Agent skill

Security Audit 2

by sundial-org in sundial-org/awesome-openclaw-skills

Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or…

No licenceAuto-check passedSecurity

Install Security Audit 2

skills CLI
$ npx skills add sundial-org/awesome-openclaw-skills --skill security-audit-2 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sundial-org/awesome-openclaw-skills security-audit-2 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sundial-org/awesome-openclaw-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security-audit-2 .claude/skills/security-audit-2 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
security-audit-2
GitHub stars
663
Token cost
~875 tokens
SKILL.md length
226 words
Files
9 (incl. scripts)
Skills in repo
383
Repo updated
First seen
Licence
None found

At a glance

Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or…

  • Tasks that involve Static analysis and SAST
  • SKILL.md covers What it checks (high level), Run an audit (JSON), Manifest requirement (for… and Optional: execution sandbox…, plus 1 more section
  • Runs Shell and Python scripts from its folder; calls bash and jq
  • Tasks that involve Security review

What it does

Security Audit 2 is an agent skill from sundial-org/awesome-openclaw-skills. Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or installing.

Its SKILL.md is about 880 tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts (for example `CHANGELOG.md`, `README.md` and `docs/OPENCLAW_SKILL_MANIFEST_SCHEMA.md`).

It sits in Security, covering Static analysis and SAST, Security review and Prompt injection and agent security. It works with Semgrep and Docker. The repository describes itself as: Top OpenClaw skills, with the most popular and useful ones.

When your agent uses it

  • Tasks that involve Static analysis and SAST
  • Tasks that involve Security review
  • Tasks that involve Prompt injection and agent security

Example prompts

  • “/security-audit-2”

Requirements

  • Python 3
  • A Bash shell
  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit b80cde2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 3 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Security Audit 2 loads about 875 tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 226 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~875

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 226 words (~875 tokens).

“A hostile-by-design, fail-closed audit workflow for codebases and OpenClaw/ClawHub skills.”

— opening of SKILL.md by sundial-org
name
security-audit-2

Read the full SKILL.md on GitHub

Files

SKILL.md and 8 other files (scripts) in skills/security-audit-2 of sundial-org/awesome-openclaw-skills.

  • SKILL.md
  • CHANGELOG.md
  • README.md
  • docs/OPENCLAW_SKILL_MANIFEST_SCHEMA.md
  • docs/README_ZERO_TRUST_INSTALL.md
  • openclaw-skill.json
  • scripts/hostile_audit.py
  • scripts/run_audit_json.sh
  • scripts/security_audit.sh

Open the folder on GitHubat commit b80cde2

Compare with similar skills

Security Audit 2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Security Audit 2 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Security Audit 2 this skillsundial-org/awesome-openclaw-skills663—~875Automated safety check: PassNone
Cyber NeoHainrixz/cyber-neo283—~5.9kAutomated safety check: WarnMIT
Security ReviewerJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Moai Ref Secopsmodu-ai/moai-adk1.2k—~2.6kAutomated safety check: PassApache-2.0
Security Scanericrisco/rsc-harness174—~2.8kAutomated safety check: NotesMIT
Kedro Security Reviewkedro-org/kedro11k—~3.3kAutomated safety check: PassCustom licence

Similar skills

  • Cyber Neo

    Hainrixz/cyber-neo

    Comprehensive cybersecurity analysis for any local project. An agent skill from Hainrixz/cyber-neo.

    283 GitHub stars~5.9k tokensUpdated 2 mo ago
    SecurityAuto-check: warnings
  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 6 days ago
    SecurityAuto-check passed
  • Moai Ref Secops

    modu-ai/moai-adk

    DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning…

    1.2k GitHub stars~2.6k tokensUpdated today
    SecurityAuto-check passed
  • Security Scan

    ericrisco/rsc-harness

    A skill your agent uses when automated scanners drive a security sweep of a repo or app — SAST, dependency/lockfile CVEs, secrets in the tree or git history, IaC misconfig — and the raw output has…

    174 GitHub stars~2.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Kedro Security Review

    kedro-org/kedro

    Run a Kedro security scan on the full codebase or just a pull request.

