skills-auditSecurity audit + append-only logging + monitoring for OpenClaw skills (file-level diff, baseline approval, SHA-256 integrity).
Install via ClawdBot CLI:
clawdbot install buffedon/skills-auditGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/shadowPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/sudoersCalls external URL not in known-safe list
https://safeskill.qianxin.comUsage Guide
Loading usage data… refresh in a few seconds.
Scored Jun 20, 2026
AI Analysis
This skill is a security auditing tool designed to monitor other skills, not to exfiltrate data or execute malicious code. It performs static analysis, maintains local logs, and uses git for diffs—all consistent with its stated security monitoring purpose. The only external interaction appears to be push notifications (likely user-configured), and the skill explicitly states it never executes skill code.
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Analyze and classify agent skills for safety using local evaluation. Optionally produce a signed attestation of the vetting result.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle tim...
Git 安全扫描器 - 检查提交中的敏感信息泄露(API keys、密码、token)