security-testerSecurity testing for web applications and APIs based on OWASP standards. Identify common vulnerabilities (injection, auth bypass, XSS, CSRF, IDOR), generate...
Install via ClawdBot CLI:
clawdbot install zhanghengyi1986-afk/security-testerGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdCalls external URL not in known-safe list
https://owasp.org/Top10/Audited Apr 17, 2026 · audit v1.0
Generated May 23, 2026
Test API endpoints for OWASP Top 10 vulnerabilities like IDOR, SQLi, and XSS during checkout. Automate curl commands to verify access controls and input validation, ensuring sensitive payment data is protected. Recommended for online retail platforms to prevent data breaches.
Apply the brute force and session fixation tests to a healthcare login system. Ensure robust authentication prevents unauthorized access to patient records, meeting HIPAA compliance. Use the CVSS scoring to prioritize findings.
Conduct injection and access control tests on a financial services API. Focus on SQLi and privilege escalation to protect transaction data. Use the vulnerability report template to document critical findings for remediation.
Test for SSRF, security misconfigurations, and insecure deserialization in a public service portal. Leverage the OWASP matrix to cover all categories, ensuring compliance with government security standards.
Integrate the security test scripts into CI/CD pipelines for automated scanning of web apps. Trigger curl-based checks on every build to catch regressions early, aligning with DevSecOps practices. Ideal for tech companies with rapid deployment cycles.
Offer as a managed security testing service for clients, performing audits and generating detailed reports. Revenue from per-engagement fees or monthly retainers. Scales with client portfolio size.
Package the skill into a SaaS plugin that integrates with GitHub Actions, Jenkins, or GitLab CI. Charge per month based on number of repositories or scans. Recurring revenue from subscriptions.
Use the OWASP matrix and test cases to create hands-on security training modules. Sell courses to enterprises for upskilling developers in secure coding. Revenue from course sales or institutional licenses.
💬 Integration Tip
To integrate, embed the curl test scripts into your CI pipeline and parse outputs to automatically generate vulnerability reports using the provided template.
Scored May 23, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...