{"id":"4912363b-f8e6-4c3f-b5b7-979a5f2d1898","entityType":"agent","slug":"clawhub-davida-ps-clawsec-feed","name":"clawsec-feed","canonicalUrl":"https://www.xpersona.co/agent/clawhub-davida-ps-clawsec-feed","canonicalPath":"/agent/clawhub-davida-ps-clawsec-feed","generatedAt":"2026-10-10T01:13:06.054Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily. Skill: clawsec-feed Owner: davida-ps Summary: Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily. Tags: latest:0.0.4 Version history: v0.0.4 | 2026-02-05T22:54:48.184Z | user Release 0.0.4 via CI v0.0.3 | 2026-02-05T22:37:11.473Z | user Release 0.0.3 via CI v0.0.2 | 2026-02-05T22:32:38.186Z | user Release 0.0.2 via CI v0.0.1 | 2026-02-05T21:14:52.097Z | user Rele","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 4/15/2026.","installCommand":"clawhub skill install kn76m78f01hqrtpgm895s0jsax80jd8v:clawsec-feed","sourceUrl":"https://clawhub.ai/davida-ps/clawsec-feed","homepage":"https://clawhub.ai/davida-ps/clawsec-feed","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/davida-ps/clawsec-feed","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily. Skill: clawsec-feed Owner: davida-ps Summary: Securit"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"stars":null,"forks":null,"downloads":1472,"packageName":null,"latestVersion":"0.0.4","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-02-28T21:55:01.288Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-28T21:55:01.288Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-01T21:55:01.288Z","lastVerifiedAt":null,"highlights":[{"version":"0.0.4","createdAt":"2026-02-05T22:54:48.184Z","changelog":"Release 0.0.4 via CI","fileCount":5,"zipByteSize":10954},{"version":"0.0.3","createdAt":"2026-02-05T22:37:11.473Z","changelog":"Release 0.0.3 via CI","fileCount":5,"zipByteSize":10941},{"version":"0.0.2","createdAt":"2026-02-05T22:32:38.186Z","changelog":"Release 0.0.2 via CI","fileCount":null,"zipByteSize":null},{"version":"0.0.1","createdAt":"2026-02-05T21:14:52.097Z","changelog":"Release 0.0.1 via CI","fileCount":null,"zipByteSize":null}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install kn76m78f01hqrtpgm895s0jsax80jd8v:clawsec-feed","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T01:13:06.054Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-feed/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"Skill: clawsec-feed\n\nOwner: davida-ps\n\nSummary: Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily.\n\nTags: latest:0.0.4\n\nVersion history:\n\nv0.0.4 | 2026-02-05T22:54:48.184Z | user\n\nRelease 0.0.4 via CI\n\nv0.0.3 | 2026-02-05T22:37:11.473Z | user\n\nRelease 0.0.3 via CI\n\nv0.0.2 | 2026-02-05T22:32:38.186Z | user\n\nRelease 0.0.2 via CI\n\nv0.0.1 | 2026-02-05T21:14:52.097Z | user\n\nRelease 0.0.1 via CI\n\nArchive index:\n\nArchive v0.0.4: 5 files, 10954 bytes\n\nFiles: advisories/feed.json (5819b), README.md (1795b), skill.json (1168b), SKILL.md (21229b), _meta.json (131b)\n\nFile v0.0.4:SKILL.md\n\n---\nname: clawsec-feed\nversion: 0.0.4\ndescription: Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily.\nhomepage: https://clawsec.prompt.security\nmetadata: {\"openclaw\":{\"emoji\":\"📡\",\"category\":\"security\"}}\nclawdis:\n  emoji: \"📡\"\n  requires:\n    bins: [curl, jq]\n---\n\n# ClawSec Feed 📡\n\nSecurity advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence and stay informed about emerging threats.\n\nThis feed is automatically updated daily with CVEs related to OpenClaw, clawdbot, and Moltbot from the NIST National Vulnerability Database (NVD).