frontend-security-review前端代码安全审查,检测 XSS、CSRF、敏感数据泄露、不安全的用户输入处理和依赖风险,并将报告保存为 Markdown 文件。当用户要求安全检查、安全审查,或代码涉及用户输入、认证、支付、文件上传等敏感操作时自动激活。
Install via ClawdBot CLI:
clawdbot install bovinphang/frontend-security-reviewGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Apr 18, 2026
Review frontend code for payment processing, user input forms, and token handling in checkout flows to prevent XSS and CSRF attacks that could compromise financial transactions.
Audit authentication logic, sensitive data display, and file upload features in patient portals to ensure compliance with privacy regulations and prevent data leaks.
Examine code for account management, transaction confirmations, and third-party script integrations to mitigate risks like token theft and unauthorized access.
Assess dynamic content rendering, user-generated input handling, and dependency security to protect against XSS and malicious script injections in social feeds.
Review admin interfaces for user management, sensitive operations like deletions, and API key usage to enforce CSRF protection and secure data storage.
Offer recurring security review services for companies needing continuous frontend code monitoring, generating revenue through monthly or annual subscription fees.
Provide one-time security assessments for specific projects or PR reviews, charging fixed fees based on codebase size and complexity.
License the skill to IDE or CI/CD platforms, earning revenue through integration fees or usage-based pricing for automated security checks in developer workflows.
💬 Integration Tip
Integrate this skill into CI/CD pipelines to automatically trigger security reviews on code commits, ensuring continuous compliance without manual intervention.
Scored Apr 19, 2026
Security vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated code, exfiltration. Risk classification L...
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Audit a user's current AI tool stack. Score each tool by ROI, identify redundancies, gaps, and upgrade opportunities. Produces a structured report with score...
Detect anomalies and outliers in construction data: unusual costs, schedule variances, productivity spikes. Statistical and ML-based detection methods.