agentCLAWHUBUnverified

Code Security Audit

Comprehensive code security audit toolkit combining OWASP Top 10 vulnerability scanning, dependency analysis, secret detection, SSL/TLS verification, AI Agen...

OpenClaw

Rank

62

Safety

84

Downloads

1.3k

Updated

Oct 10, 2026

Version

2.1.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.3K downloadsadoption · observed Oct 10, 2026
Latest release
2.1.0release · observed Feb 24, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17816dwhde506q6hgdqabzsx983kpd7:code-security-audit
  1. Install using `clawhub skill install s17816dwhde506q6hgdqabzsx983kpd7:code-security-audit` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/wisdomsword/code-security-audit before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-wisdomsword-code-security-audit/snapshot"

Documentation

CLAWHUB

126,246 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: code-security-audit
description: Comprehensive code security audit toolkit combining OWASP Top 10 vulnerability scanning, dependency analysis, secret detection, SSL/TLS verification, AI Agent security checks, and automated security scoring. Use when auditing codebases, scanning for vulnerabilities, detecting hardcoded secrets, checking OWASP compliance, AI/LLM application security, or preparing for security reviews.
version: 2.1.0
author: LobsterAI Security Team
metadata:
  category: security
  requires_bins:
    - npm
    - git
    - openssl
    - curl
  features:
    - owasp_top_10: true
    - dependency_scan: true
    - secret_detection: true
    - ssl_verification: true
    - security_scoring: true
    - auto_fix: true
    - ai_agent_security: true
  languages:
    - javascript
    - typescript
    - python
    - go
    - java
    - rust
    - php
    - ruby
    - solidity
  score_range: 0-100
---

# Code Security Audit

**Unified security audit toolkit** combining OWASP Top 10 vulnerability scanning, dependency analysis, secret detection, SSL/TLS verification, AI Agent security checks, and automated security scoring.

## Overview

This skill merges the best of `security-auditor` and `security-audit-toolkit` into a comprehensive security auditing solution:

- ✅ **OWASP Top 10 Vulnerability Detection** - All 10 categories with code patterns
- ✅ **Dependency Vulnerability Scanning** - npm, pip, cargo, go modules
- ✅ **Secret Detection** - 70+ API key patterns, credentials, private keys, crypto wallets
- ✅ **SSL/TLS Verification** - Certificate validation, cipher suite checks
- ✅ **AI Agent Security** - Numeric risks, prompt injection, crypto wallet safety (NEW)
- ✅ **Security Scoring** - Quantified 0-100 security score
- ✅ **Auto-Fix Suggestions** - Actionable remediation recommendations
- ✅ **Multi-Language Support** - JS/TS, Python, Go, Java, Rust, PHP, Ruby, Solidity
- ✅ **CI/CD Integration** - GitHub Actions, GitLab CI templates

## Quick Start

```bash
# Full security audit with scoring
./scripts/security-audit.sh --full

# Quick scan (secrets + dependencies only)
./scripts/security-audit.sh --quick

# OWASP Top 10 check
./scripts/security-audit.sh --owasp

# AI Agent security check (NEW - inspired by Lobstar Wilde incident)
./scripts/security-audit.sh --ai

# Dependency vulnerabilities only
./scripts/security-audit.sh --deps

# Secret detection only
./scripts/security-audit.sh --secrets

# SSL/TLS verification
./scripts/security-audit.sh --ssl example.com
```

## Security Score Calculation

| Category | Weight | Max Points |
|----------|--------|------------|
| OWASP Top 10 Compliance | 25% | 25 |
| AI Agent Security | 15% | 15 |
| Dependency Security | 20% | 20 |
| Secret Management | 15% | 15 |
| SSL/TLS Configuration | 10% | 10 |
| Code Quality (Security) | 10% | 10 |
| Documentation & Policies | 5% | 5 |
| **Total** | **100%** | **100** |

### Score Interpretation

| Score | Risk Level | Action |
|-------|------------|------

README.md

# Code Security Audit

Unified security audit toolkit for comprehensive code security analysis.

## Features

- **OWASP Top 10 Detection** - All 10 vulnerability categories with code patterns
- **Dependency Vulnerability Scanning** - npm, pip, cargo, go modules
- **Secret Detection** - 70+ API key patterns, credentials, private keys, crypto wallets
- **SSL/TLS Verification** - Certificate validation, cipher suite checks
- **AI Agent Security** (NEW) - Numeric risks, prompt injection, crypto wallet safety
- **Security Scoring** - Quantified 0-100 security score
- **Multi-Language Support** - JS/TS, Python, Go, Java, Rust, PHP, Ruby, Solidity

## Quick Start

```bash
# Full security audit with scoring
./scripts/security-audit.sh --full

# Quick scan (secrets + dependencies only)
./scripts/security-audit.sh --quick

# OWASP Top 10 check
./scripts/security-audit.sh --owasp

# AI Agent security check (NEW)
./scripts/security-audit.sh --ai

# SSL/TLS verification
./scripts/security-audit.sh --ssl example.com

# Generate report
./scripts/security-audit.sh --full --output report.md
```

## Security Score

| Score | Risk Level |
|-------|------------|
| 90-100 | ✅ Low |
| 70-89 | ⚠️ Medium |
| 50-69 | 🔶 High |
| 0-49 | 🚨 Critical |

## AI Agent Security (v2.1.0)

Inspired by the Lobstar Wilde incident (Feb 2026) where an AI agent accidentally transferred $250,000 due to numeric parsing errors.

