skills-audit审计技能库健康度:项目画像→七维评分→容量预警→趋势对比→快照回滚。 支持技能/项目双模式 + CI/CD。Capabilities: skill audit, project profiling, 7-dim scoring, capacity analysis, liveness check, snapsho...
Install via ClawdBot CLI:
clawdbot install buffedon/skills-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/shadowPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/sudoersCalls external URL not in known-safe list
https://safeskill.qianxin.comGenerated Aug 23, 2026
As organizations adopt AI agents with custom skills, they need automated security audits to detect malicious or vulnerable code. This skill provides continuous scanning, logging, and alerts for any changes, ensuring skills remain safe and compliant.
In CI/CD pipelines, skills being deployed to production environments must pass security checks. This skill can be integrated as a gate to audit skills for dangerous patterns, enforce policies, and maintain audit trails for compliance.
Large enterprises with many AI agents need centralized governance over skill development and usage. This skill provides baseline approval workflows and change monitoring, helping IT teams manage skills across the organization.
In finance and healthcare, AI systems must comply with strict regulations. This skill's append-only logging and integrity verification provide a tamper-evident audit trail for skill changes, supporting compliance audits.
Offer automated security audits for AI skills as a subscription service. Enterprises pay a monthly fee to continuously monitor their skills and receive alerts and reports.
Sell or license the skill as a plugin for CI/CD platforms like Jenkins or GitHub Actions. Provide premium support and customization for enterprise clients.
Provide consulting services to implement and customize the skill for organizations, including policy configuration, baseline setup, and training. Include ongoing managed monitoring and response.
💬 Integration Tip
Integrate into your CI/CD pipeline or as a scheduled task, and configure the QianXin token for enhanced threat intelligence if available.
Scored Aug 23, 2026
AI Analysis
This skill is a security auditing tool designed to monitor other skills, not to exfiltrate data or execute malicious code. It performs static analysis, maintains local logs, and uses git for diffs—all consistent with its stated security monitoring purpose. The only external interaction appears to be push notifications (likely user-configured), and the skill explicitly states it never executes skill code.
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...