Agent skill

Clawsec Scanner

by LeoYeAI in LeoYeAI/openclaw-master-skills

Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

MITAuto-check passedSecurity

Install Clawsec Scanner

skills CLI
$ npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LeoYeAI/openclaw-master-skills clawsec-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LeoYeAI/openclaw-master-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/clawsec-scanner .claude/skills/clawsec-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clawsec-scanner
GitHub stars
2.2k
Token cost
~4.1k tokens
SKILL.md length
1,088 words
Files
24 (incl. scripts)
Skills in repo
1,235
Repo updated
First seen
Licence
MIT

At a glance

Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills.

  • Works in 4 steps: Dependency Scanning → CVE Database Queries → Static Analysis (SAST) → …
  • Tasks that involve Static analysis and SAST
  • SKILL.md covers Features, Installation, Usage and Architecture, plus 5 more sections
  • Runs JavaScript, TypeScript and Shell scripts from its folder; calls node, npm and curl; reaches github.com; needs CLAWSEC_NVD_API_KEY and GITHUB_TOKEN

What it does

Clawsec Scanner is an agent skill from LeoYeAI/openclaw-master-skills. Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific DAST hook execution testing for OpenClaw hooks.

Its SKILL.md is about 4.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 27 other files, including scripts (for example `CHANGELOG.md`, `_meta.json` and `hooks/clawsec-scanner-hook/HOOK.md`).

It sits in Security, covering Static analysis and SAST, Vulnerability scanning and Dependency management. It works with GitHub, Semgrep and Python. The repository describes itself as: 🧠 Curated collection of 1209+ best OpenClaw skills — weekly updated by MyClaw.ai. The licence is MIT.

When your agent uses it

  • Tasks that involve Static analysis and SAST
  • Tasks that involve Vulnerability scanning
  • Tasks that involve Dependency management

Example prompts

  • “/clawsec-scanner”

Requirements

  • Python 3
  • Node.js
  • A Bash shell
  • Docker
  • A credential in CLAWSEC_NVD_API_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Dependency Scanning
  2. CVE Database Queries
  3. Static Analysis (SAST)
  4. Dynamic Analysis (DAST)

What it can do on your machine

Read from SKILL.md and the folder at commit e5199b5. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 7 files in scripts/ (JavaScript, TypeScript and Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • npm
    • curl
    • npx
    • jq
    • pip
    • python3
    • semgrep
    • openssl
    • python
    • ruff
    • shellcheck

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    Also links to:

    • clawsec.prompt.security
    • osv.dev
    • nvd.nist.gov
    • semgrep.dev
    • bandit.readthedocs.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CLAWSEC_NVD_API_KEY
    • GITHUB_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Clawsec Scanner loads about 4.1k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 1,088 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from LeoYeAI/openclaw-master-skills at commit e5199b5, republished under its MIT licence (© LeoYeAI). 1,088 words, ~4,088 tokens.

Download SKILL.mdSave it as .claude/skills/clawsec-scanner/SKILL.md (or your agent's skills folder). This skill also uses 23 other files; get the full folder from GitHub.
name
clawsec-scanner
description
Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific DAST hook execution testing for OpenClaw hooks.
version
0.0.2
homepage
https://clawsec.prompt.security
clawdis.emoji
🔍

ClawSec Scanner

Comprehensive security scanner for agent platforms that automates vulnerability detection across multiple dimensions:

  • Dependency Scanning: Analyzes npm and Python dependencies using npm audit and pip-audit with structured JSON output parsing
  • CVE Database Integration: Queries OSV (primary), NVD 2.0, and GitHub Advisory Database for vulnerability enrichment
  • SAST Analysis: Static code analysis using Semgrep (JavaScript/TypeScript) and Bandit (Python) to detect hardcoded secrets, command injection, path traversal, and unsafe deserialization
  • DAST Framework: Agent-specific dynamic analysis with real OpenClaw hook execution harness (malicious input, timeout, output bounds, event mutation safety)
  • Unified Reporting: Consolidated vulnerability reports with severity classification and remediation guidance
  • Continuous Monitoring: OpenClaw hook integration for automated periodic scanning

Features

Multi-Engine Scanning

The scanner orchestrates four complementary scan types to provide comprehensive vulnerability coverage:

