Kedro Security Review
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.
$ npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills clawsec-scanner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/clawsec-scanner .claude/skills/clawsec-scanner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "clawsec-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/clawsec-scanner into .claude/skills/clawsec-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clawsec-scanner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/clawsec-scannerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills clawsec-scanner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/clawsec-scanner .agents/skills/clawsec-scanner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "clawsec-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/clawsec-scanner into .agents/skills/clawsec-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clawsec-scanner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills clawsec-scanner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/clawsec-scanner .cursor/skills/clawsec-scanner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "clawsec-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/clawsec-scanner into .cursor/skills/clawsec-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clawsec-scanner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/LeoYeAI/openclaw-master-skills.git --path skills/clawsec-scanner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills clawsec-scanner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/clawsec-scanner .gemini/skills/clawsec-scanner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "clawsec-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/clawsec-scanner into .gemini/skills/clawsec-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clawsec-scanner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install LeoYeAI/openclaw-master-skills clawsec-scannerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/clawsec-scanner .github/skills/clawsec-scanner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "clawsec-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/clawsec-scanner into .github/skills/clawsec-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clawsec-scanner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install LeoYeAI/openclaw-master-skills clawsec-scanner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/clawsec-scanner .opencode/skills/clawsec-scanner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "clawsec-scanner" agent skill from https://github.com/LeoYeAI/openclaw-master-skills/tree/main/skills/clawsec-scanner into .opencode/skills/clawsec-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "clawsec-scanner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
clawsec-scannerAutomated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.
Clawsec Scanner is an agent skill from LeoYeAI/openclaw-master-skills. Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific DAST hook execution testing for OpenClaw hooks.
Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 27 other files, including scripts (for example `CHANGELOG.md`, `_meta.json` and `hooks/clawsec-scanner-hook/HOOK.md`).
It sits in Security, covering Static analysis and SAST, Vulnerability scanning and Dependency management. It works with GitHub, Semgrep and Python. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 7 files in scripts/ (JavaScript, TypeScript and Shell, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
nodenpmcurlnpxjqpippython3semgrepopensslpythonruffshellcheckFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comAlso links to:
clawsec.prompt.securityosv.devnvd.nist.govsemgrep.devbandit.readthedocs.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CLAWSEC_NVD_API_KEYGITHUB_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Clawsec Scanner loads about 4.1k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 1,088 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,088 words, ~4,088 tokens.
.claude/skills/clawsec-scanner/SKILL.md (or your agent's skills folder). This skill also uses 23 other files; get the full folder from GitHub.Comprehensive security scanner for agent platforms that automates vulnerability detection across multiple dimensions:
npm audit and pip-audit with structured JSON output parsingThe scanner orchestrates four complementary scan types to provide comprehensive vulnerability coverage:
