pre-install-security-checkPre-installation security verification for external code and dependencies. Automated risk analysis for GitHub repos, npm packages, PyPI libraries, and she...
Install via ClawdBot CLI:
clawdbot install gawezepobi09-debug/pre-install-security-checkGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
Report → https://github.com/gawezepobi09-debug/security-check-skill/issuesPotentially destructive shell commands in tool definitions
curl <url> | bashCalls external URL not in known-safe list
https://github.com/user/repoUses known external API (expected, informational)
api.github.comGenerated Mar 21, 2026
Developers integrating third-party libraries into new projects can use this skill to vet dependencies before installation, ensuring they meet security standards and reducing supply chain risks. It automatically checks npm or PyPI packages for known vulnerabilities and activity levels, providing risk scores to guide safe adoption.
In CI/CD pipelines, this skill can be integrated to scan GitHub repositories or packages during build processes, flagging high-risk dependencies before deployment. It helps enforce security policies by requiring manual approval for risky items, preventing vulnerable code from reaching production environments.
Students and educators in coding bootcamps or universities can use this skill to learn about security best practices when downloading external code. It provides real-time feedback on risk factors like license compliance and CVE history, fostering awareness of safe dependency management in early development stages.
Freelancers working on client projects can leverage this skill to quickly assess the security of required libraries or scripts before installation, ensuring they don't introduce vulnerabilities. It saves time by automating checks across GitHub, npm, and PyPI sources, with actionable recommendations for safer alternatives.
IT teams evaluating open-source software for enterprise use can run this skill to audit GitHub repositories or packages, checking for maintenance activity and security issues. It supports decision-making by providing risk levels and summaries, helping comply with internal security policies during procurement reviews.
Offer a free basic version with limited API calls and risk checks, then charge for premium features like advanced pattern detection, CI/CD integration, and priority support. Revenue comes from monthly subscriptions tailored to individual developers, teams, or enterprises, scaling with usage and enhanced security metrics.
Sell annual licenses to large organizations for on-premises deployment or cloud-based integration, including custom thresholds, private registry support, and dedicated security updates. Revenue is generated through upfront licensing fees and optional consulting services for setup and training, targeting sectors with strict compliance needs.
Monetize the underlying security APIs by offering them to other developers or platforms, charging per API call for vulnerability checks and risk scoring. Revenue streams include pay-as-you-go pricing and bulk discounts, enabling integration into third-party tools like IDEs or package managers without full skill adoption.
💬 Integration Tip
Start by integrating with GitHub API for repo checks, as it's widely used and provides rich metrics; ensure to implement rate limiting to avoid hitting API quotas during frequent scans.
Scored Jun 19, 2026
AI Analysis
The skill's external API calls (e.g., api.github.com, CVE databases) are consistent with its stated purpose of pre-installation security verification. The 'UNKNOWN_DATA_SINK' signal appears to be a false positive referencing the skill's own issue tracker, not an exfiltration endpoint. The 'UNSAFE_SHELL' signal is an example of dangerous commands the skill is designed to warn against, not execute.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...