flyai-env-guardianProtect sensitive environment variables from accidental exposure in commits, logs, and CI pipelines with automated scanning and pre-commit validation.
Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
http://internal-api.corp:8080Audited Apr 17, 2026 · audit v1.0
Generated May 10, 2026
A developer is about to commit code that accidentally includes hardcoded API keys. The skill scans staged files, blocks the commit, and suggests moving secrets to .env files for secure management.
When starting a new project, this skill helps establish secure .env file patterns including .env.example and .env.test templates, ensuring teams adopt best practices from the beginning.
A security team audits an existing codebase for exposed credentials like database passwords or private keys. The skill performs deep git history scans and reports all critical finds.
Integrate with GitHub Actions to validate that no .env files are in build artifacts and that required environment variables are set. The skill checks PR diffs for new secrets.
Before deploying a Docker container, the skill scans the image for embedded credentials, ensuring that secrets are not hardcoded and are instead managed via Docker secrets or runtime .env mounts.
Offer a free tier for individual developers with basic scanning capabilities, and a premium plan with advanced features like CI/CD integration, custom patterns, and team dashboards.
Pitch the skill as an add-on to existing CI/CD platforms (GitHub Actions, GitLab CI) for enterprises needing compliance with SOC2, HIPAA, or GDPR secret management requirements.
Combine the scanning tool with manual security audits, remediation workshops, and custom policy creation for organizations with legacy codebases needing thorough secret cleanup.
💬 Integration Tip
Add the skill as a pre-commit hook via .git/hooks/pre-commit and configure .envguardian.json for custom patterns; for CI, use GitHub Actions by adding a workflow step that runs flyai env-guardian scan --ci.
Scored May 10, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Detect anomalies and outliers in construction data: unusual costs, schedule variances, productivity spikes. Statistical and ML-based detection methods.
无损回忆技能。对对话或会话记录做本地蒸馏,提取身份信息、偏好、任务和长期知识,剔除噪声并保留可追溯日志。
Analyze and classify agent skills for safety using local evaluation. Optionally produce a signed attestation of the vetting result.