n0nu-security-auditLogs risky OpenClaw agent actions, conducts activity audits, and reviews OpenClaw configs for security risks without blocking operations.
Install via ClawdBot CLI:
clawdbot install n0nu/n0nu-security-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/sudoersCalls external URL not in known-safe list
https://x.com/i.shGenerated Mar 22, 2026
Used by DevOps teams to log and audit risky operations like remote code execution or bulk file deletions in CI/CD pipelines. It provides an audit trail for compliance and helps identify unauthorized actions without disrupting workflows.
Employed in financial institutions to monitor agent activities involving sensitive data access or network requests. It supports periodic audits for regulatory compliance and flags potential security breaches in automated processes.
Applied in healthcare settings to log credential access and file writes related to patient data. It aids in auditing agent actions for HIPAA compliance and detecting anomalies in system configurations.
Used by e-commerce platforms to audit external network requests and configuration changes that could indicate fraud or security vulnerabilities. It helps maintain secure transaction environments through regular activity reviews.
Implemented in educational institutions to monitor and audit agent operations on student data and system configurations. It provides logs for security reviews and helps prevent unauthorized access in academic systems.
Offered as a cloud service with tiered pricing based on log volume and audit frequency. Revenue comes from monthly subscriptions, targeting small to medium enterprises needing affordable security monitoring.
Sold as a licensed product with custom integrations and support for large organizations. Revenue is generated through one-time license fees and annual maintenance contracts, focusing on high-security industries.
Provides a free basic version for logging and simple audits, with premium features like advanced notifications and deep config audits. Revenue comes from upgrades to paid plans, appealing to startups and individual developers.
💬 Integration Tip
Integrate this skill by setting up notification configs and scheduling periodic audits via cron jobs to enhance proactive security monitoring without operational delays.
Scored Apr 19, 2026
AI Analysis
The skill is designed as an observer-only logging and auditing tool with no evidence of data exfiltration, credential harvesting, or hidden malicious instructions. The primary risk is the potential for the logging scripts to be misconfigured or for logs containing sensitive data to be stored insecurely, but the skill's core functionality aligns with its stated security auditing purpose.
Audited Apr 17, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.