security-hardening-safeyAgent 安全加固技能。用于:(1) 安装后经用户确认,将安全红线注入所有 Agent 的底层记忆(AGENTS.md),精简版注入~112行,不造成token膨胀;(2) 当用户问到安全规则、提示词注入防御、危险命令管控、外部代码审查、多模态注入等话题时加载此技能;(3) 进行安全审计或排查疑似注入事件时使用...
Install via ClawdBot CLI:
clawdbot install beyound87/security-hardening-safeyGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
rm -rf ~Accesses system directories or attempts privilege escalation
/proc/Generated May 20, 2026
An enterprise deploying Retrieval-Augmented Generation (RAG) systems uses this skill to prevent indirect prompt injection via ingested documents. When external content contains hidden commands or identity masquerading, the skill triggers red flags and blocks dangerous operations, ensuring the RAG pipeline remains secure.
In DevOps environments, users often execute scripts from online sources. This skill enforces a four-step security review protocol before any external script runs, generating structured risk reports and requiring explicit user approval, thus preventing unintended command injection or malicious code execution.
When multiple AI agents work together (e.g., in a task orchestration platform), this skill prevents credential leakage, instruction spoofing, and context window attacks. It ensures each agent validates command origins and restricts unauthorized self-modification, critical for safe multi-agent coordination.
Organizations processing PDFs, images, and other non-text files use this skill to treat all multimodal content as external data. It detects scripts embedded in PDFs or EXIF instructions, blocking path traversal attempts and protecting the underlying system from file-based attacks.
Cloud service providers offering AI agents to customers incorporate this skill during onboarding. It injects security rules into each agent's base memory (~112 lines) after user consent, reducing token overhead while establishing a robust security baseline against prompt injection and dangerous command execution.
Offer the Security Hardening Safey as a premium add-on for existing AI agent platforms. Customers pay a monthly fee per agent or per seat to activate continuous protection, including rule updates and audit capabilities.
License the skill as part of an enterprise security toolkit for internal AI deployments. Revenue comes from a one-time per-deployment fee, with optional annual maintenance for updates and support.
Provide a free basic version of the skill (core injection only) and charge for advanced features like comprehensive audit reports, custom rule creation, and compliance integrations (e.g., SOC2, HIPAA).
💬 Integration Tip
Integrate during initial agent setup to establish a security baseline; run the initialization script after user approval to avoid token waste.
Scored May 20, 2026
Calls external URL not in known-safe list
https://clawhub.ai/spclaudehome/skill-vetterAudited Apr 20, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...