Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
AI agent skills for vulnerability scanning, penetration testing, authentication, and compliance automation.
Secure your codebase and infrastructure with AI agent skills for OWASP vulnerability detection, dependency auditing, pen testing automation, auth implementation, and compliance reporting. Used by security engineers, developers, and compliance teams.
Scan code and dependencies for CVEs, OWASP issues, and hardcoded secrets.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Performs static analysis for OWASP 2025 risks, supply chain threats, secrets detection, code patterns, and prioritizes vulnerabilities by exploitability and...
Automated authorized penetration testing skill with multi-layer detection, PoC/exploit generation, comprehensive vulnerability reporting, and scope safety co...
오픈소스 취약점 분석 스킬. 사용자가 오픈소스 패키지 이름과 사용 중인 버전을 입력하면, NVD(NIST), OSV.dev(Google), GitHub Advisory 3개 데이터 소스에서 CVE 취약점을 조회하여 최신 버전 정보와 함께 보안 리포트를 생성한다. 마크다운, Exce...
技能生态的「安全策展 → 安装闸门 → 生态治理」全能工具,find-skills 的社区超级增强版(能力已超越原版与 skill-vetter 等同类)。 当用户用自然语言描述需求("我想做个海报""帮我分析股票""有没有能做 X 的技能"),或明确说 "找个 skill / 找技能 / 安装技能 / find skills / 技能推荐 / 技能管理 / 卸载技能 / 技能安全审查 / 技能装太多太乱了"时触发。 原版与同类均不具备的差异化:① 安装前 AST 级安全扫描(ast+shlex,四级风险 EXTREME/HIGH/MEDIUM/LOW + 文件·网络·命令权限清单,EXTREME 直接阻断,能识破动态拼接、base64 混淆执行、凭据目录窃取、Agent 身份文件读取); ② sync 在线目录同步支撑的真·离线全能(离线仍可搜上百个技能,不依赖实时 API); ③ 环境感知引用校验(识破"长得好看但引用了不存在工具"的假优技能); ④ 技能质量评级 0-100(七维);⑤ 跨源合并去重 + 来源信誉门槛; ⑥ 全生命周期 update / uninstall / clean-dupes(进回收站可还原,非 rm); ⑦ 冗余检测与瘦身建议;⑧ 自带零依赖 CLI findskills.py(20 子命令,140 项测试全绿 + 端到端冒烟自证); ⑨ 内置 promote 自我营销引擎与 demo 可录屏演示。 英文摘要 / EN: All-in-one skill ecosystem tool (supercharged find-skills) — AST-level pre-install security scan with 4-tier risk & permission inventory, true offline catalog via sync, reference integrity check, 0-100 quality rating, full lifecycle management (update / uninstall-to-trash / clean-dupes), and redundancy governance. 20 zero-dependency subcommands, 140 passing tests, MIT.
Quick install — most popular security & compliance skill:
clawdbot install bvinci1-design/skill-scanner1,400 skills found
Page 1 of 59
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Proactive security monitoring, threat scanning, and auto-remediation for OpenClaw deployments
Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP guida...
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
Performs a two-phase audit combining a fast deterministic scan and a deep LLM quality review of security, cron jobs, config, and skills.
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
information-security-manager-iso27001ISO 27001 ISMS implementation and cybersecurity governance for HealthTech and MedTech companies. Use for ISMS design, security risk assessment, control imple...
Self-hosted auth for TypeScript/Cloudflare Workers with social auth, 2FA, passkeys, organizations, RBAC, and 15+ plugins. Requires Drizzle ORM or Kysely for D1 (no direct adapter). Self-hosted alternative to Clerk/Auth.js. Use when: self-hosting auth on D1, building OAuth provider, multi-tenant SaaS, or troubleshooting D1 adapter errors, session caching, rate limits, Expo crashes, additionalFields bugs.
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...
Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention.
GDPR and German DSGVO compliance automation. Scans codebases for privacy risks, generates DPIA documentation, tracks data subject rights requests. Use for GD...
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.
验证码识别与解决 - 本地OCR识别 + 第三方API / CAPTCHA Recognition and Solving - Local OCR + Third-party APIs
CAPA system management for medical device QMS. Covers root cause analysis, corrective action planning, effectiveness verification, and CAPA metrics. Use for...
Performs static analysis for OWASP 2025 risks, supply chain threats, secrets detection, code patterns, and prioritizes vulnerabilities by exploitability and...
Security scanner for OpenClaw/ClawHub skills. Detects malware, reverse shells, credential theft, prompt injection, memory poisoning, typosquatting, and suspicious prerequisites before installation. Use when installing new skills, auditing existing skills, checking a skill name for typosquatting, or scanning ClawHub skills for security risks.
Security scanner for OpenClaw skill packages. Scans skills for malicious code, evasion techniques, prompt injection, and misaligned behavior BEFORE installation. Use to audit any skill from ClawHub or local directories.
Senior Regulatory Affairs Manager for HealthTech and MedTech companies. Prepares FDA 510(k), De Novo, and PMA submission packages; analyzes regulatory pathwa...
Shorten URLs using is.gd (no auth required). Returns a permanent short link.
Use when building Spring Boot 3.x applications, microservices, or reactive Java applications. Invoke for Spring Data JPA, Spring Security 6, WebFlux, Spring Cloud integration.
提供智能合同风险识别、条款解读、合同生成与法律咨询,支持多合同类型,助力企业合法合规管理。
AI-first security intelligence with LLM-powered intent analysis. 743+ findings from 361+ skill audits, 25 pattern rules, 22 attack classes.
Autonomous RPC & VPN rotation for AI Agents. Ensures 99.9% uptime by bypassing geo-locks and rate limits on exchanges and Web3 protocols.
Yes. Security scanning skills detect SQL injection, XSS, CSRF, hardcoded secrets, insecure deserialization, and other OWASP issues in source code and dependencies.
Auth skills generate OAuth 2.0 flows, JWT middleware, SAML integrations, MFA setup, and role-based access control (RBAC) for common frameworks and cloud providers.