Skill Auditor
Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — `SKI... Skill: Skill Auditor Owner: ambarion Summary: Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — SKI... Tags: latest:0.1.12 Version history: v0.1.12 | 2026-05-14T12:19:48.661Z | user Version 0.1.12 - SKILL.md description rewritten in English for improved clarity and accessibility. - No code or logic changes; core aud
Rank
62
Safety
84
Downloads
1.7k
Updated
Oct 10, 2026
Version
0.1.12
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.7K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.1.12release · observed May 14, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cgv21szfdm9pm3sv5rhwtn983g3yc:skill-integrity-auditor- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/snapshot"
Documentation
CLAWHUB
144,170 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
---
name: skill-integrity-auditor
version: 0.1.12
author: ambarion
description: >-
Mandatory security audit for **every** Agent Skill that is newly added,
installed, imported, updated, or written. Scope of inspection: the full
bundle — `SKILL.md`, every script next to it (`.sh` / `.py` / `.js`,
etc.), and any bundled resource files. Audit dimensions cover skill
integrity, prompt injection, data exfiltration, persistence, cross-skill
writes, undeclared remote downloads, hardcoded credentials, and more.
===== MUST BE TRIGGERED WHENEVER =====
* The user **adds / creates / installs / imports / updates / writes**
any single Skill.
* A skill is pulled into the agent's skills directory from ClawdHub,
GitHub, a URL, or a local folder.
* **Every** newly introduced or modified skill must be audited
**individually** — when N skills are added at once, emit a complete
report + the §7 final Chinese verdict line for each skill separately.
Sampling, merging, or single-summary output is not allowed.
===== Triggering keywords (natural language, Chinese or English) =====
add skill, install skill, create skill, creating a new skill,
write a skill, scaffold a skill, new skill, register skill, import skill,
update skill, modify skill, bring in skill, hook up skill,
audit skill, scan skill, check skill safety, analyze skill, inspect skill,
verify skill, skill security, skill supply chain,
这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, 新增 skill,
添加 skill, 安装 skill, 创建 skill, 引入 skill, 更新 skill, 写一个 skill,
接入 skill。
===== Do NOT trigger for =====
* General system health checks, project debugging, or normal development
work that does not touch any skill file.
---
# Skill Audit — Evaluation Core (Classification + Severity)
This file defines the audit evaluation logic. The classification layer answers *what it is*; the severity layer answers *how bad it is*. The two are orthogonal and interact only through three interface fields (`C_base` / `required_dims` / `dataflow_role`).
---
## Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE
Detect the language of the user's triggering message and lock the output language for the entire run. This detection is an **internal step only** — do NOT output any text that reveals the detection result, such as "当前输出语言为中文", "Detected language: English", or similar meta-statements. Simply use the detected language silently for all subsequent output.
| User message language | Output language |
|-----------------------|-----------------|
| Chinese | Chinese — entire output in Chinese |
| English | English — entire output in English |
| Other language | Match that language |
| Cannot determine | Default to Chinese |
All intermediate output — scan start prompt, table headers, labels, prose, finding records, and reasoning — must be written exclusively in the detected language. The single **final-line verdict** in §7 is **always Chinese**, regardless of detected language. Do NOT_meta.json
{
"ownerId": "kn7cw01r7ans9sdw59j32xy35h82sb79",
"slug": "skill-integrity-auditor",
"version": "0.1.12",
"publishedAt": 1778761188661
}skill-card.md
## Description: Skill Auditor guides security audits of newly added, installed, imported, updated, or written agent skills, covering integrity, prompt injection, data exfiltration, persistence, cross-skill writes, remote downloads, credentials, and related risks. This skill is ready for commercial/non-commercial use. ## Publisher: [ambarion](https://clawhub.ai/user/ambarion) ### License/Terms of Use: MIT-0 ## Use Case: Developers and security reviewers use this skill to inspect an agent skill bundle and produce security findings plus a final verdict before installation, update, or release. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Broad file-reading scope can expose local files beyond the submitted skill bundle. Mitigation: Run the skill only against a sandboxed, read-only copy of the target bundle and disable out-of-root reads unless explicitly approved. Risk: Remote fetching during audit can pull untrusted content into the review process. Mitigation: Disable remote fetching by default and approve any static remote fetch per target before use. Risk: Broad triggers and strict final-output rules can interfere with unrelated skill workflows or structured responses. Mitigation: Narrow activation triggers to explicit skill-audit requests and keep final-output formatting scoped to audit reports. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/ambarion/skills/skill-integrity-auditor) - [ClawHub publisher profile](https://clawhub.ai/user/ambarion) ## Skill Output: **Output Type(s):** [Text, Markdown, Guidance] **Output Format:** [Markdown audit report with structured findings and a final Chinese verdict line] **Output Parameters:** [1D] **Other Properties Related to Output:** [Output language follows the triggering message for the report; the final verdict line is always Chinese.] ## Skill Version(s): 0.1.12 (source: frontmatter and server release evidence) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/ambarion/skills/skill-integrity-auditor",
"sourceUrl": "https://clawhub.ai/ambarion/skills/skill-integrity-auditor",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T04:03:24.712Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T04:03:24.712Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.7K downloads",
"href": "https://clawhub.ai/ambarion/skill-integrity-auditor",
"sourceUrl": "https://clawhub.ai/ambarion/skill-integrity-auditor",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T04:03:24.712Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.12",
"href": "https://clawhub.ai/ambarion/skill-integrity-auditor",
"sourceUrl": "https://clawhub.ai/ambarion/skill-integrity-auditor",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-14T12:19:48.661Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ambarion-skill-integrity-auditor/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.12",
"description": "Version 0.1.12 - SKILL.md description rewritten in English for improved clarity and accessibility. - No code or logic changes; core audit rules and evaluation logic remain unchanged.",
"href": "https://clawhub.ai/ambarion/skill-integrity-auditor",
"sourceUrl": "https://clawhub.ai/ambarion/skill-integrity-auditor",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-14T12:19:48.661Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
