safe-guardClaude Code / OpenClaw Skill 安全防护工具。 三大能力:(1) 始终生效的 PreToolUse Hook,拦截高危操作; (2) 静态正则 + LLM 语义审计的深度扫描; (3) 沙盒隔离环境运行脚本并监控行为。 支持 scan-only、safe-run、sandbox-test...
Install via ClawdBot CLI:
clawdbot install igloomatics/safe-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
exec (Accesses system directories or attempts privilege escalation
/etc/hostsCalls external URL not in known-safe list
https://github.com/x/yAI Analysis
The skill contains potentially destructive shell commands (exec()) and attempts to access system directories like /etc/hosts, indicating privilege escalation risks. While no confirmed data exfiltration patterns were found, the combination of unsafe shell operations and system file access creates a meaningful security risk that requires user awareness.
Generated May 9, 2026
在安装或使用来自市场的第三方AI Skill前,使用safe-guard进行自动化安全扫描和LLM语义审计,确保没有恶意代码或隐藏行为。适用于团队引入外部Skill时的审核流程。
开发团队内部编写的AI Skill需要统一安全检查,safe-guard可扫描所有文件、分析权限和数据流,确保符合公司安全规范,防止敏感信息泄露。
在沙盒环境中运行可疑Skill,监控其对网络和文件系统的访问行为,评估其实际威胁等级,避免在真实环境中触发恶意操作。
将safe-guard集成到CI/CD流水线中,每当有新的Skill提交或更新时自动触发扫描和审计,阻止不安全的Skill进入生产环境,实现DevSecOps。
对通过URL获取的远程Skill进行临时克隆和扫描,评估其安全性后决定是否安装,避免引入未知风险的第三方扩展。
提供基础的安全扫描和静态分析免费,高级功能如LLM语义审计、沙盒测试和详细报告需订阅付费。适用于中小企业安全需求。
面向大型企业提供定制化安装、私有化部署、策略配置和持续安全运营支持。按用户数或Skill数收取许可费。
构建在线平台,用户上传Skill即时获取审计报告,按报告次数或服务包收费。可附加人工专家复审服务。
💬 Integration Tip
将safe-guard的脚本路径添加到环境变量,在CI脚本中直接调用静态扫描和沙盒测试命令即可快速集成。
Scored May 9, 2026
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...