bookforge-secure-code-reviewReview code for security vulnerabilities and reliability anti-patterns: scan for SQL injection risks (raw string concatenation into queries), XSS exposure (u...
Install via ClawdBot CLI:
clawdbot install quochungto/bookforge-secure-code-reviewGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
exec(Calls external URL not in known-safe list
https://github.com/bookforge-ai/bookforge-skills/tree/main/books/building-secureAI Analysis
The skill definition describes a static code analysis tool that runs locally using Grep and Read; the only external reference is a public GitHub repository URL for its homepage, which is not called during execution. No evidence of data exfiltration, credential harvesting, or hidden malicious instructions exists.
Audited Apr 17, 2026 · audit v1.0
Generated May 12, 2026
A fintech company is about to launch a new payment processing service. The secure code review skill scans the codebase for SQL injection risks in transaction queries and XSS vulnerabilities in user-facing dashboards, ensuring compliance with financial regulations.
A healthcare startup's platform manages sensitive patient data. Using this skill, the team reviews code for authorization bypass vulnerabilities and primitive type obsession in medical record identifiers to prevent unauthorized access.
An e-commerce company receives a pull request that modifies the checkout flow. The skill identifies XSS exposure in new HTML templates and SQL injection risks in discount code queries before deployment.
A social media company introduces a direct messaging feature. This skill reviews the RPC backend for missing framework enforcement of authentication and rate-limiting, and checks for stored XSS in message rendering.
A large enterprise maintains a legacy CRM system. The skill assesses YAGNI complexity like unused parameters and dead code, and scans for primitive type obsession that could lead to security misconfigurations.
Offer the secure code review as a premium module in a SaaS platform, allowing customers to run automated security audits on their codebases periodically. Revenue from tiered subscriptions based on frequency and codebase size.
Provide a professional services model where clients pay for a one-time deep security code review before major releases. Revenue from flat fees or hourly rates plus a findings report.
Package the skill as a plugin for popular CI/CD tools (e.g., GitHub Actions, GitLab CI). Charge per usage or a flat monthly fee per repository. Revenue from plugin purchases or subscription to a security audit tool.
💬 Integration Tip
Integrate this skill into your CI/CD pipeline to automatically run reviews on every pull request; combine with a static analysis tool for continuous vulnerability tracking.
Scored May 12, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...