**Detection Categories:**
- Numeric handling risks (floating-point, unit conversion)
- Prompt injection patterns
- Cryptocurrency/wallet security
- Amount validation
- Human-in-the-loop mechanism
- API response validation

## CI/CD Integration

See `templates/` directory for GitHub Actions and GitLab CI templates.

## License

MIT

_meta.json

{
  "ownerId": "kn7dwy5afmvc9xq2ygxqz09jxn81kwab",
  "slug": "code-security-audit",
  "version": "2.1.0",
  "publishedAt": 1771912616757
}

patterns/ai-agent.json

{
  "ai_agent_security": {
    "version": "1.0.0",
    "description": "Security patterns for AI Agent applications, inspired by Lobstar Wilde incident (Feb 2026)"
  },
  "numeric_risks": {
    "precision_loss": {
      "patterns": [
        "parseFloat\\s*\\([^)]+\\)\\s*[+\\-*/]",
        "parseInt\\s*\\([^)]+\\)\\s*[+\\-*/]",
        "Number\\s*\\([^)]+\\)\\s*[+\\-*/]",
        "parseFloat\\s*\\(.*amount",
        "parseFloat\\s*\\(.*balance",
        "parseFloat\\s*\\(.*price",
        "parseInt\\s*\\(.*amount",
        "Number\\s*\\(.*amount"
      ],
      "severity": "high",
      "description": "Potential floating-point precision loss in numeric operations",
      "recommendation": "Use BigInt, BigNumber, or integer-based calculations for financial values"
    },
    "unit_confusion": {
      "patterns": [
        "wei\\s*\\*\\s*1e18",
        "lamports\\s*\\*\\s*1e9",
        "eth\\s*\\*\\s*1e18",
        "sol\\s*\\*\\s*1e9",
        "\\*\\s*10\\s*\\*\\s*\\*\\s*18",
        "\\*\\s*1000000000000000000",
        "LAMPORTS_PER_SOL\\s*\\*",
        "WEI_PER_ETH\\s*\\*"
      ],
      "severity": "high",
      "description": "Manual unit conversion - potential precision loss or confusion",
      "recommendation": "Use library functions (toWei, parseEther) instead of manual multiplication"
    },
    "hardcoded_large_amounts": {
      "patterns": [
        "amount\\s*[:=]\\s*[0-9]{7,}",
        "value\\s*[:=]\\s*[0-9]{7,}",
        "quantity\\s*[:=]\\s*[0-9]{7,}",
        "transfer\\s*\\([^,]+,\\s*[0-9]{7,}",
        "send\\s*\\([^,]+,\\s*[0-9]{7,}"
      ],
      "severity": "medium",
      "description": "Hardcoded large amounts in code - potential error or attack vector",
      "recommendation": "Never hardcode amounts; use configuration or validated input"
    },
    "missing_amount_validation": {
      "patterns": [
        "function\\s+transfer\\s*\\([^)]*\\)\\s*\\{(?![^}]*require|[^}]*if\\s*\\(\\s*amount)",
        "function\\s+withdraw\\s*\\([^)]*\\)\\s*\\{(?![^}]*require|[^}]*if\\s*\\(\\s*amount)",
        "function\\s+send\\s*\\([^)]*\\)\\s*\\{(?![^}]*require|[^}]*if\\s*\\(\\s*amount)",
        "\\.transfer\\s*\\([^)]+\\)\\s*;",
        "\\.send\\s*\\([^)]+\\)\\s*;",
        "\\.withdraw\\s*\\([^)]+\\)\\s*;"
      ],
      "severity": "critical",
      "description": "Transfer/withdraw/send without visible amount validation",
      "recommendation": "Always validate amount > 0, amount <= max_limit, amount <= balance"
    }
  },
  "prompt_injection": {
    "ignore_instructions": {
      "patterns": [
        "ignore.{0,30}(previous|all|above|prior).{0,30}(instruction|prompt|rule|directive)",
        "disregard.{0,30}(all|any|previous|prior).{0,30}(instruction|rule|directive)",
        "forget.{0,30}(everything|all|previous|prior).{0,30}(instruction|rule)",
        "skip.{0,30}(all|any|previous).{0,30}(instruction|rule)",
        "override.{0,30}(previous|all|default).{0,30}(instruction|rule|setting)",
        "\\[SYSTEM\\].*ignore",
  

