skill-sec-scan-en自动检测 JavaScript、TypeScript、Python 和 Shell 文件中的数据外泄、注入、代码混淆与木马后门等安全风险并生成详细报告。
Install via ClawdBot CLI:
clawdbot install torchesfrms/skill-sec-scan-enGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdPotentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://clawhub.ai/AphobiaCat/aibtcAI Analysis
This skill definition demonstrates concerning security practices including credential access patterns, destructive shell commands, and external URL calls to unspecified endpoints. The skill's own scanning logic references high-risk operations like accessing /etc/passwd and using 'rm -rf /' commands, suggesting it may implement or facilitate similar behaviors. The trigger phrases are overly broad, potentially scanning unintended targets.
Usage Guide
Loading usage data… refresh in a few seconds.
Scored Jun 29, 2026
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...