\n\n**An open source project by [Prompt Security](https://prompt.security)**\n\n---\n\n## Installation Options\n\nYou can get clawsec-feed in two ways:\n\n### Option A: Bundled with ClawSec Suite (Recommended)\n\n**If you've installed clawsec-suite, you may already have this!**\n\nClawSec-feed is bundled alongside ClawSec Suite to provide crucial CVE and threat intelligence information. When you install the suite, if you don't already have the feed installed, it will be deployed from the bundled copy.\n\n**Advantages:**\n- Convenient - no separate download needed\n- Standard location - installed to `~/.openclaw/skills/clawsec-feed/`\n- Preserved - if you already have feed installed, it won't be overwritten\n- Single verification - integrity checked as part of suite package\n\n### Option B: Standalone Installation (This Page)\n\nInstall clawsec-feed independently without the full suite.\n\n**When to use standalone:**\n- You only need the advisory feed (not other suite components)\n- You want to install before installing the suite\n- You prefer explicit control over feed installation\n\n**Advantages:**\n- Lighter weight installation\n- Independent from suite\n- Direct control over installation process\n\nContinue below for standalone installation instructions.\n\n---\n\nInstallation Steps:\nAgents should review scripts before execution!\n\n\n```bash\n# Get latest clawsec-feed release tag\nLATEST_TAG=$(curl -sSL https://api.github.com/repos/prompt-security/ClawSec/releases | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name')\n\n# Download SKILL.md from latest release\nSKILL_URL=\"https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG/SKILL.md\"\ncurl -sSL --fail --show-error \"$SKILL_URL\"\n```\n\nOnce you have this skill file, proceed to **[Deploy ClawSec Feed](#deploy-clawsec-feed)** below.\n\n---\n\n## Deploy ClawSec Feed\n\nInstallation steps:\n\n### Step 1: Create skill directory and save this file\n\n```bash\nmkdir -p ~/.openclaw/skills/clawsec-feed\n# Save this SKILL.md as SKILL.md in the directory above\n```\n\n### Step 2: Install skill files\n\n```bash\n# Get latest release tag with retry logic\nLATEST_TAG=$(curl -sSL --retry 3 --retry-delay 1 \\\n  https://api.github.com/repos/prompt-security/ClawSec/releases | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name')\n\nBASE_URL=\"https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG\"\nINSTALL_DIR=\"${CLAWSEC_INSTALL_DIR:-$HOME/.openclaw/skills/clawsec-feed}\"\nTEMP_DIR=$(mktemp -d)\ntrap \"rm -rf '$TEMP_DIR'\" EXIT\n\n# Download checksums.json (REQUIRED for integrity verification)\necho \"Downloading checksums...\"\nif ! curl -sSL --fail --show-error --retry 3 --retry-delay 1 \\\n     \"$BASE_URL/checksums.json\" -o \"$TEMP_DIR/checksums.json\"; then\n  echo \"ERROR: Failed to download checksums.json\"\n  exit 1\nfi\n\n# Validate checksums.json structure\nif ! jq -e '.skill and .version and .files' \"$TEMP_DIR/checksums.json\" >/dev/null 2>&1; then\n  echo \"ERROR: Invalid checksums.json structure\"\n  exit 1\nfi\n\n# PRIMARY: Try .skill artifact\necho \"Attempting .skill artifact installation...\"\nif curl -sSL --fail --show-error --retry 3 --retry-delay 1 \\\n   \"$BASE_URL/clawsec-feed.skill\" -o \"$TEMP_DIR/clawsec-feed.skill\" 2>/dev/null; then\n\n  # Security: Check artifact size (prevent DoS)\n  ARTIFACT_SIZE=$(stat -c%s \"$TEMP_DIR/clawsec-feed.skill\" 2>/dev/null || stat -f%z \"$TEMP_DIR/clawsec-feed.skill\")\n  MAX_SIZE=$((50 * 1024 * 1024))  # 50MB\n\n  if [ \"$ARTIFACT_SIZE\" -gt \"$MAX_SIZE\" ]; then\n    echo \"WARNING: Artifact too large ($(( ARTIFACT_SIZE / 1024 / 1024 ))MB), falling back to individual files\"\n  else\n    echo \"Extracting artifact ($(( ARTIFACT_SIZE / 1024 ))KB)...