patterns/secrets.json

{
  "secrets": {
    "aws_access_key": {
      "pattern": "AKIA[0-9A-Z]{16}",
      "severity": "critical",
      "description": "AWS Access Key ID"
    },
    "aws_secret_key": {
      "pattern": "[A-Za-z0-9/+=]{40}",
      "severity": "critical",
      "description": "AWS Secret Access Key (when near access key)"
    },
    "openai_api_key": {
      "pattern": "sk-[A-Za-z0-9]{20,}",
      "severity": "high",
      "description": "OpenAI API Key"
    },
    "github_token": {
      "pattern": "(ghp|gho|ghu|ghs|ghr)_[A-Za-z0-9]{36}",
      "severity": "high",
      "description": "GitHub Personal/OAuth/Server Token"
    },
    "github_pat": {
      "pattern": "github_pat_[A-Za-z0-9_]{22,}",
      "severity": "high",
      "description": "GitHub Fine-grained PAT"
    },
    "slack_token": {
      "pattern": "xox[bpoas]-[A-Za-z0-9-]+",
      "severity": "high",
      "description": "Slack Token"
    },
    "slack_webhook": {
      "pattern": "https://hooks.slack.com/services/T[A-Z0-9]+/B[A-Z0-9]+/[A-Za-z0-9]+",
      "severity": "medium",
      "description": "Slack Webhook URL"
    },
    "stripe_live_key": {
      "pattern": "sk_live_[A-Za-z0-9]{24,}",
      "severity": "critical",
      "description": "Stripe Live Secret Key"
    },
    "stripe_publishable_key": {
      "pattern": "pk_live_[A-Za-z0-9]{24,}",
      "severity": "medium",
      "description": "Stripe Live Publishable Key"
    },
    "twilio_auth_token": {
      "pattern": "[A-Fa-f0-9]{32}",
      "severity": "high",
      "description": "Twilio Auth Token (when near twilio context)"
    },
    "sendgrid_api_key": {
      "pattern": "SG\\.[A-Za-z0-9_-]+\\.[A-Za-z0-9_-]+",
      "severity": "high",
      "description": "SendGrid API Key"
    },
    "mailgun_api_key": {
      "pattern": "key-[A-Za-z0-9]{32}",
      "severity": "high",
      "description": "Mailgun API Key"
    },
    "private_key": {
      "pattern": "-----BEGIN (RSA |DSA |EC |OPENSSH )?PRIVATE KEY-----",
      "severity": "critical",
      "description": "Private Key"
    },
    "jwt_token": {
      "pattern": "eyJ[A-Za-z0-9_-]*\\.eyJ[A-Za-z0-9_-]*\\.[A-Za-z0-9_-]*",
      "severity": "medium",
      "description": "JWT Token"
    },
    "mongodb_uri": {
      "pattern": "mongodb(\\+srv)?://[^:]+:[^@]+@[^/]+",
      "severity": "critical",
      "description": "MongoDB Connection String with credentials"
    },
    "mysql_uri": {
      "pattern": "mysql://[^:]+:[^@]+@[^/]+",
      "severity": "critical",
      "description": "MySQL Connection String with credentials"
    },
    "postgres_uri": {
      "pattern": "postgres(ql)?://[^:]+:[^@]+@[^/]+",
      "severity": "critical",
      "description": "PostgreSQL Connection String with credentials"
    },
    "redis_uri": {
      "pattern": "redis://[^:]*:[^@]+@[^/]+",
      "severity": "high",
      "description": "Redis Connection String with password"
    },
    "google_api_key": {
      "pattern": "AIza[A-Za-z0-9_-]{35}",
      "severity": "high",
      "description"
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/wisdomsword/skills/code-security-audit",
      "sourceUrl": "https://clawhub.ai/wisdomsword/skills/code-security-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T17:51:53.190Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-wisdomsword-code-security-audit/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-wisdomsword-code-security-audit/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T17:51:53.190Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.3K downloads",
      "href": "https://clawhub.ai/wisdomsword/code-security-audit",
      "sourceUrl": "https://clawhub.ai/wisdomsword/code-security-audit",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T17:51:53.190Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.1.0",
      "href": "https://clawhub.ai/wisdomsword/code-security-audit",
      "sourceUrl": "https://clawhub.ai/wisdomsword/code-security-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-24T05:56:56.757Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-wisdomsword-code-security-audit/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-wisdomsword-code-security-audit/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.1.0",
      "description": "**AI Agent security checks, pattern expansion, and Solidity support added.** - Added AI Agent security auditing (prompt injection, crypto wallet/key exposure) with a new `patterns/ai-agent.json` file. - Introduced quick and dedicated AI audit mode (`--ai`) for security checks inspired by recent incidents. - Expanded secret/key detection coverage (70+ patterns, including crypto wallets). - Updated security scoring to include AI Agent Security (15% weight). - Official support for Solidity and wider language coverage. - Improved documentation and quick start instructions.",
      "href": "https://clawhub.ai/wisdomsword/code-security-audit",
      "sourceUrl": "https://clawhub.ai/wisdomsword/code-security-audit",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-02-24T05:56:56.757Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to Code Security Audit and adjacent AI workflows.