  1. Dependency Scanning

    • Executes npm audit --json and pip-audit -f json as subprocesses
    • Parses structured output to extract CVE IDs, severity, affected versions
    • Handles edge cases: missing package-lock.json, zero vulnerabilities, malformed JSON
  2. CVE Database Queries

    • OSV API (primary): Free, no authentication, broad ecosystem support (npm, PyPI, Go, Maven)
    • NVD 2.0 (optional): Requires API key to avoid 6-second rate limiting
    • GitHub Advisory Database (optional): GraphQL API with OAuth token
    • Normalizes all API responses to unified Vulnerability schema
  3. Static Analysis (SAST)

    • Semgrep for JavaScript/TypeScript: Detects security issues using --config auto or --config p/security-audit
    • Bandit for Python: Leverages existing pyproject.toml configuration
    • Identifies: hardcoded secrets (API keys, tokens), command injection (eval, exec), path traversal, unsafe deserialization
  4. Dynamic Analysis (DAST)

    • Real hook execution harness for OpenClaw hook handlers discovered from HOOK.md metadata
    • Verifies: malicious input resilience, timeout behavior, output amplification bounds, and core event mutation safety
    • Note: Traditional web DAST tools (ZAP, Burp) do not apply to agent platforms - this provides agent-specific testing
Unified Reporting

All scan types emit a consistent ScanReport JSON schema:

typescript
{
  scan_id: string;         // UUID
  timestamp: string;       // ISO 8601
  target: string;          // Scanned path
  vulnerabilities: Vulnerability[];
  summary: {
    critical: number;
    high: number;
    medium: number;
    low: number;
    info: number;
  }
}

Each Vulnerability object includes:

  • id: CVE-2023-12345 or GHSA-xxxx-yyyy-zzzz
  • source: npm-audit | pip-audit | osv | nvd | github | sast | dast
  • severity: critical | high | medium | low | info
  • package: Package name (or 'N/A' for SAST/DAST)
  • version: Affected version
  • fixed_version: First version with fix (if available)
  • title: Short description
  • description: Full advisory text
  • references: URLs for more info
  • discovered_at: ISO 8601 timestamp
OpenClaw Integration

Automated continuous monitoring via hook:

  • Runs scanner on configurable interval (default: 86400s / 24 hours)
  • Triggers on agent:bootstrap and command:new events
  • Posts findings to event.messages array with severity summary
  • Rate-limited by CLAWSEC_SCANNER_INTERVAL environment variable

Installation

Prerequisites

Verify required binaries are available:

bash
# Core runtimes
node --version  # v20+
npm --version
python3 --version  # 3.10+

# Scanning tools
pip-audit --version  # Install: uv pip install pip-audit
semgrep --version    # Install: pip install semgrep OR brew install semgrep
bandit --version     # Install: uv pip install bandit

# Utilities
jq --version
curl --version
bash
npx clawhub@latest install clawsec-scanner
Option B: Manual installation with verification
bash
set -euo pipefail

VERSION="${SKILL_VERSION:?Set SKILL_VERSION (e.g. 0.1.0)}"
INSTALL_ROOT="${INSTALL_ROOT:-$HOME/.openclaw/skills}"
DEST="$INSTALL_ROOT/clawsec-scanner"
BASE="https://github.com/prompt-security/clawsec/releases/download/clawsec-scanner-v${VERSION}"

TEMP_DIR="$(mktemp -d)"
trap 'rm -rf "$TEMP_DIR"' EXIT

# Pinned release-signing public key
# Fingerprint (SHA-256 of SPKI DER): 711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8
cat > "$TEMP_DIR/release-signing-public.pem" <<'PEM'
-----BEGIN PUBLIC KEY-----
MCowBQYDK2VwAyEAS7nijfMcUoOBCj4yOXJX+GYGv2pFl2Yaha1P4v5Cm6A=
-----END PUBLIC KEY-----
PEM

ZIP_NAME="clawsec-scanner-v${VERSION}.zip"

# Download release archive + signed checksums
curl -fsSL "$BASE/$ZIP_NAME" -o "$TEMP_DIR/$ZIP_NAME"
curl -fsSL "$BASE/checksums.json" -o "$TEMP_DIR/checksums.json"
curl -fsSL "$BASE/checksums.sig" -o "$TEMP_DIR/checksums.sig"

