zero2ai-security-auditSecurity auditing for git commits, repos, and skills before publishing. Run automatically before any `git commit`, `git push`, or `clawhub publish`. Detects...
Install via ClawdBot CLI:
clawdbot install zero2ai-hub/zero2ai-security-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
process.env.SECRETAI Analysis
The skill is a local security auditing tool designed to prevent credential leaks; it scans local files and git operations without sending data externally. The flagged signal for accessing `process.env.SECRET` is a false positive, as it's an example in the documentation for remediation, not an action the skill performs.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Developers creating AI agent skills can run this audit before publishing to ClawHub to detect and fix security issues like hardcoded secrets or absolute paths. This ensures their skills are safe for distribution, preventing accidental exposure of sensitive data in public repositories.
DevOps teams integrate this skill into their CI/CD pipelines to automatically scan staged changes or last commits before pushes. It helps enforce security policies by blocking deployments with high-severity findings, such as API keys or .env files, reducing risks in production environments.
Maintainers of open-source projects use this tool to audit contributions for security vulnerabilities before merging pull requests. It scans for patterns like committed node_modules or hardcoded IPs, ensuring the codebase remains clean and secure for community use.
Security teams employ this skill to investigate potential secret exposures in git history after a breach alert. By scanning repositories for high-severity patterns, they can identify compromised credentials, rotate them, and guide remediation steps like rewriting git history to prevent further damage.
Offer this audit skill as part of a monthly subscription service for developers and teams, providing regular updates and premium features like custom rule sets. Revenue is generated through tiered pricing based on usage volume or number of repositories scanned.
Provide a free basic version for individual developers, with paid enterprise plans that include advanced integrations, priority support, and compliance reporting. Revenue comes from upselling to larger organizations needing enhanced security and automation capabilities.
Monetize by offering consulting services to help businesses integrate this audit skill into their existing workflows, such as CI/CD pipelines or custom security audits. Revenue is earned through project-based fees or hourly rates for setup and training.
💬 Integration Tip
Set up git hooks to automatically run the audit before commits and pushes, ensuring consistent security checks without manual intervention.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...