firm-runtime-audit-packRuntime environment and configuration audit pack. Validates Node.js version, secrets workflow, HTTP headers, allowed commands, trusted proxy, disk budget, an...
Install via ClawdBot CLI:
clawdbot install romainsantoli-web/firm-runtime-audit-packGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Mar 21, 2026
This scenario involves auditing a Node.js-based web application for runtime security compliance. The skill checks Node.js version compatibility, HTTP security headers like HSTS and CSP, and secrets handling in workflows to prevent vulnerabilities such as data leaks or injection attacks. It's ideal for ensuring applications meet security standards before deployment in production environments.
In this scenario, the skill audits cloud infrastructure configurations, including trusted proxy settings and command allowlists, to secure deployments on platforms like AWS or Azure. It helps identify misconfigurations that could lead to unauthorized access or resource abuse, ensuring infrastructure adheres to security best practices and compliance requirements.
This scenario focuses on integrating the audit pack into CI/CD pipelines to validate runtime security during automated builds. It checks secrets workflow, disk budget limits, and DM allowlist policies to catch issues early, reducing risks in continuous deployment processes and enhancing overall pipeline security and reliability.
Here, the skill is used to perform audits for regulatory compliance, such as GDPR or HIPAA, by verifying HTTP headers, proxy configurations, and session management. It helps organizations demonstrate adherence to security standards through automated checks, streamlining audit processes and reducing manual effort.
Offer this audit pack as part of a subscription-based security service for businesses using OpenClaw deployments. Provide regular runtime audits, detailed reports, and remediation advice, generating recurring revenue through monthly or annual fees while helping clients maintain secure environments.
Sell consulting services to integrate and customize the audit pack for specific client needs, such as tailored security checks or compliance support. Charge per project or hourly rates, leveraging expertise in runtime security to address unique business challenges and enhance client security postures.
Provide the basic audit pack for free to attract users, then monetize through premium features like advanced analytics, priority support, or integration with other security tools. Upsell to enterprise clients for enhanced functionality, driving revenue from upgrades and add-ons.
💬 Integration Tip
Ensure mcp-openclaw-extensions version 3.0.0 or higher is installed and configure the audit tools with correct config_path parameters for seamless integration into existing workflows.
Scored Apr 19, 2026
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Coding style memory that adapts to your preferences, conventions, and patterns for consistent coding.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.