zero2ai-security-auditSecurity auditing for git commits, repos, and skills before publishing. Run automatically before any `git commit`, `git push`, or `clawhub publish`. Detects...
Install via ClawdBot CLI:
clawdbot install Zero2Ai-hub/zero2ai-security-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
process.env.SECRETAI Analysis
The skill is a local security auditing tool designed to prevent credential leaks; it scans local files and git operations without sending data externally. The flagged signal for accessing `process.env.SECRET` is a false positive, as it's an example in the documentation for remediation, not an action the skill performs.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Developers creating AI agent skills can run this audit before publishing to ClawHub to detect and fix security issues like hardcoded secrets or absolute paths. This ensures their skills are safe for distribution, preventing accidental exposure of sensitive data in public repositories.
DevOps teams integrate this skill into their CI/CD pipelines to automatically scan staged changes or last commits before pushes. It helps enforce security policies by blocking deployments with high-severity findings, such as API keys or .env files, reducing risks in production environments.
Maintainers of open-source projects use this tool to audit contributions for security vulnerabilities before merging pull requests. It scans for patterns like committed node_modules or hardcoded IPs, ensuring the codebase remains clean and secure for community use.
Security teams employ this skill to investigate potential secret exposures in git history after a breach alert. By scanning repositories for high-severity patterns, they can identify compromised credentials, rotate them, and guide remediation steps like rewriting git history to prevent further damage.
Offer this audit skill as part of a monthly subscription service for developers and teams, providing regular updates and premium features like custom rule sets. Revenue is generated through tiered pricing based on usage volume or number of repositories scanned.
Provide a free basic version for individual developers, with paid enterprise plans that include advanced integrations, priority support, and compliance reporting. Revenue comes from upselling to larger organizations needing enhanced security and automation capabilities.
Monetize by offering consulting services to help businesses integrate this audit skill into their existing workflows, such as CI/CD pipelines or custom security audits. Revenue is earned through project-based fees or hourly rates for setup and training.
💬 Integration Tip
Set up git hooks to automatically run the audit before commits and pushes, ensuring consistent security checks without manual intervention.
Scored Apr 19, 2026
Security vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated code, exfiltration. Risk classification L...
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Audit a user's current AI tool stack. Score each tool by ROI, identify redundancies, gaps, and upgrade opportunities. Produces a structured report with score...
Detect anomalies and outliers in construction data: unusual costs, schedule variances, productivity spikes. Statistical and ML-based detection methods.