jason-security-auditSecurity audit for external resources (GitHub repos, downloaded skills, files). Detects malicious code, suspicious executables, and content mismatches. Use w...
Install via ClawdBot CLI:
clawdbot install ithacajason/jason-security-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/user/repo.gitAudited Apr 17, 2026 · audit v1.0
Generated Mar 22, 2026
Developers cloning GitHub repositories for integration into their projects can use this skill to automatically audit the code for malicious content before merging or executing. It ensures that external dependencies do not introduce security vulnerabilities, such as hidden executables or obfuscated payloads, by scanning file types and content patterns.
Platforms hosting AI agent skills or plugins can integrate this audit tool to vet uploaded packages from third-party authors. It checks for mismatches between README descriptions and actual code, blocks suspicious executables, and flags potential threats, enhancing trust and safety for users downloading skills from web sources.
IT departments in corporations can deploy this skill as part of their security protocols when employees download external scripts or tools from untrusted sources. It automates initial scans for red flags like base64-encoded payloads or network connections, reducing manual review time and preventing malware execution in sensitive environments.
Educators and students using online coding tutorials or repositories can run this audit to ensure downloaded materials are safe and match their described content. It helps detect fraudulent resources, such as those with misleading READMEs or hidden malicious files, protecting learning environments from security risks.
Offer a basic version of the audit skill for free to individual developers, with premium features like advanced threat detection, detailed reporting, and integration APIs for enterprises. Revenue is generated through subscription plans for teams and organizations needing enhanced security and support.
License the audit skill to companies for embedding into their internal development workflows or product platforms, such as CI/CD pipelines or app marketplaces. Revenue comes from one-time licensing fees or annual contracts based on usage scale and customization requirements.
Bundle the audit skill with professional security consulting services, where experts help clients implement and customize the tool for specific threats. Revenue is generated through service packages that include audits, training, and ongoing threat pattern updates tailored to industry needs.
💬 Integration Tip
Integrate this skill into automated workflows, such as post-clone hooks in Git or pre-execution scripts, to ensure security checks run seamlessly without manual intervention.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...