xfire leverages multiple AI agents in an adversarial debate to find and verify security vulnerabilities in your codebase.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install xfire-security-review
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install xfire-security-review using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
xfire is a sophisticated security auditing tool designed to eliminate blind spots by employing a multi-agent adversarial approach. By sending code to three distinct AI models—Claude, Codex, and Gemini—it ensures independent findings that are then rigorously cross-examined through a prosecution, defense, and judge pipeline. This process filters out false positives and ensures that only the most critical, verified vulnerabilities make it into the final report.
As one of the most robust Openclaw Skills available, xfire transforms how developers approach automated security reviews. It goes beyond simple pattern matching by using large language models to understand intent, trust boundaries, and complex logic flaws that traditional static analysis tools often miss.
To begin using this skill, ensure you have Python 3.11+ installed and then follow these steps:
# Install the package
pip install xfire
# Initialize configuration in your current repository
xfire init
# Configure your AI agent credentials
xfire auth login --provider claude
# Test connectivity to the AI models
xfire test-llm
xfire organizes its analysis using structured configuration files and persistent data stores to maintain context across Openclaw Skills workflows:
| Component | Description |
|---|---|
| .xfire/config.yaml | Primary configuration for agent roles, sensitive paths, and severity gates. |
| XFIRE_CACHE_DIR | Directory for storing repository context and intent persistence to speed up subsequent scans. |
| XFIRE_AUTH_PATH | Secure store for agent credentials and authentication tokens. |
| SARIF / JSON Reports | Standardized output including CWE mappings, severity levels, and confidence scores. |
Loading
A secure automation skill for managing 1Password CLI operations and secret injection within AI agent workflows.

A standardized messaging and discovery protocol that allows AI agents to communicate, collaborate on tasks, and share information across different providers.

An advanced browser automation skill providing programmatic control over web interfaces using the Playwright framework.

A managed headful Chrome browser solution designed for Openclaw agents to bypass bot detection through VNC takeover and session isolation.

A technical integration for AI agents to retrieve, parse, and interpret astrological data from the Grupo Venus platform.

A minimal, offline-first CLI tool for cross-chain wallet generation and message signing across EVM, Solana, Bitcoin, and more.








































