bug-auditComprehensive bug audit for Node.js web projects. Activate when user asks to audit, review, check bugs, find vulnerabilities, or do security/quality review o...
Install via ClawdBot CLI:
clawdbot install abczsl520/bug-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Contains telemetry, tracking, or analytics calls not mentioned in documentation
Beacon(Potentially destructive shell commands in tool definitions
eval(Generated Mar 21, 2026
A studio building a multiplayer online game with in-app purchases needs to ensure no bugs allow players to duplicate currency, skip payment for premium items, or exploit race conditions in battle states. The audit dissects API endpoints for payment flows, state machines for game sessions, and resource ledgers for virtual goods.
A company providing financial APIs for transactions and account management requires security audits to prevent authentication bypass, data leakage in responses, and concurrency issues in balance updates. The audit focuses on API endpoints, data flows between payment steps, and numeric validation for transaction amounts.
An online marketplace with user dashboards and inventory management needs to audit for vulnerabilities like price manipulation, coupon abuse, and stock reservation race conditions. The audit examines numeric values for costs, data flows for buy-sell operations, and concurrency hotspots in order processing.
A tool for processing and visualizing patient data must ensure data integrity, access control, and no leaks of sensitive information. The audit reviews API endpoints for authentication, state machines for user sessions, and resource ledgers for data access logs to comply with regulations.
A bot managing user interactions and content moderation on platforms like WeChat requires auditing for message injection, bot state abuse, and rate limiting issues. The audit analyzes timers for scheduled tasks, data flows for user actions, and concurrency in message handling.
Offer ongoing audit services to clients on a monthly or annual subscription, providing regular bug checks and updates as code evolves. This ensures continuous security and quality assurance, especially for agile development teams.
Charge a fixed fee or hourly rate for one-time comprehensive audits of specific projects, such as before major releases or compliance reviews. This targets clients with immediate security needs or limited budgets.
License the bug audit skill to be integrated into CI/CD pipelines or IDEs, automating checks during development. This model appeals to tech companies seeking to embed security into their workflows.
💬 Integration Tip
Integrate this skill into your CI/CD pipeline to automatically run audits on code commits, ensuring bugs are caught early in development cycles.
Scored Jun 19, 2026
Calls external URL not in known-safe list
https://img.shields.io/badge/ClawHub-bug--audit-blue?style=flat-squareAI Analysis
The skill is a legitimate code audit tool that analyzes project files locally; the flagged signals are false positives from its own descriptive examples (like '/etc/passwd' as a hypothetical attack vector) and its own badge URL. No evidence of credential harvesting, data exfiltration, or hidden malicious instructions exists.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...