jasonlai-security-auditSecurity audit for external resources (GitHub repos, downloaded skills, files). Detects malicious code, suspicious executables, and content mismatches. Use w...
Install via ClawdBot CLI:
clawdbot install ithacajason/jasonlai-security-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/user/repo.gitAudited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Developers frequently clone GitHub repositories for evaluation or contribution. This skill automatically audits new clones to detect malicious code, suspicious executables, and content mismatches, ensuring safe integration into development environments before any execution.
When users download and install skills from external sources like clawhub or the web, this skill runs post-installation to verify file integrity and flag high-risk elements like obfuscated scripts or mismatched READMEs, preventing potential security breaches in AI agent ecosystems.
Integrate this skill into continuous integration pipelines to audit external dependencies or scripts before deployment. It checks for suspicious patterns like base64 payloads or shellcode, providing automated security gates that reduce risks in production environments.
Educators and students downloading coding tutorials or sample projects from untrusted websites can use this skill to scan files for executable risks and content anomalies, ensuring learning materials are safe and free from hidden malware before use in classrooms.
Freelancers receiving code or scripts from clients for modification or execution can audit the files to detect high-risk elements like unknown binaries or encrypted content, protecting their systems and maintaining trust before starting work on external projects.
Offer a basic version for free with core audit features, targeting individual developers and small teams. Monetize through premium tiers that include advanced threat detection, automated reporting, and integration with popular platforms like GitHub Actions or Slack, generating revenue from subscriptions.
License this skill as part of a broader security suite for large organizations, providing custom rules, compliance reporting, and dedicated support. Integrate with existing DevOps tools to enhance security workflows, with revenue from annual enterprise contracts and service fees.
Sell this skill on AI agent marketplaces like clawhub or similar platforms, where users can purchase it as a one-time or subscription-based add-on. Bundle it with other security tools or offer updates for new threat patterns, driving revenue from direct sales and commissions.
💬 Integration Tip
Automate this skill by adding it to post-clone hooks in git or pre-execution scripts in workflows, ensuring it runs seamlessly without manual intervention for consistent security checks.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...