Openclaw Skill
Sandboxed command runner for AI agents — validates and isolates every shell action inside a Bubblewrap user namespace.
End-to-end security and exposure audit of the Annual Reports CRM stack (n8n + Cloudflare Workers + Pages + Airtable + Microsoft Graph + GitHub). Triggers on /security-deep-audit, /audit-security, /full-security-audit, or phrases like 'deep security audit', 'find all leaks', 'audit everything', 'find loose ends', or after a secret rotation completes (post-rotation paranoid sweep), or as a monthly cadence run. Hunts ten categories in parallel: public-repo git-history leakage, document/PII leakage, n8n credential and inline-secret drift, Worker/Pages drift, GitHub posture, local laptop hygiene, third-party SaaS posture, code-level auth/access patterns, time-decaying risks, and known dual-use HEAD constants. Read-only — never auto-rotates, commits, or pushes. Writes a prioritized report to .agent/audits/. Does NOT trigger for n8n silent-drop or workflow-correctness bugs (use silent-failure-hunt instead), single-PR secret reviews (use /security-review), or one-off targeted lookups.
This listing is imported from SkillsMP metadata and should be treated as untrusted until upstream source review is completed.
Install skill "security-deep-audit" with this command: npx skills add LiozShor/skillsmp-liozshor-liozshor-security-deep-audit
This source entry does not include full markdown content beyond metadata.
This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.
Related by shared tags or category signals.
Sandboxed command runner for AI agents — validates and isolates every shell action inside a Bubblewrap user namespace.
Prompt injection defense for OpenClaw agents. Scans emails and skill installations through a two-phase security pipeline (pattern matching + optional LLM ana...
Security audit and vulnerability scanner for AI agent skills before installation. Use when: (1) evaluating a skill from an untrusted source, (2) auditing a s...
Give your agent the superpower to read the modern web without getting blocked by Cloudflare. Extracts clean JSON, saves 98% of LLM tokens, and executes zero...