slowmist-security-ccSlowMist AI Agent Security Review — comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version)
Install via ClawdBot CLI:
clawdbot install 0xcjl/slowmist-security-ccGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdPotentially destructive shell commands in tool definitions
curl | sh, curl | bash, wget | sh, wget | bashAccesses system directories or attempts privilege escalation
/etc/sudoersCalls external URL not in known-safe list
https://github.com/slowmist/slowmist-agent-securityGenerated May 12, 2026
When a user considers installing a new Skill, MCP server, or npm/pip/cargo package, this framework guides the reviewer to list the file manifest, verify the source, and scan for red flags before installation. It prevents supply chain attacks and malicious code injection from third-party packages.
For evaluating a GitHub repository before using or integrating it, the framework instructs to examine commit history, check star counts, and analyze code for dangerous patterns. It helps developers avoid malicious or poorly maintained codebases.
When a user receives a URL, document, or Gist containing code blocks, this framework requires line-by-line scanning of the code to detect social engineering or hidden malicious payloads. It protects against phishing attacks that trick users into running harmful code.
Before interacting with a blockchain address or smart contract, the framework checks AML scores and reviews the contract code for vulnerabilities. It safeguards cryptocurrency users from scams and exploits in DeFi and Web3 applications.
When evaluating a new product, service, or API, the framework prioritizes checking private key management and authentication mechanisms. It ensures that third-party services meet security standards before being used in production systems.
Provide ongoing security review services for AI agent skills and third-party integrations. Companies pay a subscription for continuous monitoring and automated reports on repositories, packages, and URLs.
Offer one-time or retainer-based deep-dive security audits for smart contracts, SDKs, and high-risk products using the SlowMist framework. Deliver detailed reports and remediation guidance.
Sell access to an expanded database of red flag patterns, social engineering tactics, and supply chain attack signatures that update the framework's reference libraries. Developers and security teams pay for curated threat intelligence.
💬 Integration Tip
Start by integrating the fast decision card as a prompt prefix for your AI agent to trigger the correct review type based on user requests.
Scored May 12, 2026
AI Analysis
This is a security auditing framework skill that provides structured guidelines for evaluating other skills and external content. It contains no executable code, data collection mechanisms, or external API calls that would pose security risks. The skill's purpose is purely educational and procedural for security assessment.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...