\"\n\n    # Security: Check for path traversal before extraction\n    if unzip -l \"$TEMP_DIR/clawsec-feed.skill\" | grep -qE '\\.\\./|^/|~/'; then\n      echo \"ERROR: Path traversal detected in artifact - possible security issue!\"\n      exit 1\n    fi\n\n    # Security: Check file count (prevent zip bomb)\n    FILE_COUNT=$(unzip -l \"$TEMP_DIR/clawsec-feed.skill\" | grep -c \"^[[:space:]]*[0-9]\" || echo 0)\n    if [ \"$FILE_COUNT\" -gt 100 ]; then\n      echo \"ERROR: Artifact contains too many files ($FILE_COUNT) - possible zip bomb\"\n      exit 1\n    fi\n\n    # Extract to temp directory\n    unzip -q \"$TEMP_DIR/clawsec-feed.skill\" -d \"$TEMP_DIR/extracted\"\n\n    # Verify skill.json exists\n    if [ ! -f \"$TEMP_DIR/extracted/clawsec-feed/skill.json\" ]; then\n      echo \"ERROR: skill.json not found in artifact\"\n      exit 1\n    fi\n\n    # Verify checksums for all extracted files\n    echo \"Verifying checksums...\"\n    CHECKSUM_FAILED=0\n    for file in $(jq -r '.files | keys[]' \"$TEMP_DIR/checksums.json\"); do\n      EXPECTED=$(jq -r --arg f \"$file\" '.files[$f].sha256' \"$TEMP_DIR/checksums.json\")\n      FILE_PATH=$(jq -r --arg f \"$file\" '.files[$f].path' \"$TEMP_DIR/checksums.json\")\n\n      # Try nested path first, then flat filename\n      if [ -f \"$TEMP_DIR/extracted/clawsec-feed/$FILE_PATH\" ]; then\n        ACTUAL=$(shasum -a 256 \"$TEMP_DIR/extracted/clawsec-feed/$FILE_PATH\" | cut -d' ' -f1)\n      elif [ -f \"$TEMP_DIR/extracted/clawsec-feed/$file\" ]; then\n        ACTUAL=$(shasum -a 256 \"$TEMP_DIR/extracted/clawsec-feed/$file\" | cut -d' ' -f1)\n      else\n        echo \"  ✗ $file (not found in artifact)\"\n        CHECKSUM_FAILED=1\n        continue\n      fi\n\n      if [ \"$EXPECTED\" != \"$ACTUAL\" ]; then\n        echo \"  ✗ $file (checksum mismatch)\"\n        CHECKSUM_FAILED=1\n      else\n        echo \"  ✓ $file\"\n      fi\n    done\n\n    if [ \"$CHECKSUM_FAILED\" -eq 0 ]; then\n      # Validate feed.json structure (skill-specific)\n      if [ -f \"$TEMP_DIR/extracted/clawsec-feed/advisories/feed.json\" ]; then\n        FEED_FILE=\"$TEMP_DIR/extracted/clawsec-feed/advisories/feed.json\"\n      elif [ -f \"$TEMP_DIR/extracted/clawsec-feed/feed.json\" ]; then\n        FEED_FILE=\"$TEMP_DIR/extracted/clawsec-feed/feed.json\"\n      else\n        echo \"ERROR: feed.json not found in artifact\"\n        exit 1\n      fi\n\n      if ! jq -e '.version and .advisories' \"$FEED_FILE\" >/dev/null 2>&1; then\n        echo \"ERROR: feed.json missing required fields (version, advisories)\"\n        exit 1\n      fi\n\n      # SUCCESS: Install from artifact\n      echo \"Installing from artifact...\"\n      mkdir -p \"$INSTALL_DIR\"\n      cp -r \"$TEMP_DIR/extracted/clawsec-feed\"/* \"$INSTALL_DIR/\"\n      chmod 600 \"$INSTALL_DIR/skill.json\"\n      find \"$INSTALL_DIR\" -type f ! -name \"skill.json\" -exec chmod 644 {} \\;\n      echo \"SUCCESS: Skill installed from .skill artifact\"\n      exit 0\n    else\n      echo \"WARNING: Checksum verification failed, falling back to individual files\"\n    fi\n  fi\nfi\n\n# FALLBACK: Download individual files\necho \"Downloading individual files from checksums.json manifest...