An automated security and privacy auditing skill that performs deep SAST analysis to identify vulnerabilities and PII leaks in codebases.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install securityreview
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install securityreview using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Security Shield is a professional-grade security analysis tool designed for AI agents to conduct Static Application Security Testing (SAST). Acting as a senior security engineer, this skill meticulously scans repositories for modern vulnerabilities, ranging from hardcoded secrets to complex LLM-specific safety risks. It follows a strict Fail Securely principle, ensuring that all external inputs are treated as malicious until validated and sanitized.
By integrating this skill into your Openclaw Skills library, developers can automate the detection of broken access control, injection flaws, and privacy violations. The tool is engineered to provide high-fidelity reporting, minimizing false positives by focusing exclusively on executable code and direct evidence, ensuring that every finding is actionable and impactful for the engineering team.
To activate this skill within your Openclaw Skills environment, no complex installation is required. Ensure your agent has permission to execute read-only CLI commands.
# Trigger a comprehensive security scan of your current workspace
/security:full-analyze
The skill will automatically create a .shield_security/ directory in your project root to store persistent audit artifacts and historical reports.
The skill organizes its findings using a structured taxonomy to ensure clarity and compliance:
| Component | Description |
|---|---|
| .shield_security/ | Dedicated workspace directory for storing vulnerability reports and scan metadata. |
| Vulnerability Report | A detailed breakdown containing vulnerability name, type, severity, and exact source/sink locations. |
| Privacy Taint Map | A logical map tracing PII (emails, tokens) from entry points to potential exposure sinks. |
| Severity Rubric | A standardized assessment matrix (Critical, High, Medium, Low) based on exploit impact and complexity. |
Loading
A high-performance command-line tool for private, local speech-to-text transcription optimized for Apple Silicon.

A powerful bridge connecting the EvoAgentX framework to Openclaw Skills for creating agentic workflows that automatically improve through evolutionary optimization.

Seamlessly manage Jira issues, transitions, and worklogs through a powerful CLI-driven interface.

A secure, developer-centric integration for managing Google Calendar and Gmail using private Google Cloud Platform credentials across multiple accounts.

A professional security auditing tool designed to identify vulnerabilities, instruction injections, and data exfiltration risks within codebases and agent configurations.

A sophisticated extraction engine that converts Instagram reels into structured recipes using caption parsing, local audio transcription, and vision analysis.








































