security-audit-toolsInspect third-party Claude/OpenClaw/Codex/OpenCode skills, plugins, repos, npm packages, pip packages, shell installers, and GitHub Actions before any downlo...
Install via ClawdBot CLI:
clawdbot install luojin520520/security-audit-toolsGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
curl ... | sh`, `wget ... | bashCalls external URL not in known-safe list
https://registry.npmjs.org/package/versionUses known external API (expected, informational)
api.github.comAI Analysis
This skill definition is a security auditing tool designed to inspect third-party packages and installations for malicious patterns. It explicitly prohibits credential harvesting, data exfiltration, and unsafe behaviors, and its external API calls (e.g., npmjs.org, api.github.com) are standard for package reputation checks and are consistent with its stated security purpose.
Generated Mar 21, 2026
A developer wants to integrate a third-party npm package into their Node.js application for enhanced functionality. The skill automatically triggers to audit the package's source code, dependencies, and installation scripts before allowing the npm install command, preventing potential supply chain attacks like dependency confusion or malicious scripts.
A data scientist intends to clone a machine learning repository from GitHub to replicate a research paper's results. The skill performs a pre-download inspection of the repository's code, checking for obfuscated code or suspicious shell scripts in workflows, ensuring safe cloning without executing any malicious install hooks.
A DevOps engineer updates a CI/CD pipeline to include a new GitHub Action for automated testing. The skill audits the Action's YAML files and associated scripts for unsafe patterns like remote command execution or credential theft, blocking integration if high-risk elements are detected to secure the deployment process.
An analyst needs to install a Python library from PyPI for data visualization in a Jupyter notebook. The skill inspects the pip package's source code and metadata, verifying it lacks hard-coded API keys or data exfiltration code, and recommends version locking to maintain security post-installation.
A developer adds a new plugin to their IDE from a third-party marketplace to boost productivity. The skill reviews the plugin's source files and lifecycle hooks for prompt-injection-to-shell patterns or wallet theft code, escalating for manual review if medium-risk issues are found before installation proceeds.
Offer this skill as part of a cloud-based security platform where users upload code or package names for automated audits. Revenue is generated through subscription tiers based on audit depth, number of scans per month, and integration with CI/CD tools like Jenkins or GitHub Actions.
License the skill to large enterprises for integration into their internal development pipelines, providing customized audits for proprietary code and third-party dependencies. Revenue comes from one-time licensing fees, annual maintenance contracts, and premium support for high-risk scenarios.
Provide a free version with basic quick scans for individual developers, while charging for advanced features like deep code analysis, historical Git audits, and priority support. Monetize through in-app purchases for additional audit credits or team collaboration features.
💬 Integration Tip
Integrate this skill early in development workflows, such as pre-commit hooks or CI pipeline stages, to automate security checks and reduce manual review overhead.
Scored Jun 19, 2026
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...