nyx-archive-skill-security-protocolTeach your AI agent to think about security. A reasoning methodology for vetting skills before installation — red/green flag heuristics, 4-phase audit protoc...
Install via ClawdBot CLI:
clawdbot install nyxur42/nyx-archive-skill-security-protocolGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
curl ... \| bashAccesses system directories or attempts privilege escalation
/etc/hostsCalls external URL not in known-safe list
https://clawhub.comGenerated Mar 21, 2026
A company deploys AI agents to automate internal workflows, such as data analysis or customer support. The security protocol ensures agents vet third-party skills before installation, preventing malicious code from compromising sensitive corporate data or systems. This is critical in regulated industries like finance or healthcare where data breaches have severe consequences.
A platform hosting AI skills for public use, similar to ClawHub, integrates this protocol to help users assess skill safety. It reduces the risk of distributing harmful skills, building trust in the ecosystem and encouraging adoption. This is essential for maintaining a secure and reliable marketplace for AI tools.
Institutions teaching AI development use this skill to train students on security best practices. Students learn to audit skills systematically, applying red/green flag analysis to real-world examples, preparing them for careers in AI safety and cybersecurity. This hands-on approach enhances practical learning outcomes.
A consultant helps clients customize AI agents with specific skills, using this protocol to verify each addition for safety. This prevents vulnerabilities in client systems, ensuring reliable automation without exposing them to risks like data theft or unauthorized access. It adds value by providing a security-focused service layer.
In smart home or industrial IoT setups, AI agents manage device interactions and updates. This protocol vets skills that control devices, preventing malicious scripts from altering configurations or exfiltrating data, crucial for maintaining operational integrity and privacy in connected environments.
Offer a basic version of the protocol for free to attract users, with premium features like advanced audit reports or integration APIs for a subscription fee. This model leverages the growing demand for AI security tools, generating recurring revenue from enterprises and developers seeking enhanced protection.
Provide expert services to organizations for implementing and customizing the security protocol, including workshops, audits, and support. This capitalizes on the need for specialized knowledge in AI safety, with revenue from hourly rates or project-based contracts, especially in high-stakes industries.
Partner with AI platform providers to embed the protocol directly into their ecosystems, earning revenue through licensing fees or revenue-sharing agreements. This model expands reach by leveraging existing user bases, while providing added value through built-in security features for skill vetting.
💬 Integration Tip
Integrate this protocol early in the skill installation workflow, using its commands like /security vet to automate audits and provide clear reports to users for transparent decision-making.
Scored Jun 19, 2026
Audited Apr 17, 2026 · audit v1.0
This skill produces a DESCRIPTIVE Git-history reflection report. It is intended ONLY for: (a) a developer running it on their own repository for self-reflect...
Connect to external services through Maton-managed API routes. Use this skill only after the user names the target app, account, and task. Start with read/li...
Ad intelligence & app analytics assistant. Search ad creatives, analyze apps, view rankings, track downloads/revenue, and get market insights. Get your API k...
Write and run tests across languages and frameworks. Use when setting up test suites, writing unit/integration/E2E tests, measuring coverage, mocking dependencies, or debugging test failures. Covers Node.js (Jest/Vitest), Python (pytest), Go, Rust, and Bash.
Tally API integration with managed OAuth. Manage forms, submissions, workspaces, webhooks, organization users, and organization invites. All write operations...
Build, debug, and deploy websites using HTML, CSS, JavaScript, and modern frameworks following production best practices.