flyai-env-guardianProtect sensitive environment variables from accidental exposure in commits, logs, and CI pipelines with automated scanning and pre-commit validation.
Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
http://internal-api.corp:8080Audited Apr 17, 2026 · audit v1.0
Generated May 10, 2026
A developer is about to commit code that accidentally includes hardcoded API keys. The skill scans staged files, blocks the commit, and suggests moving secrets to .env files for secure management.
When starting a new project, this skill helps establish secure .env file patterns including .env.example and .env.test templates, ensuring teams adopt best practices from the beginning.
A security team audits an existing codebase for exposed credentials like database passwords or private keys. The skill performs deep git history scans and reports all critical finds.
Integrate with GitHub Actions to validate that no .env files are in build artifacts and that required environment variables are set. The skill checks PR diffs for new secrets.
Before deploying a Docker container, the skill scans the image for embedded credentials, ensuring that secrets are not hardcoded and are instead managed via Docker secrets or runtime .env mounts.
Offer a free tier for individual developers with basic scanning capabilities, and a premium plan with advanced features like CI/CD integration, custom patterns, and team dashboards.
Pitch the skill as an add-on to existing CI/CD platforms (GitHub Actions, GitLab CI) for enterprises needing compliance with SOC2, HIPAA, or GDPR secret management requirements.
Combine the scanning tool with manual security audits, remediation workshops, and custom policy creation for organizations with legacy codebases needing thorough secret cleanup.
💬 Integration Tip
Add the skill as a pre-commit hook via .git/hooks/pre-commit and configure .envguardian.json for custom patterns; for CI, use GitHub Actions by adding a workflow step that runs flyai env-guardian scan --ci.
Scored May 10, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...