rafter-security
Security toolkit for AI workflows. Use when scanning code or repos for vulnerabilities, auditing third-party skills/MCPs/agent configs before installing, evaluating shell commands before running them, or generating secure design questions for new features. Provides `rafter run` (remote SAST + SCA, needs RAFTER_API_KEY), `rafter secrets` (offline secrets-only), `rafter agent exec --dry-run` (command-risk classification), and `rafter skill review`. Skill: rafter-security Owner: rafter Summary: Security toolkit for AI workflows. Use when scanning code or repos for vulnerabilities, auditing third-party skills/MCPs/agent configs before installing, evaluating shell commands before running them, or generating secure design questions for new features. Provides rafter run (remote SAST + SCA, needs RAFTER_API_KEY), rafter secrets (offline secrets-only), rafter agent ex
Rank
62
Safety
84
Downloads
2.3k
Updated
Oct 9, 2026
Version
0.10.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.3K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.3K downloadsadoption · observed Oct 9, 2026
- Latest release
- 0.10.6release · observed Oct 3, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s172bdp0kgrkm0bjw76jdgbr7x86cbb9:rafter-security- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-rafter-rafter-security/snapshot"
Documentation
CLAWHUB
134,537 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
---
name: rafter-security
description: Security toolkit for AI workflows. Use when scanning code or repos for vulnerabilities, auditing third-party skills/MCPs/agent configs before installing, evaluating shell commands before running them, or generating secure design questions for new features. Provides `rafter run` (remote SAST + SCA, needs RAFTER_API_KEY), `rafter secrets` (offline secrets-only), `rafter agent exec --dry-run` (command-risk classification), and `rafter skill review`.
version: 0.10.6
homepage: https://rafter.so
metadata:
openclaw:
skillKey: rafter-security
primaryEnv: RAFTER_API_KEY
emoji: 🛡️
always: false
requires:
bins: [rafter]
envVars:
- name: RAFTER_API_KEY
required: false
description: API key for `rafter run` (remote SAST + SCA + agentic deep-dive). Without it, `rafter secrets` (local secrets scan) still works.
last_updated: 2026-05-12
---
# Rafter Security
Local security toolkit for developers. Scans code, enforces policies on commands, audits extensions, and prevents vulnerabilities.
## Overview
Rafter provides real-time security checks for agent operations:
- **Secret Detection**: Scan files before commits
- **Command Validation**: Block dangerous shell commands
- **Skill Auditing**: Comprehensive security analysis of Claude Code skills
- **Output Filtering**: Redact secrets in responses
- **Audit Logging**: Track all security events
---
## Setup
To initialize Rafter, use **opt-in** `--with-*` flags to select integrations. There are NO `--skip-*` flags.
```bash
# Install specific integrations (opt-in)
rafter agent init --with-openclaw
rafter agent init --with-claude-code --with-betterleaks
# Install everything detected
rafter agent init --all
# WRONG — these flags do not exist:
# rafter agent init --skip-openclaw # DOES NOT EXIST
# rafter agent init --skip-claude-code # DOES NOT EXIST
```
---
## Commands
### /rafter-scan
Scan files for secrets before committing.
```bash
rafter secrets <path>
```
**When to use:**
- Before git commits
- When handling user-provided code
- When reading sensitive files
**What it detects:**
- AWS keys, GitHub tokens, Stripe keys
- Database credentials
- Private keys (RSA, SSH, etc.)
- 21+ secret patterns
**Exit codes:**
- `0` — clean, no secrets
- `1` — secrets found
- `2` — runtime error (path not found, not a git repo)
**JSON output** (`--json`): Array of `{file, matches[]}` objects. Each match contains `pattern` (name, severity, description), `line`, `column`, and `redacted` value. Raw secrets are never included.
---
### /rafter-bash
Explicitly run a command through Rafter's security validator.
```bash
rafter agent exec <command>
```
**When to use:** Only needed in environments where the `PreToolUse` hook is not installed. When `rafter agent init` has been run, all shell commands are validated automatically — you do not need to route commands through this.
**Risk levels:**
- **Critical** (blocked): rm -rf /, _meta.json
{
"ownerId": "kn7a8aa64xq84ta3cv4bn39ms186bsyk",
"slug": "rafter-security",
"version": "0.10.6",
"publishedAt": 1791021158365
}skill-card.md
## Description: Helps developers scan code for vulnerabilities and secrets, review third-party skills, and assess shell command risks. This skill is ready for commercial/non-commercial use. ## Publisher: [rafter](https://clawhub.ai/user/rafter) ### License/Terms of Use: MIT-0 ## Use Case: Developers and security teams use this skill to scan repositories for vulnerabilities and secrets, review untrusted extensions, and evaluate shell commands before running them. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Remote scans may share code or metadata with Rafter's service. Mitigation: Review what will be scanned before enabling remote scans with RAFTER_API_KEY; use the local secrets scan when remote sharing is not appropriate. Risk: Opt-in agent initialization can add persistent security hooks or audit logging. Mitigation: Review the selected integrations and configuration before enabling them; avoid broad initialization unless needed. ## Reference(s): - [Rafter](https://rafter.so) - [Rafter Security on ClawHub](https://clawhub.ai/rafter/skills/rafter-security) ## Skill Output: **Output Type(s):** [Security guidance, Markdown reports, Shell commands, JSON scan results] **Output Format:** [Markdown guidance and audit reports; optional JSON secret-scan results] **Output Parameters:** [1D] **Other Properties Related to Output:** [Secret-scan JSON redacts matched values.] ## Skill Version(s): 0.10.6 (source: skill frontmatter and ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/rafter/skills/rafter-security",
"sourceUrl": "https://clawhub.ai/rafter/skills/rafter-security",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T16:19:38.637Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-rafter-rafter-security/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-rafter-rafter-security/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T16:19:38.637Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.3K downloads",
"href": "https://clawhub.ai/rafter/rafter-security",
"sourceUrl": "https://clawhub.ai/rafter/rafter-security",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T16:19:38.637Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.10.6",
"href": "https://clawhub.ai/rafter/rafter-security",
"sourceUrl": "https://clawhub.ai/rafter/rafter-security",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T09:52:38.365Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-rafter-rafter-security/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-rafter-rafter-security/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.10.6",
"description": "- Removed unused or redundant file: skill-card.md - SKILL.md updated to version 0.10.6 - No functional or command changes described - Documentation improvements and cleanup only",
"href": "https://clawhub.ai/rafter/rafter-security",
"sourceUrl": "https://clawhub.ai/rafter/rafter-security",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-03T09:52:38.365Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
