ictSecurity audit tool for Claw Skills - NOT malicious. This tool contains detection rules (eval, exec, subprocess, etc.) for scanning skills, these are securit...
Install via ClawdBot CLI:
clawdbot install vimvem/ictGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Hardcoded API key or token pattern found in skill definition
ghp_xxxxxxxx...Potentially destructive shell commands in tool definitions
curl | bashGenerated Sep 30, 2026
Integrate the ict skill into a CI/CD pipeline to automatically audit every skill package before deployment. Use the exit codes (0=PASS, 1=REVIEW, 2=FAIL) to gate releases and prevent malicious code from reaching production.
Skill marketplace operators can run batch scans with `--all` to vet submitted skills before listing them. The global security report identifies risky packages so they can be quarantined or rejected.
Security teams can perform recurring audits across all internally developed skills, track trust scores over time with `--save-trend` and `--trend`, and enforce minimum grade thresholds for internal deployment.
Maintainers of open-source skill repositories can use the `--diff` feature to compare pull request versions against the main branch, quickly spotting newly introduced security patterns or regressions.
Organizations subject to SOC 2, ISO 27001, or similar frameworks can generate consistent JSON audit reports for each skill, providing documented evidence of due diligence in third-party code review.
Offer the core auditing engine for free while selling curated rule packs (e.g., industry-specific compliance checks, advanced exfiltration signatures) and team dashboards as add-ons.
Provide a hosted platform that continuously scans an organization's installed skills, stores historical trends, and sends alerts on newly discovered vulnerabilities, reducing the need for in-house security expertise.
Sell enterprise support contracts that include custom rule development, integration with existing SIEM/SOAR tools, and prioritized updates for emerging threats, targeting large organizations with strict security requirements.
💬 Integration Tip
Wrap the CLI in a pre-commit hook or CI step using the exit codes to fail builds; parse the JSON output to feed dashboards or ticketing systems for automated triage.
Scored Sep 30, 2026
Calls external URL not in known-safe list
https://api.clawhub.ai/skills/ictAudited Apr 18, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...