clawhub-gomboc-security-main-v0-2-0Automatically scan any codebase for security issues and generate deterministic, merge-ready fixes for continuous remediation via CLI, CI/CD, or agents.
Install via ClawdBot CLI:
clawdbot install matthewsweeney/clawhub-gomboc-security-main-v0-2-0Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → http://localhost:3100/scanCalls external URL not in known-safe list
https://app.gomboc.aiAI Analysis
The skill sends code to a documented external service (Gomboc.ai) for analysis, which is consistent with its stated purpose of code remediation. While this involves data transfer to a third party, it is not unauthorized or hidden, and there is no evidence of credential harvesting, obfuscation, or malicious overrides of user intent.
Audited Apr 18, 2026 · audit v1.0
Generated May 12, 2026
An enterprise DevOps team uses the Gomboc skill to continuously scan Terraform and Kubernetes configs for security misconfigurations and automatically generate merge-ready pull requests. This ensures compliance with standards like CIS AWS Foundations without manual effort.
A SaaS company integrates the Gomboc skill as a GitHub Action in their CI/CD pipeline. Every commit triggers a scan for IaC and application security issues, with fixes automatically proposed or applied, preventing vulnerable code from reaching production.
An AI coding agent (e.g., based on Claude or GPT) uses the Gomboc MCP server to autonomously scan and fix security issues in a codebase it is modifying. The deterministic fixes complement the agent's generative coding, providing a trusted remediation step.
A security consulting firm uses the Gomboc CLI to scan multiple client codebases (Terraform, CloudFormation, configs) during audits. They generate detailed reports and merge-ready fixes, reducing manual review time and ensuring consistent remediation.
Offer free basic scanning and fixing capabilities for individual developers and small teams, with limits on scans per month. Generate leads for the paid enterprise version which offers higher limits, advanced policies, and priority support.
Sell a premium GitHub Actions integration that includes advanced features like auto-merge, policy customisation, and integration with multiple repositories. Charged per repository per month.
Provide a fully managed service where the company sets up, monitors, and maintains continuous security scanning and fixing for a client's entire codebase. Includes reporting, compliance dashboards, and SLA-backed remediation.
💬 Integration Tip
For a fast start, set the GOMBOC_PAT environment variable and run the CLI scan command; for continuous automated remediation, add the Gomboc GitHub Action to your workflow file.
Scored May 12, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...