Loading...
Loading...
Found 19 Skills
Analyze CVE vulnerabilities in Java and JavaScript components, determine false positives, and provide upgrade recommendations. Use this when users provide a CVE number and affected object, e.g., CVE-2024-38816 and spring-webmvc-5.3.39.jar. Supports false positive analysis, compatibility risk assessment, and standard report generation.
Main security scanning orchestration. Detects language, runs OWASP Top 10 patterns, identifies vulnerabilities, generates structured reports. Use when scanning for XSS, SQL injection, command injection, secrets, or any security vulnerability.
Automated daily security audits for OpenClaw agents with email reporting. Runs deep audits and sends formatted reports.
OpenClaw security scanning skill that performs comprehensive system security audits and generates human-friendly reports
Runs a context-aware security review of a software project — first understands what the system does and who could attack it, then adapts the analysis instead of running a static checklist. Produces a ranked, evidence-backed findings report and triages each finding by what kind of action it needs (code fix, spec change, design/ADR change, product decision, or accepted risk). Never edits the project — analysis only. Use when the user asks for a security review, security pass, security audit, or to find vulnerabilities in their project.
Analyze agent skills for security risks, malicious patterns, and potential dangers before installation. Use when asked to "audit a skill", "check if a skill is safe", "analyze skill security", "review skill risk", "should I install this skill", "is this skill safe", or when evaluating any skill directory for trust and safety. Also triggers when the user pastes a skill install command like "npx skills add https://github.com/org/repo --skill name". Produces a comprehensive security report with a clear install/reject verdict.
Comprehensive security code review workflow for a target repository, producing a markdown report with findings and recommendations.
Universal security and robustness scanner for any codebase. Use when auditing code for vulnerabilities, security issues, bugs, or robustness problems. Automatically detects tech stack, creates custom audit plans, and performs recursive deep analysis.
Identify, analyze, and report malicious software distribution repositories masquerading as legitimate security tools
Audit installed skills for malicious code, hidden instructions, and security vulnerabilities. Use when users want to scan their skills for potential security issues, verify skill safety before use, or investigate suspicious skill behavior.
Web application security testing workflow for OWASP Top 10 vulnerabilities including injection, XSS, authentication flaws, and access control issues.
Comprehensive security audit of codebase using multiple security-auditor agents. Use before production deployments or after major features.