pre-publish-securityMulti-layered security audit system for GitHub/ClawHub releases. Prevents credential leaks, detects vulnerabilities, validates documentation. Frequency-aware...
Install via ClawdBot CLI:
clawdbot install solmas/pre-publish-securityGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/solmas/openclaw-pre-publish-securityAI Analysis
The skill's primary function is local security auditing of git repositories and dependencies, aligning with its stated purpose. The external URL reference is to its own public GitHub repository for installation/updates, which is a common and low-risk pattern. The flagged 'UNSAFE_SHELL' signal is a design concern within the tool's own code, not an active risk to the user's system or data exfiltration.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 22, 2026
Maintainers of open-source repositories use this skill to automatically scan every push for exposed credentials and vulnerabilities, preventing accidental leaks from contributors. It integrates with Git hooks to block risky commits and runs scheduled deep scans to audit historical commits and dependencies, ensuring long-term security compliance.
Development teams in enterprises deploy this skill in CI/CD pipelines to enforce security checks before code merges and releases. It scans for secrets in code, validates documentation, and checks dependencies for CVEs, reducing the risk of data breaches and ensuring adherence to internal security policies.
DevOps engineers use this skill to secure infrastructure-as-code repositories by scanning for hardcoded secrets in configuration files and scripts. It automates weekly dependency audits and history scans to detect vulnerabilities in tools like Terraform or Ansible, enhancing cloud security posture.
Institutions teaching coding or security courses integrate this skill to help students learn secure coding practices by automatically flagging issues like exposed API keys or unsafe patterns in their projects. It provides actionable feedback through reports, making it a practical tool for hands-on learning.
Freelance developers install this skill as a pre-push hook to protect client repositories from accidental credential exposure during rapid development cycles. It runs quick scans on every push and full audits before delivery, ensuring deliverables are secure and professional.
Offer a free version with basic scanning and Git hook integration, then charge for advanced features like real-time monitoring, detailed analytics dashboards, or priority support. Revenue can come from subscription tiers for teams or enterprises needing enhanced security tools.
Sell customized licenses to large organizations for integration into their proprietary systems, with added features like compliance reporting, API access, and dedicated support. Revenue is generated through annual contracts based on the number of repositories or users.
Provide paid consulting services to help companies set up and customize the skill for their specific workflows, including training, CI/CD pipeline integration, and security audits. Revenue comes from one-time project fees or ongoing retainer agreements for maintenance.
💬 Integration Tip
Start by installing the pre-push hook with install-hooks.sh for automatic protection on every Git push, then use schedule.sh to set up weekly cron jobs for dependency and history scans to maintain ongoing security.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...