audit-codeSecurity-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities
Install via ClawdBot CLI:
clawdbot install itsnishi/audit-codeGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdPotentially destructive shell commands in tool definitions
eval(AI Analysis
The skill is a static code analyzer that runs locally using allowed tools (Read, Glob, Grep, Bash) and does not invoke external APIs or send data externally. The rule-based signals are triggered by the skill's own code scanning for dangerous patterns (like eval or file access), which is its intended security-auditing function, not malicious behavior.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 1, 2026
Integrate the audit-code skill into a CI/CD pipeline to automatically scan code changes before commits. This helps developers catch hardcoded secrets and dangerous calls early, reducing security risks in production deployments.
Use the skill to audit contributions from external developers or open-source libraries. It identifies vulnerabilities like SQL injection or dependency risks, ensuring code quality and security in collaborative projects.
After generating code with AI tools, run the audit-code skill to check for introduced vulnerabilities such as hardcoded API keys or unsafe function calls. This validates the safety of AI-assisted development workflows.
Schedule regular scans of the entire codebase to detect new security issues over time. This proactive approach helps maintain compliance with security standards and mitigates risks from evolving threats.
Offer the audit-code skill as a cloud-based service with subscription plans. Provide automated reports and integrations with popular development platforms, generating revenue through monthly or annual licenses.
Bundle the skill with professional services for custom security audits and training. Target large organizations needing tailored solutions, with revenue from project-based contracts and ongoing support.
Release a basic version of the skill as free open-source software, with premium features like advanced reporting or priority support available for purchase. This model builds a user base and drives upgrades.
💬 Integration Tip
Set up the skill to run automatically in CI/CD pipelines using tools like GitHub Actions or Jenkins, ensuring scans occur on every code change without manual intervention.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...