A non-intrusive security tool that scans deployed URLs for exposed secrets, source code, and misconfigured infrastructure.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install preflyt
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install preflyt using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Preflyt is a specialized security auditing skill designed for the post-deployment phase of web development. It functions as an automated inspector that probes public-facing URLs to ensure no sensitive information—such as .env files, database credentials, or .git repositories—is accidentally exposed to the internet. As a vital addition to the Openclaw Skills ecosystem, it provides developers with a safety net that catches common devops oversights before they can be exploited by malicious actors.
This skill is particularly valuable because it performs read-only, non-intrusive checks from an outside-in perspective, mimicking how a scanner might first scout a target. By integrating this into your daily workflow, you ensure that every infrastructure change or code push is validated against high-severity security risks without requiring complex manual auditing processes.
To use this tool within the Openclaw Skills environment, ensure you have Node.js installed. You can run a scan manually using npx:
npx preflyt-check https://your-deployed-url.com
To integrate it into automated deployment scripts or CI/CD pipelines and force a failure on security findings:
npx preflyt-check https://your-deployed-url.com --fail
For users with a Pro license, you can activate unlimited scans by including your license key:
npx preflyt-check https://your-deployed-url.com --key YOUR_LICENSE_KEY
Preflyt organizes scan results into severity levels and specific technical categories. The following structure outlines the data evaluated during a scan:
| Category | Items Scanned |
|---|---|
| Secrets | .env, config.json, database passwords, API keys |
| Source Leakage | .git folders, .svn, server.js, app.py, source maps |
| Databases | Exposed ports for MySQL, Postgres, Redis, MongoDB |
| Security Headers | HSTS, Content-Security-Policy, X-Frame-Options |
| Server Config | Directory listings, server version leakage, insecure cookies |
All results are displayed in the terminal by default to maintain privacy. If the --share flag is used, a temporary report is generated on preflyt.dev for team review.
--fail flag if the scan detects vulnerabilities.Loading
Valinor is a Multi-Agent Dungeon (MAD) infrastructure that allows AI agents to meet, interact, and collaborate in a shared virtual environment.

Provides comprehensive insights into repository size, complexity, and language distribution.

A file-based planning and execution workflow designed to provide AI agents with structured task management and change control.

A robust file-based framework for managing complex AI agent tasks through structured planning, change control, and isolated execution sessions.

Automate your Amazon affiliate marketing with AI-driven product recommendations that match your content perfectly.

A bidirectional bridge enabling Clawdbot to delegate complex, autonomous coding and research tasks to the Agent Zero framework.








































