security-sweepSecurity scanner for OpenClaw skills and plugins. Scans for hardcoded secrets, dangerous exec patterns, dependency vulnerabilities, and network egress. Use w...
Install via ClawdBot CLI:
clawdbot install rhombusmaximus/security-sweepGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://www.notion.so/my-integrationsAI Analysis
The skill is a security scanner designed to audit other skills/plugins, and its documented external calls (e.g., Notion) appear related to reporting or integration for its stated purpose. No evidence of credential harvesting, data exfiltration, or hidden malicious instructions was found in the provided definition.
Audited Apr 16, 2026 · audit v1.0
Generated May 22, 2026
Before publishing a skill to ClawHub, run the full security sweep to identify hardcoded secrets, dangerous exec patterns, and dependency vulnerabilities. This ensures the skill meets publishing standards and avoids credential leaks or code injection risks.
Periodically scan all user-installed workspace skills for security issues. The security-sweep agent automates this, flagging critical findings like hardcoded API keys or shell injection surfaces that could compromise the host system.
Integrate the quick scan or full sweep into a CI/CD pipeline to automatically reject builds or deployments of skills with critical or high-risk findings. This prevents vulnerable code from reaching production or being shared via ClawHub.
Use the agent to set up a cron job that runs a comprehensive sweep every week. The agent saves reports and notifies the user if any critical issues are found, enabling proactive remediation without manual scheduling.
Offer a cloud dashboard that aggregates security sweep reports from multiple organizations. Users submit reports or grant API access, and the service visualizes risk trends, generates compliance documentation, and alerts on critical vulnerabilities.
Provide the security-sweep agent for free with basic scanning capabilities (quick scan, single skill). Charge for premium features like automated fix suggestions, integration with CI/CD platforms, and priority support.
Use the agent as part of a consulting engagement to audit an organization's custom skills and plugins. Generate detailed reports, provide remediation guidance, and help implement ongoing security scanning processes.
💬 Integration Tip
Integrate into CI/CD by running 'bash ~/.openclaw/workspace/skills/security-sweep/scripts/quick-scan.sh --dir <repo>' as a pre-commit hook or build step to catch issues early.
Scored Jun 29, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...