openclaw-sec-plusAI Agent Security Suite - Real-time protection against prompt injection, command injection, SSRF, path traversal, secrets exposure, and content policy violat...
Install via ClawdBot CLI:
clawdbot install lockdown56/openclaw-sec-plusGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"Ignore all previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
webhook → https://hooks.slack.com/services/...Hardcoded API key or token pattern found in skill definition
sk-xxxxxxxxx...Generated May 9, 2026
A company deploys an internal AI assistant that employees interact with via natural language. Openclaw-sec validates all inputs to prevent prompt injection attacks that could leak sensitive data or override system instructions.
A DevOps team uses an AI agent to execute shell commands for infrastructure management. The skill validates commands in real-time, blocking dangerous patterns like 'rm -rf' or directory traversal, ensuring safe automation.
A bank integrates an AI chatbot to handle customer queries. Openclaw-sec scans URLs and content for SSRF attempts or secrets exposure, preventing attacks on internal systems and protecting customer data.
A healthcare provider uses AI to process patient records. The skill validates file paths and scans content for PHI/PII leakage, ensuring compliance with HIPAA and preventing unauthorized data access.
An online retailer deploys an AI agent to handle returns and refunds. Openclaw-sec blocks malicious inputs like command injection or policy violations, reducing fraud and maintaining secure transactions.
Offer the security suite as a cloud service where customers pay per API call or per active user. This model scales with customer adoption and provides predictable recurring revenue.
License the software to enterprises that require on-premise deployment for data sovereignty or latency reasons. Includes annual maintenance and support contracts.
Provide basic validation for free (e.g., prompt injection only) and charge for advanced modules like secrets detection, SSRF, and content scanning. Upsell based on detected threats.
💬 Integration Tip
Use the CLI or API with automatic hooks to wrap your existing AI agent pipeline — the skill is designed to be dropped in with minimal configuration.
Scored Jun 29, 2026
Potentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/hostsCalls external URL not in known-safe list
https://example.comUses known external API (expected, informational)
slack.comAudited Apr 18, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...