\"\nmkdir -p \"$TEMP_DIR/downloads\"\n\nDOWNLOAD_FAILED=0\nfor file in $(jq -r '.files | keys[]' \"$TEMP_DIR/checksums.json\"); do\n  FILE_URL=$(jq -r --arg f \"$file\" '.files[$f].url' \"$TEMP_DIR/checksums.json\")\n  EXPECTED=$(jq -r --arg f \"$file\" '.files[$f].sha256' \"$TEMP_DIR/checksums.json\")\n\n  echo \"Downloading: $file\"\n  if ! curl -sSL --fail --show-error --retry 3 --retry-delay 1 \\\n       \"$FILE_URL\" -o \"$TEMP_DIR/downloads/$file\"; then\n    echo \"ERROR: Failed to download $file\"\n    DOWNLOAD_FAILED=1\n    continue\n  fi\n\n  # Verify checksum immediately\n  ACTUAL=$(shasum -a 256 \"$TEMP_DIR/downloads/$file\" | cut -d' ' -f1)\n  if [ \"$EXPECTED\" != \"$ACTUAL\" ]; then\n    echo \"ERROR: Checksum mismatch for $file\"\n    DOWNLOAD_FAILED=1\n  else\n    echo \"  ✓ Verified: $file\"\n  fi\ndone\n\nif [ \"$DOWNLOAD_FAILED\" -eq 1 ]; then\n  echo \"ERROR: Individual file download failed\"\n  exit 1\nfi\n\n# Validate JSON files structure\nif ! jq -e '.name and .version' \"$TEMP_DIR/downloads/skill.json\" >/dev/null 2>&1; then\n  echo \"ERROR: skill.json missing required fields (name, version)\"\n  exit 1\nfi\n\nif ! jq -e '.version and .advisories' \"$TEMP_DIR/downloads/feed.json\" >/dev/null 2>&1; then\n  echo \"ERROR: feed.json missing required fields (version, advisories)\"\n  exit 1\nfi\n\n# Install files\necho \"Installing from individual files...\"\nmkdir -p \"$INSTALL_DIR\"\ncp \"$TEMP_DIR/downloads\"/* \"$INSTALL_DIR/\"\nchmod 600 \"$INSTALL_DIR/skill.json\"\nfind \"$INSTALL_DIR\" -type f ! -name \"skill.json\" -exec chmod 644 {} \\;\necho \"SUCCESS: Skill installed from individual files\"\n```\n\n### Step 3: Add to your heartbeat\n\nAdd ClawSec Feed to your heartbeat routine:\n\n```markdown\n## ClawSec Feed (every heartbeat)\n1. Check advisory feed for new security alerts\n2. Cross-reference with installed skills\n3. Notify user if action is required\n```\n\n### Step 4: Confirm deployment\n\nTell your user:\n```\nClawSec Feed deployed successfully. I will now:\n- Monitor the community advisory feed for threats\n- Alert you to any security issues affecting your environment\n- Keep you informed of emerging attack patterns\n```\n\n---\n\n## What ClawSec Feed Does\n\n### Advisory Feed Monitoring\n\nSubscribes to the community advisory feed for:\n\n- **Known malicious skills/plugins** - Skills that have been identified as harmful\n- **Prompt injection patterns** - Attack patterns observed in the wild\n- **Vulnerable skill versions** - Skills with known security flaws\n- **Security best practice updates** - New recommendations for agent safety\n\nWhen a relevant advisory is published, your agent will notify you.\n\n---\n\n## Checking the Advisory Feed\n\n```bash\n# Use environment variable if set, otherwise use raw GitHub feed (always up-to-date)\nDEFAULT_FEED_URL=\"https://raw.githubusercontent.com/prompt-security/ClawSec/main/advisories/feed.json\"\nFEED_URL=\"${CLAWSEC_FEED_URL:-$DEFAULT_FEED_URL}\"\n\n# Fetch with error handling and retry logic\ncurl -sSL --fail --show-error --retry 3 --retry-delay 1 \"$FEED_URL\"\n```\n\n**Feed structure:**\n\n```json\n{\n  \"version\": \"1.0\",\n  \"updated\": \"2026-02-02T12:00:00Z\",\n  \"advisories\": [\n    {\n      \"id\": \"GA-2026-001\",\n      \"severity\": \"critical\",\n      \"type\": \"malicious_skill\",\n      \"title\": \"Malicious data exfiltration in skill 'helper-plus'\",\n      \"description\": \"Skill sends user data to external server\",\n      \"affected\": [\"helper-plus@1.0.0\", \"helper-plus@1.0.1\"],\n      \"action\": \"Remove immediately\",\n      \"published\": \"2026-02-01T10:00:00Z\"\n    }\n  ]\n}\n```\n\n---\n\n## Parsing the Feed\n\n### Get advisory count\n\n```bash\n# Use environment variable if set, otherwise use raw GitHub feed (always