clawsec-nanoclawUse when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
Install via ClawdBot CLI:
clawdbot install davida-ps/clawsec-nanoclawGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://clawsec.prompt.security/advisories/feed.jsonUses known external API (expected, informational)
raw.githubusercontent.comAI Analysis
The skill appears to be a legitimate security monitoring tool that checks skills against a known advisory feed. The external URL (clawsec.prompt.security) is consistent with its stated purpose of fetching security advisories, and the GitHub URL is for fetching skill manifests. The 'rm -rf /' appears to be in example code rather than actual tool implementation, but still warrants caution.
Generated Mar 20, 2026
A small e-commerce company uses a WhatsApp bot for customer support and order tracking. They regularly install new skills to add features like payment processing or inventory checks. Before each installation, they use ClawSec to check for vulnerabilities, ensuring no known exploits compromise customer data or transaction security.
A healthcare provider employs a WhatsApp bot to schedule appointments and send medication reminders. They must comply with data protection regulations like HIPAA. ClawSec helps audit installed skills for security advisories, preventing vulnerabilities that could lead to data breaches and ensuring patient information remains secure.
A fintech startup uses a WhatsApp bot for basic banking queries and fraud alerts. They integrate third-party skills for currency conversion and transaction history. ClawSec is used to perform pre-installation checks and periodic audits, mitigating risks of financial fraud or unauthorized access through vulnerable dependencies.
A university deploys a WhatsApp bot to assist students with course registration and campus updates. They frequently update skills to add new functionalities. ClawSec ensures that before installing any skill, it is checked against security advisories, protecting student data and maintaining system integrity against potential exploits.
A logistics company uses a WhatsApp bot to track shipments and communicate with drivers. They rely on various skills for route optimization and weather updates. ClawSec monitors these skills for vulnerabilities, preventing supply chain attacks that could disrupt operations or leak sensitive shipment details.
Offer ClawSec as a monthly or annual subscription for businesses using WhatsApp bots. Provide regular updates to the advisory feed, priority support, and automated audit reports. Revenue is generated through tiered pricing based on the number of skills monitored or bot usage scale.
Provide basic vulnerability checks for free to attract users, with limitations on the number of skills or audit frequency. Charge for advanced features like real-time alerts, detailed exploitability analysis, and integration with other security tools. Revenue comes from upgrades and enterprise plans.
Offer professional services to help businesses integrate ClawSec into their existing bot ecosystems, including custom security policies and training. Revenue is generated through one-time project fees or ongoing retainer agreements for security oversight and incident response support.
💬 Integration Tip
Integrate ClawSec's pre-installation check into your skill installation workflow to automatically block unsafe installations, and set up scheduled audits to catch vulnerabilities in existing skills.
Scored Jun 13, 2026
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.