ecap-security-auditorSecurity audit framework for AI agent skills, MCP servers, and packages. Your LLM does the analysis — we provide structure, prompts, and a shared trust database.
Install via ClawdBot CLI:
clawdbot install starbuck100/ecap-security-auditorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
POST → https://skillaudit-api.vercel.app/api/findings/ECAP-2026-0777/reviewPotentially destructive shell commands in tool definitions
Generated Mar 1, 2026
A studio building custom AI agents for clients needs to ensure all third-party skills and MCP servers are secure before integration. The Security Gate automatically audits each component during development, preventing vulnerabilities from entering production environments.
A large corporation deploying AI agents across departments uses this skill to verify internal and external packages. It enforces security policies by blocking high-risk installations and logging audits for compliance reporting.
Maintainers of AI agent skills or MCP servers use the audit framework to self-assess their packages before release. They run integrity checks and submit findings to the trust registry to build user confidence and transparency.
An online platform teaching AI agent development integrates this skill to provide students with real-time security feedback. It helps learners understand risks in packages they install, fostering best practices from the start.
A consultant auditing client AI systems uses this skill to quickly assess installed packages and MCP servers for vulnerabilities. The automated gate streamlines initial checks, allowing deeper manual audits on flagged items.
Offer basic audit queries and integrity checks for free, with premium features like detailed reporting, historical data, and priority support via subscription. Revenue comes from monthly plans for enterprises and heavy users.
License the audit framework to AI platforms or development tools, allowing them to embed security gates under their own branding. Revenue is generated through licensing fees and customization services.
Provide official security certifications for packages that pass audits, displayed as trust badges. Charge package maintainers for certification reviews and ongoing monitoring, creating a trusted marketplace.
💬 Integration Tip
Integrate the Security Gate into existing CLI tools or CI/CD pipelines using the provided bash scripts and API endpoints for automated checks during package installation or deployment.
Scored Apr 19, 2026
rm -rf /Calls external URL not in known-safe list
https://skillaudit-api.vercel.app/api/findings?package=PACKAGE_NAMEAI Analysis
The skill's stated purpose is security auditing, which justifies external API calls, but it accesses sensitive files (~/.ssh/id_rsa) and contains prompt-override instructions, creating a dual-use risk. The external endpoint is undocumented and could be a data sink, though it appears consistent with the audit function.
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.