frontend-security-review前端代码安全审查,检测 XSS、CSRF、敏感数据泄露、不安全的用户输入处理和依赖风险,并将报告保存为 Markdown 文件。当用户要求安全检查、安全审查,或代码涉及用户输入、认证、支付、文件上传等敏感操作时自动激活。
Install via ClawdBot CLI:
clawdbot install bovinphang/frontend-security-reviewGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Apr 18, 2026
Review frontend code for payment processing, user input forms, and token handling in checkout flows to prevent XSS and CSRF attacks that could compromise financial transactions.
Audit authentication logic, sensitive data display, and file upload features in patient portals to ensure compliance with privacy regulations and prevent data leaks.
Examine code for account management, transaction confirmations, and third-party script integrations to mitigate risks like token theft and unauthorized access.
Assess dynamic content rendering, user-generated input handling, and dependency security to protect against XSS and malicious script injections in social feeds.
Review admin interfaces for user management, sensitive operations like deletions, and API key usage to enforce CSRF protection and secure data storage.
Offer recurring security review services for companies needing continuous frontend code monitoring, generating revenue through monthly or annual subscription fees.
Provide one-time security assessments for specific projects or PR reviews, charging fixed fees based on codebase size and complexity.
License the skill to IDE or CI/CD platforms, earning revenue through integration fees or usage-based pricing for automated security checks in developer workflows.
💬 Integration Tip
Integrate this skill into CI/CD pipelines to automatically trigger security reviews on code commits, ensuring continuous compliance without manual intervention.
Scored Jul 2, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...