sovereign-security-auditorComprehensive code security audit covering OWASP Top 10, secrets detection, dependency vulnerabilities, and language-specific attack patterns. Built by Taylo...
Install via ClawdBot CLI:
clawdbot install ryudi84/sovereign-security-auditorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
process.env.AWSHardcoded API key or token pattern found in skill definition
AKIAIOSFODNN...Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/ryudi84/sovereign-toolsGenerated Mar 22, 2026
Audit a JavaScript or Python web application for OWASP Top 10 vulnerabilities like SQL injection, XSS, and broken authentication. This is ideal for startups deploying new features, ensuring secure user input handling and API endpoints before production.
Systematically scan REST or GraphQL APIs for injection flaws, sensitive data exposure, and broken access control. Useful for fintech or healthcare companies to protect sensitive data transmissions and enforce proper authentication and authorization checks.
Inspect CI/CD configurations, Dockerfiles, and infrastructure-as-code for secrets exposure and misconfigurations. Helps enterprises automate security checks in deployment pipelines to prevent credential leaks and ensure secure default settings.
Audit older Java or Go codebases for vulnerabilities like XML external entities (XXE) and dependency risks. Assists manufacturing or logistics firms in upgrading systems to meet modern security standards without full rewrites.
Review public repositories or pull requests for security flaws before release. Beneficial for open-source maintainers or academic projects to ensure code quality and prevent common attacks like path traversal or insecure dependencies.
Offer a free tier for basic audits on small projects, with premium plans for advanced features like automated reporting and integration with CI/CD. Revenue comes from subscriptions targeting developers and small teams seeking affordable security solutions.
Provide customized audits and consulting for large organizations, including compliance checks and training. Revenue is generated through high-value contracts and ongoing support services for industries with strict regulatory requirements.
Integrate the auditor into developer platforms like GitHub Marketplace or GitLab, charging per audit or via usage-based pricing. Revenue streams include platform commissions and volume discounts for enterprise clients.
💬 Integration Tip
Integrate this skill into CI/CD pipelines using webhooks or CLI tools to automate security scans on every code commit, ensuring continuous vulnerability detection without manual intervention.
Scored Jun 19, 2026
AI Analysis
The skill is a code security auditor with a legitimate purpose, and the external URL points to its public GitHub repository for transparency. The high-risk signals are false positives: the 'AKIAIOSFODNN...' string is a well-known AWS example placeholder for demonstration, and 'eval()' is cited as a vulnerability pattern to detect, not a command the skill executes.
Audited Apr 18, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...