Dependency Scanning
npm audit --json and pip-audit -f json as subprocessesCVE Database Queries
Vulnerability schemaStatic Analysis (SAST)
--config auto or --config p/security-auditpyproject.toml configurationeval, exec), path traversal, unsafe deserializationDynamic Analysis (DAST)
HOOK.md metadataAll scan types emit a consistent ScanReport JSON schema:
{
scan_id: string; // UUID
timestamp: string; // ISO 8601
target: string; // Scanned path
vulnerabilities: Vulnerability[];
summary: {
critical: number;
high: number;
medium: number;
low: number;
info: number;
}
}Each Vulnerability object includes:
id: CVE-2023-12345 or GHSA-xxxx-yyyy-zzzzsource: npm-audit | pip-audit | osv | nvd | github | sast | dastseverity: critical | high | medium | low | infopackage: Package name (or 'N/A' for SAST/DAST)version: Affected versionfixed_version: First version with fix (if available)title: Short descriptiondescription: Full advisory textreferences: URLs for more infodiscovered_at: ISO 8601 timestampAutomated continuous monitoring via hook:
agent:bootstrap and command:new eventsevent.messages array with severity summaryCLAWSEC_SCANNER_INTERVAL environment variableVerify required binaries are available:
# Core runtimes
node --version # v20+
npm --version
python3 --version # 3.10+
# Scanning tools
pip-audit --version # Install: uv pip install pip-audit
semgrep --version # Install: pip install semgrep OR brew install semgrep
bandit --version # Install: uv pip install bandit
# Utilities
jq --version
curl --versionnpx clawhub@latest install clawsec-scannerset -euo pipefail
VERSION="${SKILL_VERSION:?Set SKILL_VERSION (e.g. 0.1.0)}"
INSTALL_ROOT="${INSTALL_ROOT:-$HOME/.openclaw/skills}"
DEST="$INSTALL_ROOT/clawsec-scanner"
BASE="https://github.com/prompt-security/clawsec/releases/download/clawsec-scanner-v${VERSION}"
TEMP_DIR="$(mktemp -d)"
trap 'rm -rf "$TEMP_DIR"' EXIT
# Pinned release-signing public key
# Fingerprint (SHA-256 of SPKI DER): 711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8
cat > "$TEMP_DIR/release-signing-public.pem" <<'PEM'
-----BEGIN PUBLIC KEY-----
MCowBQYDK2VwAyEAS7nijfMcUoOBCj4yOXJX+GYGv2pFl2Yaha1P4v5Cm6A=
-----END PUBLIC KEY-----
PEM
ZIP_NAME="clawsec-scanner-v${VERSION}.zip"
# Download release archive + signed checksums
curl -fsSL "$BASE/$ZIP_NAME" -o "$TEMP_DIR/$ZIP_NAME"
curl -fsSL "$BASE/checksums.json" -o "$TEMP_DIR/checksums.json"
curl -fsSL "$BASE/checksums.sig" -o "$TEMP_DIR/checksums.sig"
# Verify checksums manifest signature
openssl base64 -d -A -in "$TEMP_DIR/checksums.sig" -out "$TEMP_DIR/checksums.sig.bin"
if ! openssl pkeyutl -verify \
-pubin \
-inkey "$TEMP_DIR/release-signing-public.pem" \
-sigfile "$TEMP_DIR/checksums.sig.bin" \
-rawin \
-in "$TEMP_DIR/checksums.json" >/dev/null 2>&1; then
echo "ERROR: checksums.json signature verification failed" >&2
exit 1
fi
EXPECTED_SHA="$(jq -r '.archive.sha256 // empty' "$TEMP_DIR/checksums.json")"
if [ -z "$EXPECTED_SHA" ]; then
echo "ERROR: checksums.json missing archive.sha256" >&2
exit 1
fi
ACTUAL_SHA="$(shasum -a 256 "$TEMP_DIR/$ZIP_NAME" | awk '{print $1}')"
if [ "$EXPECTED_SHA" != "$ACTUAL_SHA" ]; then
echo "ERROR: Archive checksum mismatch" >&2
exit 1
fi
echo "Checksums verified. Installing..."
mkdir -p "$INSTALL_ROOT"
rm -rf "$DEST"
unzip -q "$TEMP_DIR/$ZIP_NAME" -d "$INSTALL_ROOT"
chmod 600 "$DEST/skill.json"
find "$DEST" -type f ! -name "skill.json" -exec chmod 644 {} \;
echo "Installed clawsec-scanner v${VERSION} to: $DEST"
echo "Next step: Run a scan or set up continuous monitoring"SCANNER_DIR="${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner"
# Scan all skills with JSON output
"$SCANNER_DIR/scripts/runner.sh" --target ./skills/ --output report.json --format json
# Scan specific directory with human-readable output
"$SCANNER_DIR/scripts/runner.sh" --target ./my-skill/ --format text
# Check available flags
"$SCANNER_DIR/scripts/runner.sh" --helpCLI Flags:
--target <path>: Directory to scan (required)--output <file>: Write results to file (optional, defaults to stdout)--format <json|text>: Output format (default: json)--check: Verify all required binaries are installedEnable automated periodic scanning:
SCANNER_DIR="${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner"
node "$SCANNER_DIR/scripts/setup_scanner_hook.mjs"This creates a hook that:
agent:bootstrap and command:new eventsCLAWSEC_SCANNER_INTERVAL rate limiting (default: 86400 seconds / 24 hours)Restart the OpenClaw gateway after enabling the hook, then run /new to trigger an immediate scan.
