Skip to content
Back to skills

Agxntsix Skill Auditor

ASecurity

Security audit and quarantine system for third-party OpenClaw skills. Use when evaluating, reviewing, or installing any skill from ClawHub or external sources. Automatically triggered before any skill installation.

  • 14 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 7, 2026
securitypythonrustshellbashsecurity

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill agxntsix-skill-auditor --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Agxntsix Skill Auditor?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Agxntsix Skill Auditor
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-agxntsix-skill-auditor/badge)](https://www.skillsdirectory.com/skills/modbender-agxntsix-skill-auditor)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: skill-auditor
description: Security audit and quarantine system for third-party OpenClaw skills. Use when evaluating, reviewing, or installing any skill from ClawHub or external sources. Automatically triggered before any skill installation.
---

# Skill Auditor

Security gatekeeper for third-party skill installation. **No skill gets installed without passing audit.**

## When to Use

- Before installing ANY skill from ClawHub or external sources
- When asked to review/evaluate a skill's safety
- When `clawhub install` or similar installation is requested

## Audit Workflow

### 1. Quarantine First
Never copy a skill directly to the production skills directory. Always quarantine first:

```bash
bash skills/skill-auditor/scripts/quarantine.sh /path/to/skill-source
```

This copies the skill to a temp directory, runs the full audit, and only allows installation if the risk score is CLEAN or LOW.

### 2. Manual Audit (Python Script Directly)
For inspection without the quarantine wrapper:

```bash
python3 skills/skill-auditor/scripts/audit_skill.py /path/to/skill-dir
```

Outputs JSON report to stdout. Add `--human` for formatted text output.

### 3. Interpreting Results

| Rating | Action |
|--------|--------|
| CLEAN | Safe to install |
| LOW | Safe, minor notes — review findings briefly |
| MEDIUM | **Do NOT install** without manual review of each finding |
| HIGH | **Block installation** — likely malicious patterns detected |
| CRITICAL | **Block immediately** — active threat indicators (exfil, prompt injection, obfuscated payloads) |

### 4. Exit Codes
- `0` = CLEAN or LOW (safe)
- `1` = MEDIUM (needs review)
- `2` = HIGH or CRITICAL (blocked)

## What Gets Scanned

- All files: inventory, sizes, suspicious file types
- Code: shell commands, network calls, env access, filesystem escape, obfuscation, dynamic imports
- SKILL.md: prompt injection patterns, permission scope requests
- Dependencies: requirements.txt / package.json flagged packages
- Encoding: base64 payloads, hex/unicode escapes, string manipulation tricks

## References

- `references/known-patterns.md` — catalog of real attack patterns from ClawHub
- `references/prompt-injection-patterns.md` — prompt injection signatures to detect

## Important

If a skill scores MEDIUM or above, **always show Abidi the full findings** before taking any action. Never override or bypass the auditor. This is the last line of defense before untrusted code enters the system.

Files in this skill

  • SKILL.md2.5 KB
  • references/known-patterns.md3.9 KB
  • references/prompt-injection-patterns.md2.4 KB
  • scripts/audit_skill.py24.5 KB
  • scripts/quarantine.sh2.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…