# Verify checksums manifest signature
openssl base64 -d -A -in "$TEMP_DIR/checksums.sig" -out "$TEMP_DIR/checksums.sig.bin"
if ! openssl pkeyutl -verify \
  -pubin \
  -inkey "$TEMP_DIR/release-signing-public.pem" \
  -sigfile "$TEMP_DIR/checksums.sig.bin" \
  -rawin \
  -in "$TEMP_DIR/checksums.json" >/dev/null 2>&1; then
  echo "ERROR: checksums.json signature verification failed" >&2
  exit 1
fi

EXPECTED_SHA="$(jq -r '.archive.sha256 // empty' "$TEMP_DIR/checksums.json")"
if [ -z "$EXPECTED_SHA" ]; then
  echo "ERROR: checksums.json missing archive.sha256" >&2
  exit 1
fi

ACTUAL_SHA="$(shasum -a 256 "$TEMP_DIR/$ZIP_NAME" | awk '{print $1}')"
if [ "$EXPECTED_SHA" != "$ACTUAL_SHA" ]; then
  echo "ERROR: Archive checksum mismatch" >&2
  exit 1
fi

echo "Checksums verified. Installing..."

mkdir -p "$INSTALL_ROOT"
rm -rf "$DEST"
unzip -q "$TEMP_DIR/$ZIP_NAME" -d "$INSTALL_ROOT"

chmod 600 "$DEST/skill.json"
find "$DEST" -type f ! -name "skill.json" -exec chmod 644 {} \;

echo "Installed clawsec-scanner v${VERSION} to: $DEST"
echo "Next step: Run a scan or set up continuous monitoring"

Usage

On-Demand CLI Scanning
bash
SCANNER_DIR="${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner"

# Scan all skills with JSON output
"$SCANNER_DIR/scripts/runner.sh" --target ./skills/ --output report.json --format json

# Scan specific directory with human-readable output
"$SCANNER_DIR/scripts/runner.sh" --target ./my-skill/ --format text

# Check available flags
"$SCANNER_DIR/scripts/runner.sh" --help

CLI Flags:

  • --target <path>: Directory to scan (required)
  • --output <file>: Write results to file (optional, defaults to stdout)
  • --format <json|text>: Output format (default: json)
  • --check: Verify all required binaries are installed
OpenClaw Hook Setup (Continuous Monitoring)

Enable automated periodic scanning:

bash
SCANNER_DIR="${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner"
node "$SCANNER_DIR/scripts/setup_scanner_hook.mjs"

This creates a hook that:

  • Scans on agent:bootstrap and command:new events
  • Respects CLAWSEC_SCANNER_INTERVAL rate limiting (default: 86400 seconds / 24 hours)
  • Posts findings to conversation with severity summary
  • Recommends remediation for high/critical vulnerabilities

Restart the OpenClaw gateway after enabling the hook, then run /new to trigger an immediate scan.

Environment Variables
bash
# Optional - NVD API key to avoid rate limiting (6-second delays without key)
export CLAWSEC_NVD_API_KEY="your-nvd-api-key"

# Optional - GitHub OAuth token for Advisory Database queries
export GITHUB_TOKEN="ghp_your_token_here"

# Optional - Scanner hook interval in seconds (default: 86400 / 24 hours)
export CLAWSEC_SCANNER_INTERVAL="86400"

# Optional - Allow unsigned advisory feed during development (from clawsec-suite)
export CLAWSEC_ALLOW_UNSIGNED_FEED="1"

Architecture

Modular Design

Each scan type is an independent module that can run standalone or as part of unified scan:

scripts/runner.sh              # Orchestration layer
├── scan_dependencies.mjs      # npm audit + pip-audit
├── query_cve_databases.mjs    # OSV/NVD/GitHub API queries
├── sast_analyzer.mjs          # Semgrep + Bandit static analysis
├── dast_runner.mjs            # Dynamic security testing orchestration
└── dast_hook_executor.mjs     # Isolated real hook execution harness

lib/
├── report.mjs                 # Result aggregation and formatting
├── utils.mjs                  # Subprocess exec, JSON parsing, error handling
└── types.ts                   # TypeScript schema definitions

hooks/clawsec-scanner-hook/
├── HOOK.md                    # OpenClaw hook metadata
└── handler.ts                 # Periodic scan trigger
Fail-Open Philosophy

The scanner prioritizes availability over strict failure propagation:

  • Network failures → emit partial results, log warnings
  • Missing tools → skip that scan type, continue with others
  • Malformed JSON → parse what's valid, log errors
  • API rate limits → implement exponential backoff, fallback to other sources
  • Zero vulnerabilities → emit success report with empty array

Critical failures that exit immediately:

  • Target path does not exist
  • No scanning tools available (all bins missing)
  • Concurrent scan detected (lockfile present)
Subprocess Execution Pattern

All external tools run as subprocesses with structured JSON output:

javascript
import { spawn } from 'node:child_process';

// Example: npm audit execution
const proc = spawn('npm', ['audit', '--json'], {
  cwd: targetPath,
  stdio: ['ignore', 'pipe', 'pipe']
});

// Handle non-zero exit codes gracefully
// npm audit exits 1 when vulnerabilities found (not an error!)
proc.on('close', code => {
  if (code !== 0 && stderr.includes('ERR!')) {
    // Actual error
    reject(new Error(stderr));
  } else {
    // Vulnerabilities found or success
    resolve(JSON.parse(stdout));
  }
});

Troubleshooting

Show full SKILL.md (484 more words)Show less
Common Issues

"Missing package-lock.json" warning

  • npm audit requires lockfile to run
  • Run npm install in target directory to generate
  • Scanner continues with other scan types if npm audit fails

"NVD API rate limit exceeded"

  • Set CLAWSEC_NVD_API_KEY environment variable
  • Without API key: 6-second delays enforced between requests
  • OSV API used as primary source (no rate limits)

"pip-audit not found"

  • Install: uv pip install pip-audit or pip install pip-audit
  • Verify: which pip-audit
  • Add to PATH if installed in non-standard location

"Semgrep binary missing"

  • Install: pip install semgrep OR brew install semgrep
  • Requires Python 3.8+ runtime
  • Alternative: use Docker image returntocorp/semgrep

"TypeScript hook not executable in DAST harness"

  • The DAST harness executes real hook handlers and transpiles handler.ts files when a TypeScript compiler is available
  • Install TypeScript in the scanner environment: npm install -D typescript (or provide handler.js/handler.mjs)
  • Without a compiler, scanner reports an info-level coverage finding instead of a high-severity vulnerability

"Concurrent scan detected"

  • Lockfile exists: /tmp/clawsec-scanner.lock
  • Wait for running scan to complete or manually remove lockfile
  • Prevents overlapping scans that could produce inconsistent results
Verification

Check scanner is working correctly:

bash
# Verify required binaries
./scripts/runner.sh --check

# Run unit tests
node test/dependency_scanner.test.mjs
node test/cve_integration.test.mjs
node test/sast_engine.test.mjs
node test/dast_harness.test.mjs

# Validate skill structure
python ../../utils/validate_skill.py .

# Scan test fixtures (should detect known vulnerabilities)
./scripts/runner.sh --target test/fixtures/ --format text

Development

Running Tests
bash
# All tests (vanilla Node.js, no framework)
for test in test/*.test.mjs; do
  node "$test" || exit 1
done

# Individual test suites
node test/dependency_scanner.test.mjs  # Dependency scanning
node test/cve_integration.test.mjs     # CVE database APIs
node test/sast_engine.test.mjs         # Static analysis
node test/dast_harness.test.mjs        # DAST harness execution
Linting
bash
# JavaScript/TypeScript
npx eslint . --ext .ts,.tsx,.js,.jsx,.mjs --max-warnings 0

# Python (Bandit already configured in pyproject.toml)
ruff check .
bandit -r . -ll

# Shell scripts
shellcheck scripts/*.sh
Adding Custom Semgrep Rules

Create custom rules in .semgrep/rules/:

yaml
rules:
  - id: custom-security-rule
    pattern: dangerous_function($ARG)
    message: Avoid dangerous_function - use safe_alternative instead
    severity: WARNING
    languages: [javascript, typescript]

Update scripts/sast_analyzer.mjs to include custom rules:

javascript
const proc = spawn('semgrep', [
  'scan',
  '--config', 'auto',
  '--config', '.semgrep/rules/',  // Add custom rules
  '--json',
  targetPath
]);

Integration with ClawSec Suite

The scanner works standalone or as part of the ClawSec ecosystem:

  • clawsec-suite: Meta-skill that can install and manage clawsec-scanner
  • clawsec-feed: Advisory feed for malicious skill detection (complementary)
  • openclaw-audit-watchdog: Cron-based audit automation (similar pattern)

