qa-security
Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification. Skill: qa-security Owner: jinyu12166 Summary: Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification. Tags: latest:1.0.27 Version history: v1.0.27 | 2026-07-28T12:48:07.412Z | user Version 1.1.0 - Switched to official clawtip wallet for payment processing. - Removed all references and data transmission to api.i
Rank
62
Safety
84
Downloads
1.9k
Updated
Oct 9, 2026
Version
1.0.27
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.0.27release · observed Jul 28, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17bk5y82fk590863n8fb20zvn8afqra:qa-security- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/snapshot"
Documentation
CLAWHUB
67,976 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
---
name: "qa-security"
version: "1.1.0"
description: >
Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification.
metadata:
author: "Yujin"
category: "expert"
permissions:
- "network.outbound"
- "credential.read"
- "filesystem.read"
- "filesystem.write"
requires:
- "clawtip"
workflow:
create_order:
script: scripts/create_order.py
args: ["{question}"]
outputs: ["order_no", "amount", "indicator"]
pay:
requires: clawtip
args: ["{order_no}", "{indicator}"]
service:
script: scripts/service.py
args: ["{order_no}"]
---
# qa-security
请使用中文与用户交互。
## 技能概述
代码质量审计与安全审查服务,覆盖漏洞识别模式、依赖风险评估、安全最佳实践和测试策略设计。付费服务,通过 clawtip 完成支付验证后由 AI 交付审核结果。
**直接执行:** 如用户已提供带支付凭证的订单号,直接跳到第三阶段。
---
## 环境变量配置
| 变量名 | 必填 | 说明 |
|--------|------|------|
| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |
| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥(十六进制,32 字符) |
---
## 前置条件
```bash
openclaw skills install clawtip
```
---
## 🛒 第一阶段:创建订单
```bash
python3 scripts/create_order.py "<question>"
```
**成功:** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`
**失败:** `订单创建失败: <详情>` → 终止工作流。
---
## 💳 第二阶段:支付处理
### 沙箱测试
```bash
npx --yes @clawtip/[email protected] pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12
```
### 生产环境
调用 **clawtip** 钱包:`{"orderNo": "<ORDER_NO>", "indicator": "<INDICATOR>"}`
> [!CAUTION]
> 技能名称必须严格等于 `clawtip`,不允许替代。
---
## 🚀 第三阶段:服务执行
```bash
python3 scripts/service.py "<order_no>"
```
| 字段 | 值 | 说明 |
|------|-----|------|
| PAY_STATUS | SUCCESS / ERROR | 支付验证状态 |
| ERROR_INFO | 错误描述 | 失败时的错误原因 |
---
## 数据处理说明
### 本地存储
订单元数据保存至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`。
### 远程传输
本技能不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。
### 绝不收集或传输
源代码、项目文件、凭证或 API 密钥。
---
## 版本历史
| Version | Date | Notes |
|:--------|:-----|:------|
| 1.1.0 | 2026-07-28 | Switch to official clawtip wallet; remove api.ideaidea.com.cn |
| 1.0.24 | 2026-07-27 | Fix ClawHub audit |
| 1.0.1 | 2026-07-20 | Fix payment flow |
| 1.0.0 | 2026-07-19 | Initial release |_meta.json
{
"ownerId": "kn71ajnjnjnhwfs7mmzpg48t9d8af45f",
"slug": "qa-security",
"version": "1.0.27",
"publishedAt": 1785242887412
}skill-card.md
## Description: Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment with AI-delivered service access via clawtip verification. This skill is ready for commercial/non-commercial use. ## Publisher: [jinyu12166](https://clawhub.ai/user/jinyu12166) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineers use qa-security to request code quality audits, security review guidance, vulnerability pattern analysis, dependency risk assessment, and testing strategy suggestions after completing the clawtip payment workflow. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The skill uses a paid clawtip workflow with credential access, network permission, persistent local order files, and external payment tooling. Mitigation: Install only when that payment and permission posture is acceptable for the environment, and review the payment flow before use. Risk: The local payment verification is weak according to the security guidance. Mitigation: Treat payment authorization as low-assurance until the publisher strengthens credential validation and dependency integrity. Risk: The initial question may contain sensitive project details, source code, or secrets. Mitigation: Avoid including secrets, source code, credentials, or sensitive project information in the initial consultation question. ## Reference(s): - [qa-security ClawHub skill page](https://clawhub.ai/jinyu12166/skills/qa-security) ## Skill Output: **Output Type(s):** [guidance, markdown, shell commands, configuration] **Output Format:** [Markdown guidance with shell commands and payment status text] **Output Parameters:** [1D] **Other Properties Related to Output:** [Paid clawtip workflow; order metadata is written locally before service authorization.] ## Skill Version(s): 1.0.27 (source: server release metadata; artifact frontmatter lists 1.1.0) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/jinyu12166/skills/qa-security",
"sourceUrl": "https://clawhub.ai/jinyu12166/skills/qa-security",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T22:00:51.837Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T22:00:51.837Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2K downloads",
"href": "https://clawhub.ai/jinyu12166/qa-security",
"sourceUrl": "https://clawhub.ai/jinyu12166/qa-security",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T22:00:51.837Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.27",
"href": "https://clawhub.ai/jinyu12166/qa-security",
"sourceUrl": "https://clawhub.ai/jinyu12166/qa-security",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-28T12:48:07.412Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.27",
"description": "Version 1.1.0 - Switched to official clawtip wallet for payment processing. - Removed all references and data transmission to api.ideaidea.com.cn. - Updated workflow section for clarity and accuracy. - Added environment variable requirements and setup instructions. - Added scripts/sm4_utils.py; removed skill-card.md.",
"href": "https://clawhub.ai/jinyu12166/qa-security",
"sourceUrl": "https://clawhub.ai/jinyu12166/qa-security",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-28T12:48:07.412Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
