skills-firewallSecurity firewall for skills that automatically blocks and filters malicious or potentially harmful skills. Use when: (1) Scanning skills for security threat...
Install via ClawdBot CLI:
clawdbot install huzibbs/skills-firewallGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
http://example.com/malware.shAI Analysis
The skill definition contains rule-based signals indicating unsafe shell commands (eval()) and calls to an external URL not on a known-safe list, which could be used to download and execute malicious payloads. While the skill's stated purpose is security scanning, these patterns within its own code or examples create a potential execution risk.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 20, 2026
A large organization uses an internal marketplace for AI skills. The firewall scans all submitted skills for security threats before they are published, ensuring only safe skills are available to employees. It automatically blocks skills with critical vulnerabilities like credential exposure and quarantines those with medium threats for manual review.
An online learning platform allows students to upload custom AI skills for projects. The firewall checks each skill for malicious code like eval() or command execution to prevent security breaches. It generates reports for instructors to review and manage allowed skill lists based on safety levels.
A healthcare provider uses AI skills for patient data analysis and must comply with regulations like HIPAA. The firewall scans skills for security threats such as network communication and file operations to prevent data leaks. It produces detailed security reports for compliance audits and blocks high-risk skills automatically.
A software development team integrates the firewall into their CI/CD pipeline to scan AI skills during build processes. It checks for threats like deserialization and privilege escalation before deployment, ensuring only secure skills are released. The tool outputs JSON results for automation and logs decisions for traceability.
A financial institution uses AI skills for trading algorithms and customer service. The firewall filters skills based on security rules to detect and block high-severity threats like code injection and credential exposure. It manages allowed and blocked skill lists to enforce strict security policies and prevent fraud.
Offer the firewall as a cloud-based service with tiered pricing based on usage, such as number of skills scanned per month. Include features like automated scanning, real-time threat updates, and premium support. Revenue is generated through monthly or annual subscriptions from businesses and developers.
Sell perpetual licenses to large organizations for on-premises deployment, with customization options and dedicated support. Include add-ons for advanced reporting, integration with existing security tools, and training services. Revenue comes from one-time license sales and ongoing maintenance contracts.
Provide a free version with basic scanning and limited reports to attract individual developers and small teams. Monetize through premium features like advanced threat detection, batch processing, and API access for automation. Revenue is generated from upgrades and in-app purchases.
💬 Integration Tip
Integrate the firewall into existing CI/CD pipelines using its JSON output for automated security checks, and customize rules via YAML configuration to align with specific organizational policies.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...