code-audit-clawThree-mode code auditor for OpenClaw workspaces. (1) Security audit — finds hardcoded secrets, dangerous shell commands, SQL injection, unsafe deserializatio...
Install via ClawdBot CLI:
clawdbot install hanwenyolo-dot/code-audit-clawGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://openclaw.aiUses known external API (expected, informational)
discord.comAI Analysis
The skill is a code audit tool that appears to operate locally on user files, with no evidence of sending data to external servers. The external URL references (openclaw.ai, discord.com) are likely for documentation or known API usage, not for data exfiltration. The primary risk is the potential for destructive shell commands in its tool definitions, but the skill's rules explicitly forbid automatic execution of fixes.
Generated Mar 20, 2026
Audit an open source repository for security vulnerabilities like hardcoded secrets and SQL injection before a public release. The skill scans code files and generates a tiered HTML report to prioritize fixes, ensuring compliance with security best practices.
Perform a quality audit on a large codebase to detect dead code, magic numbers, and excessive complexity. This helps development teams reduce technical debt and improve maintainability by identifying areas for refactoring.
Use the soul audit mode to inspect OpenClaw workspace files (e.g., SOUL.md, SKILL.md) for missing safety rules, plaintext API keys, and cross-file consistency. This ensures AI agents operate safely and adhere to organizational policies.
Audit code and configuration files in regulated industries like finance or healthcare to identify vulnerabilities that could lead to data breaches. The skill outputs critical warnings for issues like unsafe deserialization, aiding in compliance audits.
Offer the code audit skill as a cloud-based service with automated weekly scans via cron. Charge a monthly fee per workspace or user, providing tiered reports and optional AI-generated analysis prompts for enhanced insights.
Provide professional services to integrate the audit skill into client development pipelines. Offer custom rule sets, training, and support for specific industries, generating revenue through project-based fees and ongoing maintenance contracts.
Distribute a free version with basic security and quality audits, while charging for advanced features like soul audit mode, AI analysis prompts, and priority support. Upsell to enterprises needing comprehensive compliance checks.
💬 Integration Tip
Integrate the skill into CI/CD pipelines by automating scans with cron jobs; use the --ai flag to generate structured prompts for deeper analysis in development workflows.
Scored Apr 19, 2026
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...