skill-security-reviewReview and audit OpenClaw skills and agents for data risks, code execution, persistence, network access, privilege escalation, and supply-chain threats befor...
Install via ClawdBot CLI:
clawdbot install kickook/skill-security-reviewGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated Mar 21, 2026
Developers integrating third-party AI skills from GitHub or ClawHub need to ensure these packages don't contain malicious code like data exfiltration or privilege escalation. This skill automates security audits by scanning SKILL.md and bundled scripts, flagging risks such as network calls or local command execution, and providing a verdict before installation.
Companies deploying AI agents with custom skills must prevent supply-chain attacks and data leaks. This skill reviews skill packages for hidden capabilities like persistence mechanisms or unauthorized network access, ensuring compliance with security policies and protecting sensitive corporate data during automation tasks.
Educators and students using AI skills for learning projects need to avoid skills that could compromise personal data or system integrity. The skill audits packages for destructive behavior or excessive permissions, offering guardrails like sandboxed execution to safely explore new functionalities without risk.
Freelancers automating tasks with AI skills from various sources must verify that skills don't expose client data or install malware. This skill analyzes artifacts for suspicious patterns like base64 blobs or registry edits, recommending conditional installation with constraints like network blocking to maintain security.
Offer this skill as part of a subscription service for continuous security monitoring of AI skill repositories. Revenue comes from monthly fees based on the number of audits or integrations, targeting businesses that regularly update their AI toolkits and need automated compliance checks.
License the skill to large organizations for internal use, with custom features like integration into existing DevOps pipelines or compliance reporting. Revenue is generated through annual licenses and support contracts, focusing on sectors with strict data protection requirements.
Provide a free basic version for individual users with limited audits, and charge for advanced features like detailed risk scoring, historical tracking, or priority support. Revenue comes from upgrades and one-time payments for in-depth security reports.
💬 Integration Tip
Integrate this skill early in your development or deployment pipeline to automate security reviews before skill activation, reducing manual oversight and catching risks proactively.
Scored Apr 19, 2026
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Coding style memory that adapts to your preferences, conventions, and patterns for consistent coding.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.