check-axios-malwareCheck if the local machine is infected by the malicious axios supply-chain attack (axios 1.14.1/0.30.4 via [email protected]). Use when: user asks about...
Install via ClawdBot CLI:
clawdbot install tjefferson/check-axios-malwareGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://www.panewslab.com/zh/articles/019d42da-491d-70b7-b00b-b14e59b97f80AI Analysis
The skill performs local system checks for known malware indicators and does not contain instructions to send data to external servers. The flagged 'rm -rf /' command is part of a remediation example for a user to execute manually, not an automated action. The external URL appears to be a reference link in documentation, not an active call.
Audited Apr 16, 2026 · audit v1.0
Generated Apr 26, 2026
Security teams can use this skill to quickly scan local machines for indicators of compromise from the malicious axios supply-chain attack. It checks for the presence of plain-crypto-js, compromised axios versions, suspicious processes, and persistence mechanisms, enabling fast containment and remediation.
DevOps engineers can run this skill on CI/CD runners or developer workstations to detect if any machine was affected by the axios trojan. The automated checks help ensure that build and deployment environments are not compromised before releasing software.
Users of OpenClaw version 2026.3.28 can verify if their system was exposed during the attack window. The skill checks the OpenClaw version and axios dependency, providing clear guidance on whether credentials need rotation.
Small businesses without dedicated security teams can use this skill to perform a basic machine scan for the supply-chain backdoor. The step-by-step commands and IOC table make it accessible for non-experts.
Offer a free scan for the axios malware as a lead generation tool for a broader security monitoring platform. The free scan builds trust and demonstrates capability, with upsell to continuous monitoring or incident response services.
Include this skill as part of an incident response retainer package for clients. Rapid supply-chain compromise scanning can be a premium feature that reduces time-to-detection, justifying higher retainer fees.
Package the skill into a compliance automation tool that runs on employee laptops to enforce security policies. Sell to organizations needing to meet supply-chain security standards (e.g., SOC 2).
💬 Integration Tip
Integrate into a runbook or automated scanning script to execute on all internal machines after a supply-chain advisory. For CI/CD pipelines, run as a pre-deployment check to block builds on compromised nodes.
Scored Jun 20, 2026
Use when building iOS/macOS applications with Swift 5.9+, SwiftUI, or async/await concurrency. Invoke for protocol-oriented programming, SwiftUI state management, actors, server-side Swift.
Control Android devices via ADB (Android Debug Bridge) from a Mac. Use when: remotely operating an Android phone (tap, swipe, type, screenshot, screen record...
Information assistant for OPPO. Search products, news, financials, and official resources for OPPO.
Control iOS automation via StarryForest Agent Mail API. Use when creating alarms, reminders, memos, calendar events, focus modes, music playback, or journal...
Information assistant for Taylor Swift 泰勒斯威夫特. Get biography, latest news, career highlights, and social media updates.
介绍华为从深圳小公司成长为全球5G领导者,解析其在制裁下的生存策略与全球科技影响力。