up-to-date)\nDEFAULT_FEED_URL=\"https://raw.githubusercontent.com/prompt-security/ClawSec/main/advisories/feed.json\"\nFEED_URL=\"${CLAWSEC_FEED_URL:-$DEFAULT_FEED_URL}\"\n\nTEMP_FEED=$(mktemp)\ntrap \"rm -f '$TEMP_FEED'\" EXIT\n\nif ! curl -sSL --fail --show-error --retry 3 --retry-delay 1 \"$FEED_URL\" -o \"$TEMP_FEED\"; then\n  echo \"Error: Failed to fetch advisory feed\"\n  exit 1\nfi\n\n# Validate JSON before parsing\nif ! jq empty \"$TEMP_FEED\" 2>/dev/null; then\n  echo \"Error: Invalid JSON in feed\"\n  exit 1\nfi\n\nFEED=$(cat \"$TEMP_FEED\")\n\n# Get advisory count with error handling\nCOUNT=$(echo \"$FEED\" | jq '.advisories | length')\nif [ $? -ne 0 ]; then\n  echo \"Error: Failed to parse advisories\"\n  exit 1\nfi\necho \"Advisory count: $COUNT\"\n```\n\n### Get critical advisories\n\n```bash\n# Parse critical advisories with jq error handling\nCRITICAL=$(echo \"$FEED\" | jq '.advisories[] | select(.severity == \"critical\")')\nif [ $? -ne 0 ]; then\n  echo \"Error: Failed to filter critical advisories\"\n  exit 1\nfi\necho \"$CRITICAL\"\n```\n\n### Get advisories from the last 7 days\n\n```bash\n# Use UTC timezone for consistent date handling\nWEEK_AGO=$(TZ=UTC date -v-7d +%Y-%m-%dT00:00:00Z 2>/dev/null || TZ=UTC date -d '7 days ago' +%Y-%m-%dT00:00:00Z)\nRECENT=$(echo \"$FEED\" | jq --arg since \"$WEEK_AGO\" '.advisories[] | select(.published > $since)')\nif [ $? -ne 0 ]; then\n  echo \"Error: Failed to filter recent advisories\"\n  exit 1\nfi\necho \"$RECENT\"\n```\n\n---\n\n## Cross-Reference Installed Skills\n\nCheck if any of your installed skills are affected by advisories:\n\n```bash\n# List your installed skills (adjust path for your platform)\nINSTALL_DIR=\"${CLAWSEC_INSTALL_DIR:-$HOME/.openclaw/skills}\"\n\n# Use environment variable if set, otherwise use raw GitHub feed (always up-to-date)\nDEFAULT_FEED_URL=\"https://raw.githubusercontent.com/prompt-security/ClawSec/main/advisories/feed.json\"\nFEED_URL=\"${CLAWSEC_FEED_URL:-$DEFAULT_FEED_URL}\"\n\nTEMP_FEED=$(mktemp)\ntrap \"rm -f '$TEMP_FEED'\" EXIT\n\nif ! curl -sSL --fail --show-error --retry 3 --retry-delay 1 \"$FEED_URL\" -o \"$TEMP_FEED\"; then\n  echo \"Error: Failed to fetch advisory feed\"\n  exit 1\nfi\n\n# Validate and parse feed\nif ! jq empty \"$TEMP_FEED\" 2>/dev/null; then\n  echo \"Error: Invalid JSON in feed\"\n  exit 1\nfi\n\nFEED=$(cat \"$TEMP_FEED\")\nAFFECTED=$(echo \"$FEED\" | jq -r '.advisories[].affected[]?' 2>/dev/null | sort -u)\nif [ $? -ne 0 ]; then\n  echo \"Error: Failed to parse affected skills from feed\"\n  exit 1\nfi\n\n# Safely validate all installed skills before processing\n# This prevents shell injection via malicious filenames\nVALIDATED_SKILLS=()\nwhile IFS= read -r -d '' skill_path; do\n  skill=$(basename \"$skill_path\")\n\n  # Validate skill name BEFORE adding to array (prevents injection)\n  if [[ \"$skill\" =~ ^[a-zA-Z0-9_-]+$ ]]; then\n    VALIDATED_SKILLS+=(\"$skill\")\n  else\n    echo \"Warning: Skipping invalid skill name: $skill\" >&2\n  fi\ndone < <(find \"$INSTALL_DIR\" -mindepth 1 -maxdepth 1 -type d -print0 2>/dev/null)\n\n# Check each validated skill against affected list\n# Use grep -qF for fixed string matching (prevents regex injection)\nfor skill in \"${VALIDATED_SKILLS[@]}\"; do\n  # At this point, $skill is guaranteed to match ^[a-zA-Z0-9_-]+$\n  if echo \"$AFFECTED\" | grep -qF \"$skill\"; then\n    echo \"WARNING: Installed skill '$skill' has a security advisory!