Automated authorized penetration testing skill with multi-layer detection, PoC/exploit generation, comprehensive vulnerability reporting, and scope safety co...
Generate compliance reports, audit access logs, and enforce security policies.
631 skills found
Page 1 of 27
Automated authorized penetration testing skill with multi-layer detection, PoC/exploit generation, comprehensive vulnerability reporting, and scope safety co...
Compare fast-changing online services using current, scoped sources for features, pricing, access rules, and policy limits.
Use when the user wants audit findings turned into a stakeholder-ready document — severities, page counts, first-seen/fixed history — as a Markdown or CSV deliverable rather than a working diagnosis.
Author, harden, and publish agent skills for ClawHub — write skills that conform to ClawHub conventions (frontmatter, structure, naming, versioning, licensing), run pre-publish hardening, and remediate clawhub.ai security-audit findings. Use when creating a skill for ClawHub, preparing a new version to publish, or when given a clawhub.ai/<owner>/<slug>/security-audit page.
Perform a security audit on exposed AI service endpoints using OpenClaw threat intelligence. Trigger when the user says "security audit", "audit my AI servic...
Ask a hosted judge before risky agent actions. Returns approve, hold, or escalate with a confidence number and the rule that fired, and keeps a reviewable decision log. Use before deleting data, spending money, touching production, or messaging customers.
技能生态的「安全策展 → 安装闸门 → 生态治理」全能工具,find-skills 的社区超级增强版(能力已超越原版与 skill-vetter 等同类)。 当用户用自然语言描述需求("我想做个海报""帮我分析股票""有没有能做 X 的技能"),或明确说 "找个 skill / 找技能 / 安装技能 / find skills / 技能推荐 / 技能管理 / 卸载技能 / 技能安全审查 / 技能装太多太乱了"时触发。 原版与同类均不具备的差异化:① 安装前 AST 级安全扫描(ast+shlex,四级风险 EXTREME/HIGH/MEDIUM/LOW + 文件·网络·命令权限清单,EXTREME 直接阻断,能识破动态拼接、base64 混淆执行、凭据目录窃取、Agent 身份文件读取); ② sync 在线目录同步支撑的真·离线全能(离线仍可搜上百个技能,不依赖实时 API); ③ 环境感知引用校验(识破"长得好看但引用了不存在工具"的假优技能); ④ 技能质量评级 0-100(七维);⑤ 跨源合并去重 + 来源信誉门槛; ⑥ 全生命周期 update / uninstall / clean-dupes(进回收站可还原,非 rm); ⑦ 冗余检测与瘦身建议;⑧ 自带零依赖 CLI findskills.py(20 子命令,140 项测试全绿 + 端到端冒烟自证); ⑨ 内置 promote 自我营销引擎与 demo 可录屏演示。 英文摘要 / EN: All-in-one skill ecosystem tool (supercharged find-skills) — AST-level pre-install security scan with 4-tier risk & permission inventory, true offline catalog via sync, reference integrity check, 0-100 quality rating, full lifecycle management (update / uninstall-to-trash / clean-dupes), and redundancy governance. 20 zero-dependency subcommands, 140 passing tests, MIT.
Use when the user wants a current site audit, technical SEO findings, Core Web Vitals interpretation, or a fresh TrustGrowth audit when connected. Supports connected, imported, and public/local evidence.
五维审计存量工程:漂移、边界、判据、组合、依赖,只读输出修复路由
Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — `SKI...
已安装 Skills 的安全审计工具。用于批量审计 Skills 的安全性,包括命令执行、网络访问、文件访问、数据泄露、依赖风险、提示词越权和触发条件检查。适用于用户提供 Skills 列表和文件内容时进行安全扫描、护栏审查、提示词越权审查或强化建议。
Comprehensive audit of all construction data sources and systems. Map data flows, identify silos, assess quality, and create integration roadmap.
Trigger an Agent Token Audit via Botlington's A2A endpoint. Use when you want to audit an AI agent's token efficiency — identifies model waste, context bloat...
Audit and harden OpenClaw configuration for security. Scans openclaw.json for vulnerabilities, exposed credentials, insecure gateway settings, overly permiss...
Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing en...
This skill details how to conduct cloud security audits using Center for Internet Security benchmarks for AWS, Azure, and GCP. It covers interpreting CIS Fou...
NIST Cybersecurity Framework (CSF) and SP 800-53 Rev 5 compliance assessment for network infrastructure. Maps device configuration against 6 control families...
Deep-scan a codebase, understand its architecture and patterns, then produce a comprehensive audit report with prioritized fixes. Optionally apply changes on...
Security audit for external resources (GitHub repos, downloaded skills, files). Detects malicious code, suspicious executables, and content mismatches. Use w...
Give AI agents on-chain spending guardrails. Deploy ERC-4337 smart accounts with policy-enforced limits — agents cannot move funds beyond what you authorize,...
Audit Azure Key Vault configuration, access policies, and secret hygiene for credential exposure risks
Audit .env alias groups for missing required config, conflicting values, and canonical-key drift before deploy.
Rapid OpenClaw launch audit focused on revenue and reliability. Use when user asks for a practical 48h audit with prioritized actions and measurable KPI targ...
Provides four-layer security for OpenClaw including static code scanning, logic audit, runtime protection, and periodic security patrols with automated reports.