sx-security-audit全方位安全审计技能。检查文件权限、环境变量、依赖漏洞、配置文件、网络端口、Git 安全、Shell 安全、macOS 安全、密钥检测等。支持 CLI 参数、JSON 输出、配置文件。当用户要求"安全检查"、"漏洞扫描"、"权限检查"、"安全审计"时使用此技能。
Install via ClawdBot CLI:
clawdbot install zhuxiaobao-y/sx-security-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
send → https://...Hardcoded API key or token pattern found in skill definition
ghp_xxxxxxxx...Potentially destructive shell commands in tool definitions
eval(Generated Mar 21, 2026
A DevOps team uses this skill to audit CI/CD pipelines and cloud infrastructure configurations for security vulnerabilities before deployment. It checks environment variables, file permissions, and dependencies in automated workflows, ensuring compliance with internal security policies and reducing breach risks.
A financial institution employs this skill to scan internal systems and applications for sensitive data exposure, such as hardcoded API keys and insecure network ports. It helps meet regulatory requirements by generating detailed audit reports for compliance officers and IT security teams.
An e-commerce company integrates this skill into its monitoring systems to regularly audit server configurations, Git repositories, and dependency vulnerabilities. It detects unauthorized access risks and supply chain threats, enabling proactive fixes to protect customer data and transaction integrity.
A healthcare provider uses this skill to audit electronic health record systems and research environments for security flaws like weak permissions and exposed keys. It supports HIPAA compliance by identifying risks in configurations and code, facilitating secure handling of patient information.
A startup leverages this skill during development sprints to perform quick security checks on new code commits and server setups. It scans for common issues like world-writable files and shell history exposures, helping small teams build secure practices from the ground up with minimal overhead.
Offer this skill as part of a cloud-based security platform with tiered subscriptions. Provide automated audits, real-time alerts, and integration with tools like Slack or Jira, charging monthly fees based on usage volume or number of scans.
Sell customized security audit services using this skill, tailored to specific industries or compliance needs. Include on-site training, report analysis, and integration support, with revenue from project-based contracts and ongoing maintenance fees.
Release the core skill as open source to build community trust, then monetize through premium add-ons like advanced reporting, priority support, and enterprise integrations. Offer paid licenses for commercial use or enhanced features.
💬 Integration Tip
Integrate this skill into CI/CD pipelines using CLI commands with JSON output for automated reporting, and configure environment variables for seamless use with tools like Jenkins or GitHub Actions.
Scored Jun 19, 2026
Accesses system directories or attempts privilege escalation
/var/log/Calls external URL not in known-safe list
https://...AI Analysis
The skill performs legitimate security auditing functions, but the presence of hardcoded credential patterns in the definition and the ability to send reports to an external endpoint (Feishu) via an undocumented script introduces risk. While the external endpoint likely serves the stated reporting purpose, the lack of explicit user consent for data transmission and the potential for credential harvesting via its scanning capabilities warrant caution.
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...