huo15-openclaw-security-review对当前分支的 pending changes 做安全评审,命中密钥泄露 / SQL 注入 / XSS / SSRF / 权限绕过 / 危险依赖 六大类漏洞后出分级报告,再在用户批准下修复。用于 PR 合并前、对外开源前、线上事故后复盘。触发词:安全评审、security review、漏洞检查、密钥扫描、我的代码...
Install via ClawdBot CLI:
clawdbot install zhaobod1/huo15-openclaw-security-reviewGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
exec(Calls external URL not in known-safe list
https://...`Audited Apr 25, 2026 · audit v1.0
Generated May 20, 2026
Before merging a pull request, automatically scan all changed files for six categories of vulnerabilities including secrets, injection, and XSS. Outputs a graded report with CWE references and repairs only after user approval.
Before open-sourcing a private repository, scan for hardcoded API keys, passwords, and other sensitive information in the commit history. Provides commands to scrub secrets without automatically altering Git history.
After a security incident, review the current branch for similar vulnerabilities. Reuses the same scanning matrix to identify residual risks and generate a prioritized fix list.
As part of a CI/CD pipeline, run the skill on the release branch to ensure no known dependency with a CVE is introduced, no IDOR endpoints are exposed, and no secrets are leaked before production deployment.
Offer basic scanning (e.g., 50 scans/month) for free to individual developers, with unlimited scans, prioritized reports, and integration support for teams and enterprises on paid plans.
Provide a managed service where security experts use the tool to conduct in-depth audits for enterprise clients, including custom rules and remediation handholding.
Package the skill as a plugin for popular CI/CD platforms (GitHub Actions, GitLab CI, Jenkins) and charge per execution or via a marketplace subscription.
💬 Integration Tip
Integrate into CI by calling the skill on git diff before merge. For direct use, type 'security review' in chat to analyze pending changes.
Scored May 20, 2026
Transform AI agents from task-followers into proactive partners that anticipate needs and continuously improve. Now with WAL Protocol, Working Buffer, Autonomous Crons, and battle-tested patterns. Part of the Hal Stack 🦞
Use the ClawdHub CLI to search, install, update, and publish agent skills from clawdhub.com. Use when you need to fetch new skills on the fly, sync installed skills to latest or a specific version, or publish new/updated skill folders with the npm-installed clawdhub CLI.
Mission control dashboard for OpenClaw - real-time session monitoring, LLM usage tracking, cost intelligence, and system vitals. View all your AI agents in o...
Transcribe YouTube videos to text by extracting captions and subtitles directly from the video URL using yt-dlp without audio processing.
Manage a self-hosted Trello-like board via `wekancli`. Create, move and archive cards, lists and boards on a WeKan server. Use when user asks about task boar...
Proactive security monitoring, threat scanning, and auto-remediation for OpenClaw deployments