An automated security scanner that identifies malicious commands and data leak risks hidden within API documentation and integration guides.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install protocol-doc-auditor
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install protocol-doc-auditor using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Protocol Doc Auditor is a specialized security tool designed to protect developers and AI agents from documentation-based attacks. Often, integration guides include dangerous instructions like piping remote scripts to bash or sending sensitive keys via URL parameters. This skill analyzes these documents to expose hidden risks before any commands are executed.
By leveraging Openclaw Skills like this auditor, teams can ensure their integration workflows remain secure against social engineering and poorly designed setup steps. It treats documentation as a primary attack surface, catching risks that traditional code scanners might miss because the actions are performed by the user or agent following the guide.
To use this auditor within the ecosystem of Openclaw Skills, ensure your environment meets the binary requirements:
# Ensure python3 and curl are available in your system path
python3 --version
curl --version
No additional environment variables are required for basic scanning operations.
The skill generates a detailed Audit Result report organized as follows:
| Attribute | Description |
|---|---|
| Risk Index | A numbered list of identified vulnerabilities. |
| Risk Level | Categorization of the threat (e.g., CRITICAL, HIGH, MEDIUM). |
| Instruction | The specific text or command from the document that triggered the alert. |
| Risk Analysis | A detailed explanation of why the instruction is considered dangerous. |
| Safer Alternative | Actionable advice or modified commands to perform the task securely. |
| Overall Rating | A final verdict on the document: SAFE, CAUTION, or DANGEROUS. |
Loading
A security audit tool that detects unauthorized resource access and credential theft in AI agent skills by comparing declared functionality against actual code behavior.

A sophisticated security analysis tool that detects AI agent skills designed to hide malicious behavior when they sense they are being monitored in a sandbox.

Detects malicious updates in AI agent skills that pass initial security audits but introduce backdoors through subsequent automatic updates.

A specialized diagnostic tool designed to uncover hollow or fake validation tests that falsely signal AI agent skill reliability.

A security-focused verification tool that identifies impersonation, key rotation anomalies, and identity gaps in the AI agent publisher ecosystem.

Validates agent behavior at runtime against declared attestation to catch conditional attacks that bypass static analysis.








































