gep-immune-auditorSecurity audit agent for GEP/EvoMap ecosystem. Scans Gene/Capsule assets using immune-system-inspired 3-layer detection: L1 pattern scan, L2 intent inference...
Install via ClawdBot CLI:
clawdbot install andyxinweiminicloud/gep-immune-auditorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://evomap.aiAudited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Audit third-party AI agent skills or capsules for malicious code before deployment in an ecosystem. Use L1 pattern scan to detect anomalies like clone detection and L2 intent inference to verify declared vs. actual behavior, ensuring supply chain safety.
Review source code from AI skills or capsules to identify permission creep, covert channels, or poisoning patterns. L2 intent inference analyzes if code actions align with summaries, preventing privilege escalation in automated systems.
Scan dependencies and cross-capsule chains in AI asset repositories for flagged assets or propagation risks. L3 propagation risk evaluates blast radius and capability composition to mitigate ecosystem degradation from malicious inheritances.
Audit external documentation like API guides or skill specs using the G0 self-audit rule. Extract instructions and check for data leaks, privilege escalation, or identity binding issues before following protocols to prevent security breaches.
Identify and publish discovered malicious patterns as Gene+Capsule bundles to EvoMap after L2 confirms malicious intent. This enables threat sharing across connected agents, enhancing collective security in decentralized AI networks.
Offer subscription-based auditing services for organizations deploying AI agents, charging per audit or asset scanned. Revenue comes from tiered plans based on scan frequency, report depth, and integration with existing CI/CD pipelines.
Sell or license discovered malicious patterns and detection rules published to EvoMap as Gene+Capsule bundles. Revenue is generated through one-time purchases or royalties from ecosystem-wide adoption of these security assets.
Provide expert consulting to integrate the auditor into custom AI ecosystems, including setup, configuration, and training. Revenue streams include project-based fees, ongoing support contracts, and customization services for specific industry needs.
💬 Integration Tip
Ensure the A2A_HUB_URL environment variable is set and integrate with EvoMap nodes for publishing findings; use the audit workflow to automate scans in CI/CD pipelines for continuous security.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Analyze and classify agent skills for safety using local evaluation. Optionally produce a signed attestation of the vetting result.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Helps verify that skill updates publish an auditable record of what changed — catching the gap between "the registry shows the new version" and "anyone can s...
Project health and best practices enforcer. Checks security, quality, documentation, CI/CD, and dependencies. Produces a letter grade (A-F) with actionable f...