page-behavior-auditDeep behavioral audit with hashed policy (CSP-compliant, no plaintext badwords)
Install via ClawdBot CLI:
clawdbot install youdaolee/page-behavior-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses system directories or attempts privilege escalation
sudo cpCalls external URL not in known-safe list
https://github.com/openclaw/page-behavior-auditUses known external API (expected, informational)
qyapi.weixin.qq.comAudited Apr 17, 2026 · audit v1.0
Generated Mar 22, 2026
Audit product pages for malicious redirects, content policy violations, and SSRF risks to protect customer data and ensure compliance. Use screenshots and HAR files for forensic analysis after security incidents.
Scan banking or investment websites for unauthorized content, detect XML-based attacks like XXE, and generate audit logs for regulatory reporting. WeCom alerts notify teams of critical vulnerabilities in real-time.
Audit patient portals and healthcare sites for sensitive data leaks, monitor redirects to prevent phishing, and enforce content policies using hashed badwords to maintain privacy standards.
Scan educational websites for inappropriate content, track redirects to unsafe domains, and use screenshots to document issues for content moderation teams. HAR exports aid in debugging performance problems.
Perform deep behavioral audits on government portals to detect SSRF/XXE threats, ensure CSP compliance, and generate detailed reports with screenshots and logs for security audits and incident response.
Offer this skill as part of a subscription-based security service, providing automated audits, alerts, and compliance reports to clients. Revenue comes from monthly or annual licensing fees based on usage volume.
Integrate the skill into managed services for continuous monitoring of client websites, with WeCom alerts enabling rapid response. Revenue is generated through service contracts and incident response fees.
Use the skill in security consulting engagements to conduct in-depth audits, provide detailed reports with screenshots and HAR files, and offer remediation advice. Revenue comes from project-based fees and retainer agreements.
💬 Integration Tip
Set up environment variables like WECOM_WEBHOOK_URL for alerts and use the webhook or CLI for easy automation in CI/CD pipelines.
Scored May 17, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...