clawsec-picoclaw-self-pen-testingPicoclaw-only local posture-review skill focused on read-only findings and safe operator remediation guidance.
Install via ClawdBot CLI:
clawdbot install davida-ps/clawsec-picoclaw-self-pen-testingGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://clawsec.prompt.securityAudited Sep 7, 2026 · audit v1.0
Generated Sep 7, 2026
A SaaS company wants to ensure their internal Picoclaw deployment is not exposing the public Web UI or has disabled authentication. This scenario uses the skill to perform a local, read-only posture review of the Picoclaw profile, flagging potential security gaps before deployment.
A financial institution needs to verify that its AI agent management system meets internal security policies. The skill helps audit Picoclaw configurations for unsigned verification mode, plaintext secrets, and inadequate workspace restrictions, providing findings that support compliance audits.
A healthcare organization using Picoclaw for automation must ensure strict access controls and prevent unauthorized tooling. The skill reviews the profile for MCP trust-boundary issues and multi-channel auth requirements, helping protect sensitive patient data.
A DevOps team integrates Picoclaw into CI/CD pipelines and wants to ensure no security regressions. The skill performs a read-only posture review, checking for public exposure and scheduler persistence issues, and provides remediation guidance.
Organizations use the skill as part of their internal security review process, ensuring their AI agent configurations adhere to security best practices without external consultants.
Security consulting firms incorporate the skill into their offerings to quickly assess client Picoclaw setups and provide remediation recommendations, charging for the consulting service.
The skill is freely available on GitHub, with companies contributing improvements and adopting it to demonstrate security diligence, which may indirectly lead to paid support or enterprise features.
💬 Integration Tip
Run the skill locally with the provided Node.js script, specifying the path to the Picoclaw profile. Ensure Node.js is installed and verify the release artifacts using the provided checksum verification script to ensure integrity.
Scored Sep 7, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...