Install the full ClawSec suite:

bash
npx clawhub@latest install clawsec-suite
# Then use clawsec-suite to discover and install clawsec-scanner

Security Considerations

Scanner Security
  • No hardcoded secrets in scanner code
  • API keys read from environment variables only (never logged or committed)
  • Subprocess arguments use arrays to prevent shell injection
  • All external tool output parsed with try/catch error handling
Vulnerability Prioritization

Critical/High severity findings should be addressed immediately:

  • Known exploits in dependencies (CVSS 9.0+)
  • Hardcoded API keys or credentials in code
  • Command injection vulnerabilities
  • Path traversal without validation

Medium/Low severity findings can be addressed in normal sprint cycles:

  • Outdated dependencies without known exploits
  • Missing security headers
  • Weak cryptography usage

Info findings are advisory only:

  • Deprecated API usage
  • Code quality issues flagged by linters

Roadmap

v0.0.2 (Current)
  • Dependency scanning (npm audit, pip-audit)
  • CVE database integration (OSV, NVD, GitHub Advisory)
  • SAST analysis (Semgrep, Bandit)
  • Real OpenClaw hook execution harness for DAST
  • Unified JSON reporting
  • OpenClaw hook integration
Future Enhancements
  • Automatic remediation (dependency upgrades, code fixes)
  • SARIF output format for GitHub Code Scanning integration
  • Web dashboard for vulnerability tracking over time
  • CI/CD GitHub Action for PR blocking on high-severity findings
  • Container image scanning (Docker, OCI)
  • Infrastructure-as-Code scanning (Terraform, CloudFormation)
  • Comprehensive agent workflow DAST (requires deeper platform integration)

Contributing

Found a security issue? Please report privately to security@prompt.security.

For feature requests and bug reports, open an issue at: https://github.com/prompt-security/clawsec/issues

License

AGPL-3.0-or-later

See LICENSE file in repository root for full text.

Resources

© LeoYeAI, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 23 other files (scripts) in skills/clawsec-scanner of LeoYeAI/openclaw-master-skills.

  • SKILL.md
  • CHANGELOG.md
  • _meta.json
  • hooks/clawsec-scanner-hook/HOOK.md
  • hooks/clawsec-scanner-hook/handler.ts
  • lib/report.mjs
  • lib/types.ts
  • lib/utils.mjs
  • scripts/dast_hook_executor.mjs
  • scripts/dast_runner.mjs
  • scripts/query_cve_databases.mjs
  • scripts/runner.sh
  • scripts/sast_analyzer.mjs
  • scripts/scan_dependencies.mjs
  • scripts/setup_scanner_hook.mjs
  • skill.json
  • test
  • … and 7 more

Open the folder on GitHubat commit e5199b5

Compare with similar skills

Clawsec Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clawsec Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clawsec Scanner this skillLeoYeAI/openclaw-master-skills2.2k—~4.1kAutomated safety check: PassMIT
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence
Pyspector Security AuditParzivalHack/PySpector151—~3.5kAutomated safety check: NotesApache-2.0
Security Vulnerabilities Patcheraxelixlabs/axelix148—~4.2kAutomated safety check: PassLGPL-3.0
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security Verification Gatefengshao1227/ccg-workflow5.9k—~621Automated safety check: NotesMIT

Similar skills

  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Pyspector Security Audit

    ParzivalHack/PySpector

    Run a full Python codebase security audit using PySpector (https://github.com/ParzivalHack/PySpector), a Rust-core SAST scanner.

    151 GitHub stars~3.5k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

    148 GitHub stars~4.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Security Verification Gate

    fengshao1227/ccg-workflow

    Scans code with a bundled Node script for injection, secrets, XSS and other risky patterns, ranks findings by severity and checks that security decisions are documented.

    5.9k GitHub stars~621 tokensUpdated 24 days ago
    SecurityAuto-check: notes
  • Runs Slither and Mythril against Solidity contracts to find reentrancy, overflow and access-control bugs before mainnet deployment, then triages and reports findings.

    17k GitHub starsUsed in 1 repo~738 tokens
    SecurityAuto-check passed

More from LeoYeAI/openclaw-master-skills

All 1,235 skills in this repo
  • DevOps Pipeline Management

    LeoYeAI/openclaw-master-skills

    Manages pipelines on a DevOps quality and efficiency platform through its OpenAPI: list workspaces and templates, create, update, run and cancel pipelines, and read run records.

