security-skiil-scannerSecurity vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated code, exfiltration. Risk classification L...
Install via ClawdBot CLI:
clawdbot install firebroo/security-skiil-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
POST → https://evil.com/stealPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://clawhub.comGenerated Mar 21, 2026
Large organizations deploying AI agents across departments use this skill to vet third-party skills before integration, ensuring compliance with internal security policies and preventing data breaches from malicious code. It automates red-flag detection in skill packages, reducing manual review time and mitigating risks associated with credential theft or unauthorized data exfiltration.
Platforms like ClawHub or GitHub integrate this skill as a built-in vetting tool for developers uploading new skills, providing automated security scans and risk classification to maintain trust and safety in their ecosystems. It helps enforce quality standards by flagging obfuscated code or excessive permissions before public release.
Training programs and workshops for AI engineers use this skill to teach best practices in secure skill development, with hands-on exercises in code review and risk assessment based on real-world examples. It serves as a practical guide to identify vulnerabilities like eval() misuse or unauthorized network calls in learning environments.
Independent consultants assisting small businesses with AI agent deployments employ this skill to vet custom or third-party skills before implementation, ensuring minimal privilege access and preventing system compromises. It provides structured reports to clients, demonstrating due diligence and enhancing service credibility.
Offer a basic version of the skill for free with limited scans, then charge for premium features like automated report generation, integration with CI/CD pipelines, or advanced threat intelligence feeds. Revenue comes from subscription tiers targeting enterprises needing continuous monitoring and compliance audits.
License the skill to AI agent platforms (e.g., ClawHub) as a mandatory vetting layer, charging a fee per skill scan or taking a percentage of transactions for verified skills. Revenue is generated through partnerships that enhance platform security and reduce fraud risks for users.
Provide bespoke vetting services for high-risk industries like finance or healthcare, using the skill as a foundation to conduct in-depth security audits and generate compliance reports. Revenue comes from project-based contracts or retainer models for ongoing skill evaluation and threat monitoring.
💬 Integration Tip
Integrate this skill into automated workflows by using its quick vet commands in scripts, such as pre-install hooks in CI/CD pipelines, to scan skills before deployment and flag risks based on the provided checklist.
Scored Jun 19, 2026
Uses known external API (expected, informational)
api.github.comAI Analysis
The skill is a security scanner designed to vet other skills; its external calls to clawhub.com and api.github.com are consistent with its stated purpose of checking sources and repositories. The 'evidence' strings in the signals appear to be example red flags for detection, not actual malicious behavior of the scanner itself.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...