skill-dependency-chain-auditorHelps audit transitive skill dependency chains in agent compositions — catching the class of risk where a skill's direct dependencies appear safe but a depen...
Install via ClawdBot CLI:
clawdbot install andyxinweiminicloud/skill-dependency-chain-auditorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Mar 21, 2026
An AI agent used by banks to analyze transaction documents for fraud detection. It depends on skills for data extraction, format conversion, and parsing, where a vulnerability in a low-level dependency like a charset detector could allow attackers to inject malicious data, bypassing compliance checks.
An agent in hospitals that processes patient records by relying on skills for text extraction and metadata parsing. A compromised transitive dependency, such as an unverified mime detector, could leak sensitive health data or introduce errors in medical diagnoses.
An agent for online retailers that scans product descriptions and reviews using dependency chains for format conversion and text analysis. An outdated or unaudited dependency like an encoding table could allow attackers to manipulate product data, affecting pricing or inventory systems.
An agent that aggregates threat data from various sources, depending on skills for parsing and network fetching. A vulnerability in a transitive dependency like an http fetcher could enable attackers to exfiltrate sensitive threat intelligence or inject false data into security reports.
An agent used by law firms to audit contracts and legal documents, with dependencies on text extraction and metadata parsing skills. A trust gradient issue, where high-trust top skills depend on low-trust sub-skills, could lead to undetected modifications in legal terms or compliance breaches.
Offer the auditor as a cloud-based service where organizations pay a monthly fee per agent or skill analyzed. This model provides recurring revenue and scales with client usage, ideal for enterprises managing multiple AI agents.
Provide custom auditing services and integration support for companies deploying complex agent systems. This includes one-time setup fees and ongoing maintenance contracts, targeting clients with specific compliance or security needs.
Sell the auditor as an add-on tool in AI skill marketplaces, where developers and organizations can purchase it to vet skills before installation. This leverages existing platforms for distribution and monetization through direct sales or commissions.
💬 Integration Tip
Integrate the auditor into CI/CD pipelines for agent deployments to automatically scan dependency chains during skill updates, ensuring continuous security monitoring.
Scored Apr 19, 2026
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Coding style memory that adapts to your preferences, conventions, and patterns for consistent coding.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.