sec-audit对 OpenClaw 部署进行只读安全审计,检测环境泄露、认证配置、恶意 Skill 等已知风险和漏洞。
Install via ClawdBot CLI:
clawdbot install nx4dm1n/sec-auditGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/shadowPotentially destructive shell commands in tool definitions
eval(AI Analysis
The skill is a legitimate security auditing tool designed to perform read-only scans for vulnerabilities within the OpenClaw deployment itself. It does not exfiltrate data, contains no hidden instructions, and its stated purpose aligns with its defined functions. The rule-based signals appear to be false positives from generic pattern matching on terms like 'shadow' and 'eval' within its detection logic.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 20, 2026
Integrate the sec-audit skill into CI/CD pipelines for automated security checks during deployment. It scans OpenClaw environments for vulnerabilities like exposed API keys and misconfigurations before production release, ensuring compliance with security standards.
Use the skill to perform regular security audits in financial institutions deploying OpenClaw. It detects issues such as plaintext credential storage and missing authentication, helping meet regulatory requirements like GDPR or PCI-DSS by identifying and documenting risks.
Deploy the skill to scan for malicious skills and indicators of compromise (IOCs) in corporate OpenClaw setups. It identifies threats like hidden Base64 commands and known malicious authors, enabling proactive threat hunting and incident response.
Utilize the skill in cybersecurity training programs to teach students about vulnerability detection in AI systems. It provides hands-on experience with audit tools, covering topics from environment variable leaks to sandbox configuration checks.
Offer the sec-audit skill as part of a subscription-based security platform for OpenClaw users. Provide automated scanning, detailed reports, and remediation guidance, generating revenue through monthly or annual licenses.
Provide security auditing services using the skill to assess and improve OpenClaw deployments for clients. Offer customized audits, compliance support, and training sessions, charging on a project or hourly basis.
Release the sec-audit skill as open-source to build community trust, while offering premium features like advanced reporting, integration APIs, and priority support. Monetize through paid upgrades and enterprise support packages.
💬 Integration Tip
Run the skill in a test environment first to validate outputs before integrating into production pipelines, ensuring it aligns with existing security workflows.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...