanned. The build fails if critical vulnerabilities are found, and a SARIF report is uploaded to GitHub code scanning for inline annotations.
A security compliance officer needs to inventory all AI agent skills across engineering teams and produce an audit trail for SOC 2 or internal risk reviews. They run agentsec with an HTML output format to generate a stakeholder-ready report showing skill inventory, policy compliance, and remediation steps.
A decentralized finance (DeFi) protocol deploys AI agents that interact with smart contracts and wallets. Before allowing these agents to execute transactions, the team scans all installed skills using agentsec's `--profile web3` to force additional Web3-specific security rules and detect risky signing or key-handling patterns.
An MSSP offers AI agent security assessments as a service. During client onboarding, they run agentsec across the client's agent platforms (Claude, OpenClaw, Codex, Hermes) to identify vulnerable skills, generate JSON reports for their internal ticketing system, and recommend policy presets for ongoing monitoring.
The core agentsec CLI is free and open-source under MIT, covering basic OWASP scans. A paid enterprise tier offers advanced policy presets, custom rule authoring, centralized dashboards, and compliance mapping. Companies pay a subscription per seat or per audited skill directory.
Instead of selling tooling, the company uses agentsec internally to provide on-demand or scheduled audits of a client's AI agent ecosystem. Clients submit their skill directories or CI/CD pipelines, and the service returns detailed vulnerability reports, remediation guidance, and compliance attestations.
A curated marketplace where skill authors submit their packages for agentsec scanning and receive a 'Verified Safe' badge if they pass strict policy profiles. Developers browsing the marketplace can filter for verified skills, and the marketplace takes a transaction fee or listing fee from authors.
💬 Integration Tip
Integrate agentsec into CI/CD pipelines early (e.g., GitHub Actions) and use policy profiles like 'strict' or 'web3' to enforce security gates; combine with JSON/SARIF output for automated issue tracking and IDE-based code scanning.
Scored Oct 6, 2026
Meta-skill for AI agent self-improvement. Analyzes runtime logs to detect error patterns, regressions, and inefficiencies, then generates structured improvem...
Stop waiting for prompts. Keep working.
Turn OpenClaw into a learning-loop agent with seeded workspace rules, skill promotion, reflective memory, and proactive maintenance.
Meta-agent skill for orchestrating complex tasks through autonomous sub-agents. Decomposes macro tasks into subtasks, spawns specialized sub-agents with dynamically generated SKILL.md files, coordinates file-based communication, consolidates results, and dissolves agents upon completion. MANDATORY TRIGGERS: orchestrate, multi-agent, decompose task, spawn agents, sub-agents, parallel agents, agent coordination, task breakdown, meta-agent, agent factory, delegate tasks
Complete toolkit for creating autonomous AI agents and managing Discord channels for OpenClaw. Use when setting up multi-agent systems, creating new agents, or managing Discord channel organization.
Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentic...