security-reviewAttacker's-eye security review of a diff, branch, or module — walks a fixed vulnerability catalog (missing authz on new endpoints, injection, secrets in code/logs, trusting client-sent identity, SSRF, path traversal, insecure deserialization, mass assignment, broken crypto, unsafe redirects, dependency CVEs) where every finding must name a concrete attack path (attacker does X → gains Y) or be demoted to hardening advice. Never claims "secure", only "nothing found in the classes checked". Use this skill whenever the user says "security review", "is this secure", "check for vulnerabilities", "audit the auth", "threat model this", "pentest mindset", "check for injection", or "/security-review" — even if they don't name the skill. Distinct from code-review (security is one lens there); this is the dedicated deep pass.
Install via ClawdBot CLI:
clawdbot install mpbshhx/security-reviewGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated May 5, 2026
A development team evaluates an npm package before adding it to their project. The skill performs automated CVE searches and source code analysis to identify malware or data exfiltration risks, producing a GO/NO-GO verdict to prevent supply chain attacks.
A SaaS company reviews a new third-party API integration by scanning its dependencies and data flow. The skill ensures the integration does not exfiltrate customer data or introduce known vulnerabilities, enabling safe onboarding of external services.
A DevOps team evaluates a CLI tool before adding it to their CI/CD pipeline. The skill examines the tool's source code, permission scope, and dependency risk, providing a conditional verdict with specific remediation steps.
An IT security team assesses a browser extension requested by employees. The skill reviews the extension's network calls and file system access, ensuring it does not compromise corporate data or introduce spyware.
An AI research lab verifies a new Python library for model training. The skill checks for obfuscated code, telemetry, and supply chain risks, delivering a CONDITIONAL verdict that requires specific mitigations before use.
Offer the skill as a standard part of security audit engagements. Clients pay a monthly retainer for unlimited pre-install reviews, with detailed logs and verdict reports delivered regularly.
Package the skill as an add-on for CI/CD platforms (e.g., GitHub Actions, Jenkins) or development environments. Charge per review or as a subscription for teams.
License the skill to large organizations that need auditable security reviews for compliance (SOC2, FedRAMP). Provide integration with their existing toolchain and custom report templates.
💬 Integration Tip
Integrate this skill as a mandatory step in your package manager aliases or CI/CD pipeline, e.g., as a pre-install hook that runs automatically before 'npm install' or 'pip install'.
Scored Apr 28, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...