    11k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 2 days ago
    SecurityAuto-check: notes

More from sundial-org/awesome-openclaw-skills

All 383 skills in this repo
  • UI UX Pro Max

    sundial-org/awesome-openclaw-skills

    UI/UX design intelligence and implementation guidance for building polished interfaces.

    663 GitHub starsUsed in 2 repos~657 tokens
    Auto-check passed
  • Web Deploy GitHub

    sundial-org/awesome-openclaw-skills

    Create and deploy single-page static websites to GitHub Pages with autonomous workflow.

    663 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Clawd Modifier

    sundial-org/awesome-openclaw-skills

    Modify Clawd, the Claude Code mascot. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~625 tokensUpdated 7 mo ago
    Auto-check passed
  • Figma

    sundial-org/awesome-openclaw-skills

    Professional Figma design analysis and asset export. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~1.7k tokensUpdated 7 mo ago
    Auto-check: notes
  • Habit Flow

    sundial-org/awesome-openclaw-skills

    AI-powered atomic habit tracker with natural language logging, streak tracking, smart reminders, and coaching.

    663 GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed
  • Edge Tts

    sundial-org/awesome-openclaw-skills

    Text-to-speech conversion using node-edge-tts npm package for generating audio from text.

    663 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed

Works with

Categories

Questions about Security Audit 2

What does Security Audit 2 do?

Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or…. Security Audit 2 is an agent skill from sundial-org/awesome-openclaw-skills. Fail-closed security auditing for OpenClaw/ClawHub skills & repos: trufflehog secrets scanning, semgrep SAST, prompt-injection/persistence signals, and supply-chain hygiene checks before enabling or installing.

When should I use Security Audit 2?

Security Audit 2 fits situations like: tasks that involve Static analysis and SAST; tasks that involve Security review; tasks that involve Prompt injection and agent security.

How do I install Security Audit 2 in Claude Code?

Run `npx skills add sundial-org/awesome-openclaw-skills --skill security-audit-2 -a claude-code`. Or copy the skill folder (skills/security-audit-2 in sundial-org/awesome-openclaw-skills) into .claude/skills/security-audit-2 in your project. Claude Code loads it when a task matches its description.

How do I install Security Audit 2 in Codex?

Run `npx skills add sundial-org/awesome-openclaw-skills --skill security-audit-2 -a codex`. Or copy the skill folder (skills/security-audit-2 in sundial-org/awesome-openclaw-skills) into .agents/skills/security-audit-2 in your project. Codex loads it when a task matches its description.

Can I use Security Audit 2 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sundial-org/awesome-openclaw-skills --skill security-audit-2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/security-audit-2, .gemini/skills/security-audit-2, .github/skills/security-audit-2 and .opencode/skills/security-audit-2 in your project.

What does Security Audit 2 need to run?

Going by SKILL.md and its folder, Security Audit 2 needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (bash and jq). Our summary lists: Python 3; A Bash shell; Docker.

Does Security Audit 2 access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Security Audit 2 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Security Audit 2 use?

No licence was found for Security Audit 2 or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Security Audit 2 use?

About 875 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Security Audit 2?

Skills that share tags, products or a category with Security Audit 2: Cyber Neo (Hainrixz/cyber-neo, 283 stars), Security Reviewer (Jeffallan/claude-skills, 12k stars), Moai Ref Secops (modu-ai/moai-adk, 1.2k stars) and Security Scan (ericrisco/rsc-harness, 174 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Security Audit 2?

sundial-org (a GitHub organization) maintains it in sundial-org/awesome-openclaw-skills, which has 663 GitHub stars. The repository holds 383 skills in this directory. The repository was last updated on March 7, 2026.

Source: sundial-org/awesome-openclaw-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.