test0413-6348Security audit + append-only logging + monitoring for OpenClaw skills (file-level diff, baseline approval, SHA-256 integrity).
Install via ClawdBot CLI:
clawdbot install ucloud-sec/test0413-6348Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/sudoersCalls external URL not in known-safe list
https://api.example.com/...Usage Guide
Loading usage data… refresh in a few seconds.
Scored Apr 19, 2026
AI Analysis
The skill's stated purpose is security auditing and monitoring of other skills, which involves reading local skill files and executing trusted subprocesses like git for diffing. While it has high privilege to inspect the system, there is no evidence of unauthorized data exfiltration, credential harvesting, or hidden malicious instructions. The primary risk is the inherent privilege of the audit tool itself, not a violation of its stated security-focused purpose.
Audited Apr 17, 2026 · audit v1.0
Firecrawl CLI for web scraping, crawling, and search. Scrape single pages or entire websites, map site URLs, and search the web with full content extraction. Returns clean markdown optimized for LLM context. Use for research, documentation extraction, competitive intelligence, and content monitoring.
Automates system health monitoring, temp file cleanup, memory deduplication and summarization, with detailed logging for OpenClaw maintenance.
Surf forecast decision engine. Outputs surfable conditions for agent alerting.
Incident Commander Skill
Monitors OpenClaw cron job health, identifies failures, timeouts, and delivery issues.
Full stack observability - reproducibility, lineage, monitoring, alerting