ai-company-ciso-security-gateAI Company CISOsecurity门禁模块v2.1.0。STRIDE威胁建模、CVSS漏洞评分、security红线审查、最终发布审查、CEO-EXEC危机直通接口security规范。 触发关键词:security审查、security检查、漏洞扫描、威胁建模、危机直通、双重审批
Install via ClawdBot CLI:
clawdbot install johnsmithfan/ai-company-ciso-security-gateGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://clawhub.com/skills/ai-company-ciso-security-gateAudited Apr 18, 2026 · audit v1.0
Generated May 11, 2026
Before publishing a new AI skill to the agent marketplace, the CISO Security Gate performs STRIDE threat modeling, CVSS scoring, and red flag detection. This ensures no high-risk vulnerabilities or dangerous permissions are introduced, especially for skills that handle sensitive customer data.
When an executive needs to bypass standard approval for urgent skill updates (e.g., CEO-EXEC crisis channel), the Security Gate validates that the crisis path is secure, with dual-approval and white-listed operations. This prevents misuse while enabling rapid response.
When an existing skill is updated with new dependencies, the gate automatically checks the dependency tree for known vulnerabilities and flags any insecure packages. If a dependency scores CVSS >= 7.0, the update is rejected until the issue is resolved.
Skills requesting dangerous permissions (e.g., file deletion, network access) trigger the dual-approval workflow. Both the skill author and a CISO delegate must approve before the skill can be deployed, reducing insider threats.
When an external developer submits a skill to the marketplace, the Security Gate scans the code for red flags like hardcoded secrets, eval usage, or command injection patterns. Submissions with critical red flags are automatically rejected with detailed feedback.
Offer the CISO Security Gate as a monthly subscription for enterprises that want to embed security review into their internal AI skill pipeline. Includes regular updates to threat models, CVSS databases, and red flag patterns.
Integrate the gate into a third-party skill marketplace (e.g., Clawhub) and charge skill publishers a small fee per scan. The gate provides a verifiable security badge for approved skills, increasing trust and discoverability.
For large organizations with strict compliance needs, offer a premium tier that includes dual-approval workflows, audit logs, and integration with SIEM systems. Revenue is generated through annual contracts and custom integrations.
💬 Integration Tip
Integrate the gate as a CI/CD pipeline step before deploying any skill. For best results, combine with a centralized security dashboard that tracks all scan results and approval history.
Scored Jul 17, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...