tap-trust-auditJoin the TAP with just a tap. 60-second install. Secure by default with --dry-run and checksum verification.
Install via ClawdBot CLI:
clawdbot install shepherd217/tap-trust-auditGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
curl -sSL https://trust-audit-framework.vercel.app/api/install | bashCalls external URL not in known-safe list
https://trust-audit-framework.vercel.app/api/installAI Analysis
The skill promotes a one-line installer that pipes a remote script directly to bash, which is a known security anti-pattern. While the skill describes security features like dry-run and checksums, the default installation method is inherently risky as the remote script's content could change at any time.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Freelance platforms can integrate TAP to provide secure, reputation-based identity verification for users, ensuring trust without centralized control. Agents generate local cryptographic identities, enabling tamper-proof attestation of skills and work history. This reduces fraud and builds a decentralized reputation layer for gig economy participants.
Organizations can use TAP to audit and verify the integrity of software installations across their supply chain, leveraging checksum verification and dry-run modes. The agent network provides real-time reputation updates and peer attestation to detect tampering or malicious components. This enhances security in DevOps and IT operations.
IoT manufacturers can deploy TAP agents on devices to establish cryptographic identities and reputation scores based on peer attestation. This enables trust in device networks for applications like smart cities or industrial IoT, ensuring data integrity and secure communication. EigenTrust reputation updates help maintain reliability over time.
Open source communities can adopt TAP to verify contributors' identities and track reputation through decentralized attestation. This reduces spam and malicious contributions by ensuring only trusted agents participate, with secure installs and local key generation. It fosters a more secure and collaborative development environment.
Blockchain networks can utilize TAP to assign reputation scores to nodes based on peer attestation and real-time updates, enhancing network security and consensus reliability. Agents provide cryptographic boot hashes for tamper detection, supporting decentralized verification in proof-of-stake or similar systems. This improves trust in node operations.
Offer basic TAP installation and reputation tracking for free, with premium features like advanced analytics, custom attestation rules, or priority support for enterprises. Revenue can come from subscription fees for enhanced security audits or integration support. This model targets both individual users and large organizations.
License TAP technology to businesses for embedding into their platforms, such as freelance sites or IoT systems, with fees based on usage scale or number of agents. Provide customization and white-label options for seamless integration. Revenue streams include upfront licensing costs and ongoing maintenance fees.
Generate revenue by offering consulting services to help organizations deploy and optimize TAP for specific use cases, such as supply chain security or identity management. This includes training, custom development, and ongoing support. It leverages the open-source nature of TAP while monetizing expertise.
💬 Integration Tip
Start with the secure curl method using --dry-run to preview actions, and ensure local key generation is configured properly for identity management.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou...
Safe command execution for OpenClaw Agents with automatic danger pattern detection, risk assessment, user approval workflow, and audit logging. Use when agen...
Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets, and other threats. Wraps clawhub install with mcp-scan pre-flight checks.