# Optional - NVD API key to avoid rate limiting (6-second delays without key)
export CLAWSEC_NVD_API_KEY="your-nvd-api-key"
# Optional - GitHub OAuth token for Advisory Database queries
export GITHUB_TOKEN="ghp_your_token_here"
# Optional - Scanner hook interval in seconds (default: 86400 / 24 hours)
export CLAWSEC_SCANNER_INTERVAL="86400"
# Optional - Allow unsigned advisory feed during development (from clawsec-suite)
export CLAWSEC_ALLOW_UNSIGNED_FEED="1"Each scan type is an independent module that can run standalone or as part of unified scan:
scripts/runner.sh # Orchestration layer
├── scan_dependencies.mjs # npm audit + pip-audit
├── query_cve_databases.mjs # OSV/NVD/GitHub API queries
├── sast_analyzer.mjs # Semgrep + Bandit static analysis
├── dast_runner.mjs # Dynamic security testing orchestration
└── dast_hook_executor.mjs # Isolated real hook execution harness
lib/
├── report.mjs # Result aggregation and formatting
├── utils.mjs # Subprocess exec, JSON parsing, error handling
└── types.ts # TypeScript schema definitions
hooks/clawsec-scanner-hook/
├── HOOK.md # OpenClaw hook metadata
└── handler.ts # Periodic scan triggerThe scanner prioritizes availability over strict failure propagation:
Critical failures that exit immediately:
All external tools run as subprocesses with structured JSON output:
import { spawn } from 'node:child_process';
// Example: npm audit execution
const proc = spawn('npm', ['audit', '--json'], {
cwd: targetPath,
stdio: ['ignore', 'pipe', 'pipe']
});
// Handle non-zero exit codes gracefully
// npm audit exits 1 when vulnerabilities found (not an error!)
proc.on('close', code => {
if (code !== 0 && stderr.includes('ERR!')) {
// Actual error
reject(new Error(stderr));
} else {
// Vulnerabilities found or success
resolve(JSON.parse(stdout));
}
});"Missing package-lock.json" warning
npm audit requires lockfile to runnpm install in target directory to generate"NVD API rate limit exceeded"
CLAWSEC_NVD_API_KEY environment variable"pip-audit not found"
uv pip install pip-audit or pip install pip-auditwhich pip-audit"Semgrep binary missing"
pip install semgrep OR brew install semgrepreturntocorp/semgrep"TypeScript hook not executable in DAST harness"
handler.ts files when a TypeScript compiler is availablenpm install -D typescript (or provide handler.js/handler.mjs)info-level coverage finding instead of a high-severity vulnerability"Concurrent scan detected"
/tmp/clawsec-scanner.lockCheck scanner is working correctly:
# Verify required binaries
./scripts/runner.sh --check
# Run unit tests
node test/dependency_scanner.test.mjs
node test/cve_integration.test.mjs
node test/sast_engine.test.mjs
node test/dast_harness.test.mjs
# Validate skill structure
python ../../utils/validate_skill.py .
# Scan test fixtures (should detect known vulnerabilities)
./scripts/runner.sh --target test/fixtures/ --format text# All tests (vanilla Node.js, no framework)
for test in test/*.test.mjs; do
node "$test" || exit 1
done
# Individual test suites
node test/dependency_scanner.test.mjs # Dependency scanning
node test/cve_integration.test.mjs # CVE database APIs
node test/sast_engine.test.mjs # Static analysis
node test/dast_harness.test.mjs # DAST harness execution# JavaScript/TypeScript
npx eslint . --ext .ts,.tsx,.js,.jsx,.mjs --max-warnings 0
# Python (Bandit already configured in pyproject.toml)
ruff check .
