skill-sandboxSandboxed ClawHub skill installation with automated security scanning. Use when: (1) Installing any new skill from ClawHub, (2) Auditing an already-installed...
Install via ClawdBot CLI:
clawdbot install zurbrick/skill-sandboxGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Audited Apr 17, 2026 · audit v1.0
Generated Mar 20, 2026
Development teams use this skill to safely install and audit new skills from ClawHub, preventing supply chain attacks. It automates security scanning during installation, quarantining risky skills for review while auto-promoting clean ones, ensuring only verified skills are integrated into production agents.
Organizations in finance or healthcare employ this skill to audit existing AI agent skills for compliance with security standards. It scans for dangerous code patterns and dependencies, generating reports that help meet regulatory requirements and mitigate risks from third-party components.
DevOps teams integrate this skill into their continuous integration pipelines to automatically scan and validate skill updates before deployment. It uses exit codes for pass/fail verdicts, enabling automated workflows that block risky installations and maintain security in agile development environments.
Security researchers utilize this skill to analyze and quarantine suspicious skills from untrusted publishers, performing static analysis on code patterns and metadata. It helps identify potential threats like obfuscation or malicious instructions, supporting deeper audits with specialized security agents.
Offer this skill as part of a cloud-based security platform for AI agent ecosystems, charging subscription fees based on scan volume or team size. It provides automated threat detection and compliance reporting, appealing to enterprises needing scalable security solutions.
License the skill to large organizations for on-premises deployment, with custom support and integration services. Revenue comes from one-time licenses and annual maintenance fees, targeting industries with strict data privacy requirements like government or finance.
Provide a free version with basic scanning capabilities to attract individual developers, while offering premium features like advanced threat intelligence or team collaboration tools for a fee. This model drives adoption and upsells to paid tiers for enhanced security.
💬 Integration Tip
Integrate this skill into existing CI/CD pipelines by calling its script with exit code handling to automate security checks; for teams using security agents, trigger deep audits only on quarantined skills to optimize workflow efficiency.
Scored Apr 19, 2026
Access CoinMarketCap data via x402 pay-per-request protocol with USDC payments on Base. Use when users mention x402, want CMC data without API keys, ask abou...
A self-custodial crypto payment wallet for your OpenClaw agent, with a hard spend cap it can't exceed. It autonomously pays x402 paywalls ('402 Payment Requi...
Pay for APIs and services, receive payments, and manage agent wallets using Mag3nt USDC virtual cards. Activate when the agent needs to pay for a resource, e...
Run a Machine Payments Protocol (MPP) conformance test — prove an agent or wallet can complete a real $0.50 USDC payment on Solana and get a shareable "passe...
基于4个商业决策实战案例提炼的沙盘推演工具,帮助OPC创业者在重大决策前模拟多种场景,预测结果,降低试错成本。核心:先推演再行动。
x402 Bazaar protocol guide for AgentPMT — implement the HTTP 402 two-step handshake, sign EIP-3009 TransferWithAuthorization, route through the AgentPMT faci...