opena2a-securitySecurity hardening for OpenClaw. Audit your configuration, scan installed skills for malware, detect CVE-2026-25253, check credential exposure, and get actio...
Install via ClawdBot CLI:
clawdbot install abdelsfane/opena2a-securityGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://www.npmjs.com/package/hackmyagentAI Analysis
The skill's primary function is local security auditing using a known npm package (hackmyagent), which aligns with its stated purpose. The 'UNSAFE_SHELL' signal is likely a false positive from the scanner's own code detection, and the external URL is a public package registry, not a data exfiltration endpoint. However, the skill's broad filesystem and exec permissions require careful review of the underlying tool.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
A developer maintaining an OpenClaw instance for a community project uses this skill to regularly audit their setup for vulnerabilities like CVE-2026-25253 and scan installed skills for malware, ensuring the platform remains secure against supply-chain attacks and credential exposure without relying on external APIs.
An IT security team in a corporation deploys OpenClaw for internal automation and uses this skill to harden the configuration by checking file permissions, disabling unsafe plugins, and generating security reports in HTML format to comply with internal audit requirements and prevent data breaches.
A university lab running OpenClaw for student projects employs this skill to scan skills for malicious code patterns and audit credential storage, providing students with actionable fix recommendations to teach secure development practices and protect sensitive academic data.
A freelance consultant setting up OpenClaw for clients uses this skill to perform quick security checks and detect vulnerabilities like weak authentication or missing rate limiting, offering tailored hardening advice to improve client security postures before deployment.
A startup integrating OpenClaw into their product uses this skill to audit configuration and scan for CVE-2026-25253, ensuring compliance with security standards and mitigating risks like SSRF and command injection before launching to customers, with no external data leaks.
Offer a basic version of this skill for free to attract users, with premium features like advanced scanning rules, automated remediation scripts, or integration with CI/CD pipelines available via subscription, generating recurring revenue from enterprises and developers.
Provide paid consulting services where experts use this skill to conduct in-depth security audits for organizations, offering personalized hardening recommendations, training sessions, and ongoing support contracts, leveraging the tool's local scanning capabilities for client trust.
License this skill to large corporations for internal use, with options for white-labeling to integrate into their own security suites, generating revenue through one-time licensing fees or annual renewals based on the number of deployments and users.
💬 Integration Tip
Integrate this skill into your OpenClaw setup by ensuring Node.js and npx are installed, then use the provided commands like 'npx hackmyagent secure' for regular audits to maintain security without external dependencies.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...