exec-securityPre-execution security checker for shell commands. Detects dangerous patterns before running exec/bash tools including recursive deletion, credential leaks,...
Install via ClawdBot CLI:
clawdbot install yozu/exec-securityGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdSends data to undocumented external endpoint (potential exfiltration)
POST → https://...Potentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/sudoersGenerated May 22, 2026
A DevOps engineer automates infrastructure tasks using shell scripts. The AI agent validates that automation scripts do not contain destructive commands like rm -rf or credential leaks before execution, ensuring safe CI/CD pipelines.
A customer support agent assists users in backing up data to a cloud service. The AI checks backup commands for data exfiltration risks and ensures that no sensitive files are inadvertently uploaded.
An IT security analyst runs commands to audit system configurations. The AI blocks commands that could tamper with system files or expose credentials, while allowing safe read-only queries.
A software developer creates deployment scripts retrieved from external sources. The AI scans for download-and-execute patterns and warns about potential shell injection vulnerabilities.
Offer pre-flight security scanning as a cloud API for AI agents. Companies pay per scan or subscription to integrate command validation into their automation workflows.
License the security checker as a plugin for popular automation platforms (e.g., Jenkins, Ansible). Revenue from per-instance licensing and enterprise support contracts.
Provide the security checker as part of a compliance suite for SOC 2, HIPAA, or PCI DSS. Companies pay to automate security checks in their command execution pipelines.
💬 Integration Tip
Integrate as a middleware hook before shell execution in AI agents. Use tags to identify sensitive variables and disable checks for user-confirmed commands.
Scored Jun 19, 2026
Calls external URL not in known-safe list
https://example.com/script.shUses known external API (expected, informational)
api.github.comAI Analysis
The skill is a security validation tool designed to block dangerous commands and prevent credential leaks; it does not contain instructions to send data externally, override user intent, or harvest credentials. Its rules are defensive and focused on pre-execution safety checks, aligning with its stated purpose.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...