A professional security auditing tool designed to identify vulnerabilities, instruction injections, and data exfiltration risks within codebases and agent configurations.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install skill-security-audit
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install skill-security-audit using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Security Analysis skill is a specialized utility for Openclaw Skills designed to perform deep security audits and vulnerability assessments. It enables AI agents to systematically scan source code for critical flaws such as injection vulnerabilities, broken access control, and hardcoded secrets.
By adhering to the principle of least privilege and assuming all external input is malicious, this skill ensures that security reviews are both thorough and safe. It provides a robust layer of defense for modern development workflows by identifying not just standard code vulnerabilities, but also agent-specific threats like instruction injection and hidden malicious directives.
To enable security auditing within your Openclaw Skills environment, ensure the security-analysis skill is correctly referenced in your agent configuration. You can initiate a scan by targeting a specific directory:
# Example command to trigger a security review
openclaw run security-analysis --path ./src
The tool requires read permissions for the target files. All analysis artifacts and reports will be saved to the .shield_security/ directory automatically.
The skill organizes its findings into a structured taxonomy to ensure clarity and actionable insights.
| Field | Description |
|---|---|
| Vulnerability | The brief name and type of the security flaw |
| Severity | Impact rating (Critical to Low) based on the severity rubric |
| Location | Precise file path and line numbers where the issue exists |
| Content | The specific code snippet or instruction that is vulnerable |
| Recommendation | A detailed explanation of how to remediate the identified risk |
Technical artifacts and logs are maintained within the .shield_security/ folder to isolate security data from the main project source.
Loading
An automated security and privacy auditing skill that performs deep SAST analysis to identify vulnerabilities and PII leaks in codebases.

A high-performance command-line tool for private, local speech-to-text transcription optimized for Apple Silicon.

A powerful bridge connecting the EvoAgentX framework to Openclaw Skills for creating agentic workflows that automatically improve through evolutionary optimization.

Seamlessly manage Jira issues, transitions, and worklogs through a powerful CLI-driven interface.

A sophisticated extraction engine that converts Instagram reels into structured recipes using caption parsing, local audio transcription, and vision analysis.

An AI agent skill that enables real-time search and booking for in-network doctors using the Zocdoc infrastructure.








