bandit -r . -ll
# Shell scripts
shellcheck scripts/*.shCreate custom rules in .semgrep/rules/:
rules:
- id: custom-security-rule
pattern: dangerous_function($ARG)
message: Avoid dangerous_function - use safe_alternative instead
severity: WARNING
languages: [javascript, typescript]Update scripts/sast_analyzer.mjs to include custom rules:
const proc = spawn('semgrep', [
'scan',
'--config', 'auto',
'--config', '.semgrep/rules/', // Add custom rules
'--json',
targetPath
]);The scanner works standalone or as part of the ClawSec ecosystem:
Install the full ClawSec suite:
npx clawhub@latest install clawsec-suite
# Then use clawsec-suite to discover and install clawsec-scannerCritical/High severity findings should be addressed immediately:
Medium/Low severity findings can be addressed in normal sprint cycles:
Info findings are advisory only:
Found a security issue? Please report privately to security@prompt.security.
For feature requests and bug reports, open an issue at: https://github.com/prompt-security/clawsec/issues
AGPL-3.0-or-later
See LICENSE file in repository root for full text.
© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 23 other files (scripts) in skills/clawsec-scanner of LeoYeAI/openclaw-master-skills.
Open the folder on GitHubat commit e5199b5
Clawsec Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Clawsec Scanner this skillLeoYeAI/openclaw-master-skills | 2.2k | — | ~4.1k | Automated safety check: Pass | MIT | |
| Kedro Security Reviewkedro-org/kedro | 11k | — | ~3.3k | Automated safety check: Pass | Custom licence | |
| Pyspector Security AuditParzivalHack/PySpector | 151 | — | ~3.5k | Automated safety check: Notes | Apache-2.0 | |
| Security Vulnerabilities Patcheraxelixlabs/axelix | 148 | — | ~4.2k | Automated safety check: Pass | LGPL-3.0 | |
| CodeQL Security Scantrailofbits/skills | 7.4k | — | ~4.6k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Security Verification Gatefengshao1227/ccg-workflow | 5.9k | — | ~621 | Automated safety check: Notes | MIT |
kedro-org/kedro
Run a Kedro security scan on the full codebase or just a pull request.
ParzivalHack/PySpector
Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.
axelixlabs/axelix
Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
fengshao1227/ccg-workflow
Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.
tradecatlabs/vibe-coding-cn
Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.
LeoYeAI/openclaw-master-skills
Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.
LeoYeAI/openclaw-master-skills
Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.
LeoYeAI/openclaw-master-skills
Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.
LeoYeAI/openclaw-master-skills
Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.
LeoYeAI/openclaw-master-skills
Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.
LeoYeAI/openclaw-master-skills
Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.
Categories
Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills. Clawsec Scanner is an agent skill from LeoYeAI/openclaw-master-skills. Automated vulnerability scanner for agent platforms.
Clawsec Scanner fits situations like: tasks that involve Static analysis and SAST; tasks that involve Vulnerability scanning; tasks that involve Dependency management.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a claude-code`. Or copy the skill folder (skills/clawsec-scanner in LeoYeAI/openclaw-master-skills) into .claude/skills/clawsec-scanner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a codex`. Or copy the skill folder (skills/clawsec-scanner in LeoYeAI/openclaw-master-skills) into .agents/skills/clawsec-scanner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clawsec-scanner, .gemini/skills/clawsec-scanner, .github/skills/clawsec-scanner and .opencode/skills/clawsec-scanner in your project.
Going by SKILL.md and its folder, Clawsec Scanner needs JavaScript, TypeScript and a shell for the scripts in its folder, the command-line tools its instructions call (node, npm, curl, npx, jq and pip) and credentials named CLAWSEC_NVD_API_KEY and GITHUB_TOKEN. Our summary lists: Python 3; Node.js; A Bash shell; Docker; A credential in CLAWSEC_NVD_API_KEY.
SKILL.md names 6 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: clawsec.prompt.security, osv.dev, nvd.nist.gov, semgrep.dev and bandit.readthedocs.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Clawsec Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Clawsec Scanner: Kedro Security Review (kedro-org/kedro, 11k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Security Vulnerabilities Patcher (axelixlabs/axelix, 148 stars) and CodeQL Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.
Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.