code-securityReview code for security risks like injection, auth flaws, sensitive data leaks, and recommend precise, actionable fixes with risk levels and patches.
Install via ClawdBot CLI:
clawdbot install sf0799/code-securityGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated May 9, 2026
Conduct a comprehensive security review of a web application's source code to identify vulnerabilities like SQL injection, XSS, and authentication flaws. The skill analyzes input handling, session management, and data storage to provide prioritized risk assessments and fix suggestions.
Rewrite critical code sections in a fintech application to eliminate security issues such as insecure deserialization and sensitive data exposure. The skill ensures that the new code adheres to security best practices and includes patches for identified risks.
Review access control and permission logic in a multi-tenant SaaS platform to prevent privilege escalation and unauthorized data access. The skill evaluates authorization mechanisms and produces remediation steps, including code patches for robust role-based access control (RBAC).
Audit input handling in an e-commerce platform to prevent path traversal and command injection attacks. The skill identifies trust boundaries and user input points, assesses impact, and provides fixes such as input sanitization and parameterized queries.
Examine code repositories for hardcoded secrets, API keys, and credentials that pose leak risks. The skill flags such exposures, evaluates their exploitability, and recommends secure storage solutions like vaults or environment variables with code patches.
Offer periodic code security audits to software development teams on a subscription basis. The service includes risk assessment reports and prioritized fix recommendations, helping clients maintain compliance and reduce breach risks.
Provide expert consulting for integrating security into the SDLC, including code reviews and secure rewrite services. This model targets companies needing specialized security expertise for specific projects without hiring full-time staff.
Integrate the skill into CI/CD pipelines as part of a broader DevSecOps platform, offering automated security checks before deployment. This can be monetized through per-seat or per-scan pricing.
💬 Integration Tip
Run the skill on your codebase directory; for best results, ensure code is well-structured and includes comments for context. Use in a CI pipeline to catch issues early.
Scored May 9, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...