    2.2k GitHub stars~4.2k tokensUpdated 2 mo ago
    Auto-check: notes
  • Feishu Document Collaboration

    LeoYeAI/openclaw-master-skills

    Patches OpenClaw's Feishu extension so an edited document triggers an isolated agent session that reads the doc and replies inline, turning it into a live chat space.

    2.2k GitHub stars~2k tokensUpdated 2 mo ago
    Auto-check passed
  • Files Memory System

    LeoYeAI/openclaw-master-skills

    Multi-context memory management system for OpenClaw agents with group-isolated storage, global shared memory, workspace organization, and group-specific skills isolation.

    2.2k GitHub stars~3.8k tokensUpdated 2 mo ago
    Auto-check passed
  • GEO-Claw AI Visibility Agent

    LeoYeAI/openclaw-master-skills

    Runs a brand's AI-search visibility work end to end: diagnosing how AI platforms represent it, repositioning it, producing AI-optimized content and monitoring ongoing mentions.

    2.2k GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Google Workspace CLI

    LeoYeAI/openclaw-master-skills

    Installs and authenticates the gws CLI, then automates Gmail, Drive, Sheets, Calendar, Docs, Chat and Tasks with ready-made recipes, persona bundles and security audits.

    2.2k GitHub stars~2.6k tokensUpdated 2 mo ago
    Auto-check: notes
  • HealthFit Health Advisors

    LeoYeAI/openclaw-master-skills

    Runs four advisor roles, a fitness coach, nutritionist, data analyst and TCM practitioner, to build a health profile and track workouts, diet and wellness over time.

    2.2k GitHub stars~4.4k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Clawsec Scanner

What does Clawsec Scanner do?

Automated vulnerability scanner for agent platforms. An agent skill from LeoYeAI/openclaw-master-skills. Clawsec Scanner is an agent skill from LeoYeAI/openclaw-master-skills. Automated vulnerability scanner for agent platforms.

When should I use Clawsec Scanner?

Clawsec Scanner fits situations like: tasks that involve Static analysis and SAST; tasks that involve Vulnerability scanning; tasks that involve Dependency management.

How do I install Clawsec Scanner in Claude Code?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a claude-code`. Or copy the skill folder (skills/clawsec-scanner in LeoYeAI/openclaw-master-skills) into .claude/skills/clawsec-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Clawsec Scanner in Codex?

Run `npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a codex`. Or copy the skill folder (skills/clawsec-scanner in LeoYeAI/openclaw-master-skills) into .agents/skills/clawsec-scanner in your project. Codex loads it when a task matches its description.

Can I use Clawsec Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LeoYeAI/openclaw-master-skills --skill clawsec-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clawsec-scanner, .gemini/skills/clawsec-scanner, .github/skills/clawsec-scanner and .opencode/skills/clawsec-scanner in your project.

What does Clawsec Scanner need to run?

Going by SKILL.md and its folder, Clawsec Scanner needs JavaScript, TypeScript and a shell for the scripts in its folder, the command-line tools its instructions call (node, npm, curl, npx, jq and pip) and credentials named CLAWSEC_NVD_API_KEY and GITHUB_TOKEN. Our summary lists: Python 3; Node.js; A Bash shell; Docker; A credential in CLAWSEC_NVD_API_KEY.

Does Clawsec Scanner access the network?

SKILL.md names 6 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: clawsec.prompt.security, osv.dev, nvd.nist.gov, semgrep.dev and bandit.readthedocs.io. This is read from the text; nothing was executed.

Is Clawsec Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Clawsec Scanner use?

Clawsec Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clawsec Scanner use?

About 4.1k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Clawsec Scanner?

Skills that share tags, products or a category with Clawsec Scanner: Kedro Security Review (kedro-org/kedro, 11k stars), Pyspector Security Audit (ParzivalHack/PySpector, 151 stars), Security Vulnerabilities Patcher (axelixlabs/axelix, 148 stars) and CodeQL Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clawsec Scanner?

LeoYeAI (a GitHub user) maintains it in LeoYeAI/openclaw-master-skills, which has 2,160 GitHub stars. The repository holds 1,235 skills in this directory. The repository was last updated on July 20, 2026.

Source: LeoYeAI/openclaw-master-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.