skill-security-audit-v2已安装 Skills 的安全审计工具。用于批量审计 Skills 的安全性,包括命令执行、网络访问、文件访问、数据泄露、依赖风险、提示词越权和触发条件检查。适用于用户提供 Skills 列表和文件内容时进行安全扫描、护栏审查、提示词越权审查或强化建议。
Install via ClawdBot CLI:
clawdbot install chensu1234/skill-security-audit-v2Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated May 7, 2026
An AI platform manager wants to audit community-contributed skills before they are published to ensure they don't contain malicious commands or data leaks. This skill scans each skill's manifest and scripts for dangerous patterns like arbitrary shell execution or unauthorized network requests, providing a risk rating and remediation suggestions.
An enterprise with an internal library of AI skills needs to verify compliance with security policies. The audit tool checks for forbidden operations such as reading local files outside allowed directories or sending data to unapproved endpoints, generating a detailed report for each skill.
A security researcher analyzes skills for prompt injection risks that could bypass system instructions. The audit identifies overly broad trigger conditions and checks whether skill descriptions could be tricked into executing unauthorized actions.
A DevOps team wants to assess the security posture of third-party skills integrated into their workflow. The audit examines dependencies for unversioned or suspicious packages and flags skills that access external networks without clear justification.
Offer a monthly subscription to organizations that need continuous security audits of their growing skill libraries. Revenue comes from recurring subscription fees, with tiered pricing based on the number of skills audited per month.
Provide a one-time security audit for a single skill or a small batch of skills, ideal for developers who want a quick security check before deploying a new skill. Revenue comes from per-audit charges.
Integrate the audit skill into an AI platform as a mandatory pre-publish step, charging a small fee per audit or a percentage of each skill transaction. This ensures platform-wide security while generating revenue from high-volume audits.
💬 Integration Tip
Integrate the audit as a CI pipeline step that triggers on new skill submissions, automatically blocking or flagging high-risk skills.
Scored May 7, 2026
Security vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated code, exfiltration. Risk classification L...
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Audit a user's current AI tool stack. Score each tool by ROI, identify redundancies, gaps, and upgrade opportunities. Produces a structured report with score...
Detect anomalies and outliers in construction data: unusual costs, schedule variances, productivity spikes. Statistical and ML-based detection methods.