morgana-mordred-security-sandboxEducational security training sandbox for AI agents. Contains 5 intentionally vulnerable systems with annotated vulnerability descriptions and tested patches...
Install via ClawdBot CLI:
clawdbot install kofna3369/morgana-mordred-security-sandboxGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
eval(AI Analysis
The skill's stated purpose is legitimate security testing, but the rule-based signals indicate it contains high-risk patterns like credential access and prompt poisoning instructions. While likely intended for a controlled sandbox, these capabilities could be misused if the skill's isolation fails or if it is deployed outside its intended context.
Generated May 7, 2026
AI agents can learn penetration testing techniques in a controlled environment with 5 vulnerable systems. Each system demonstrates a specific vulnerability type (SQL injection, sandbox escape, prompt injection, data leak, race condition) with documented exploits and ready-to-apply vaccine patches.
Security teams can use Mordred to automatically test AI agents for vulnerabilities, such as prompt injection or data leakage, before deployment. The sandbox provides a safe environment to run exploit tests and validate security patches.
Researchers can analyze the 5 vulnerable systems to understand attack vectors and develop new 'vaccine' patches. The sandbox simulates real-world security flaws, enabling rapid prototyping and testing of mitigations.
Organizations can simulate penetration tests against internal systems using the flawed_auth and data_leak modules to validate security controls. The sandbox generates reports with vulnerabilities and recommendations for auditors.
Developers of AI agents can use the prompt_injection system to test how their models handle malicious inputs. The sandbox helps ensure agents are resilient to manipulation before deployment in customer-facing applications.
Offer Mordred as a cloud-hosted service where companies pay per agent per month to test their AI agents automatically. Includes update system, reporting, and priority support.
Bundle Mordred with custom training programs for security teams, including workshops, certification, and tailored vaccine development for proprietary systems.
Release Mordred as open source (MIT), but sell premium vaccine packs for additional vulnerabilities, early access to new systems, and dedicated integration support.
💬 Integration Tip
Integrate mordred_runner.py into your CI/CD pipeline to automatically test every new AI agent version before deployment. Use the --report flag to generate JSON output for compliance tracking.
Scored May 7, 2026
Audited Apr 16, 2026 · audit v1.0
Meta-skill for AI agent self-improvement. Analyzes runtime logs to detect error patterns, regressions, and inefficiencies, then generates structured improvem...
Stop waiting for prompts. Keep working.
Turn OpenClaw into a learning-loop agent with seeded workspace rules, skill promotion, reflective memory, and proactive maintenance.
Meta-agent skill for orchestrating complex tasks through autonomous sub-agents. Decomposes macro tasks into subtasks, spawns specialized sub-agents with dynamically generated SKILL.md files, coordinates file-based communication, consolidates results, and dissolves agents upon completion. MANDATORY TRIGGERS: orchestrate, multi-agent, decompose task, spawn agents, sub-agents, parallel agents, agent coordination, task breakdown, meta-agent, agent factory, delegate tasks
Complete toolkit for creating autonomous AI agents and managing Discord channels for OpenClaw. Use when setting up multi-agent systems, creating new agents, or managing Discord channel organization.
Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentic...