phy-graphql-schema-auditGraphQL schema static auditor. Reads any .graphql SDL file or introspection JSON to detect N+1 exposure hotspots (nested list-within-list queries with no dat...
Install via ClawdBot CLI:
clawdbot install phy041/phy-graphql-schema-auditGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://canlah.aiAudited May 20, 2026 · audit v1.0
Generated Aug 22, 2026
An e-commerce company uses GraphQL for its storefront and admin APIs. They suspect slow queries due to nested product/order relationships. The skill audits their schema, identifies N+1 hotspots, and recommends dataloader implementations to reduce database calls.
A SaaS provider offers a dashboard with complex analytics widgets. Queries can be deeply nested and unbounded, risking server overload. The skill analyzes the schema, suggests depth limits and complexity budgets, and flags missing pagination on collection fields.
A financial institution exposes transaction data via GraphQL. Security is critical. The skill checks for overly broad scalar types (like String for IDs), naming violations, and deprecated field usage to ensure compliance and reduce attack surface.
A social media startup's schema has grown organically, leading to circular type references and inconsistent naming conventions. The skill audits the schema, helping the team refactor types and maintainable conventions before scaling.
Offer the skill as a subscription service for development teams, providing automated schema audits and continuous monitoring. Revenue comes from monthly or annual subscription fees.
Use the skill to perform in-depth audits for clients as part of consulting engagements. Charge per audit or as part of broader API design consulting packages.
Provide a limited free audit (e.g., basic naming and deprecated field checks) and charge for advanced features like complexity budget recommendations, N+1 hotspot analysis, and integration with CI/CD pipelines.
💬 Integration Tip
Integrate the skill into CI/CD pipelines as a lint step to automatically audit schema changes and enforce API quality standards.
Scored May 20, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...