\"\n    # Get advisory details for this skill\n    echo \"$FEED\" | jq --arg s \"$skill\" '.advisories[] | select(.affected[] | contains($s))'\n  fi\ndone\n```\n\n**If you find affected skills:**\n1. Check the advisory for details and severity\n2. Notify your user immediately for critical/high severity\n3. Include the recommended action from the advisory\n\n---\n\n## Advisory Types\n\n| Type | Description |\n|------|-------------|\n| `malicious_skill` | Skill identified as intentionally harmful |\n| `vulnerable_skill` | Skill with security vulnerabilities |\n| `prompt_injection` | Known prompt injection pattern |\n| `attack_pattern` | Observed attack technique |\n| `best_practice` | Security recommendation |\n\n---\n\n## Severity Levels\n\n| Severity | Action Required |\n|----------|-----------------|\n| `critical` | Notify user immediately, take action |\n| `high` | Notify user soon, plan remediation |\n| `medium` | Notify at next interaction |\n| `low` | Log for reference |\n\n---\n\n## When to Notify Your User\n\n**Notify Immediately (Critical):**\n- New critical advisory affecting an installed skill\n- Active exploitation detected\n\n**Notify Soon (High):**\n- New high-severity advisory affecting installed skills\n- Failed to fetch advisory feed (network issue?)\n\n**Notify at Next Interaction (Medium):**\n- New medium-severity advisories\n- General security updates\n\n**Log Only (Low/Info):**\n- Low-severity advisories (mention if user asks)\n- Feed checked, no new advisories\n\n---\n\n## Response Format\n\n### If there are new advisories:\n\n```\n📡 ClawSec Feed: 2 new advisories since last check\n\nCRITICAL - GA-2026-015: Malicious prompt pattern \"ignore-all\"\n  → Detected prompt injection technique. Update your system prompt defenses.\n\nHIGH - GA-2026-016: Vulnerable skill \"data-helper\" v1.2.0\n  → You have this installed! Recommended action: Update to v1.2.1 or remove.\n```\n\n### If nothing new:\n\n```\nFEED_OK - Advisory feed checked, no new alerts. 📡\n```\n\n---\n\n## State Tracking\n\nTrack the last feed check to identify new advisories:\n\n```json\n{\n  \"schema_version\": \"1.0\",\n  \"last_feed_check\": \"2026-02-02T15:00:00Z\",\n  \"last_feed_updated\": \"2026-02-02T12:00:00Z\",\n  \"known_advisories\": [\"GA-2026-001\", \"GA-2026-002\"]\n}\n```\n\nSave to: `~/.openclaw/clawsec-feed-state.json`\n\n### State File Operations\n\n```bash\nSTATE_FILE=\"$HOME/.openclaw/clawsec-feed-state.json\"\n\n# Create state file with secure permissions if it doesn't exist\nif [ ! -f \"$STATE_FILE\" ]; then\n  echo '{\"schema_version\":\"1.0\",\"last_feed_check\":null,\"last_feed_updated\":null,\"known_advisories\":[]}' > \"$STATE_FILE\"\n  chmod 600 \"$STATE_FILE\"\nfi\n\n# Validate state file before reading\nif ! jq -e '.schema_version' \"$STATE_FILE\" >/dev/null 2>&1; then\n  echo \"Warning: State file corrupted or invalid schema. Creating backup and resetting.\"\n  cp \"$STATE_FILE\" \"${STATE_FILE}.bak.$(TZ=UTC date +%Y%m%d%H%M%S)\"\n  echo '{\"schema_version\":\"1.0\",\"last_feed_check\":null,\"last_feed_updated\":null,\"known_advisories\":[]}' > \"$STATE_FILE\"\n  chmod 600 \"$STATE_FILE\"\nfi\n\n# Check for major version compatibility\nSCHEMA_VER=$(jq -r '.schema_version // \"0\"' \"$STATE_FILE\")\nif [[ \"${SCHEMA_VER%%.*}\" != \"1\" ]]; then\n  echo \"Warning: State file schema version $SCHEMA_VER may not be compatible with this version\"\nfi\n\n# Update last check time (always use UTC)\nTEMP_STATE=$(mktemp)\nif jq --arg t \"$(TZ=UTC date +%Y-%m-%dT%H:%M:%SZ)\" '.last_feed_check = $t' \"$STATE_FILE\" > \"$TEMP_STATE\"; then\n  mv \"$TEMP_STATE\" \"$STATE_FILE\"\n  chmod 600 \"$STATE_FILE\"\nelse\n  echo \"Error: Failed to update state file\"\n  rm -f \"$TEMP_STATE\"\nfi\n```\n\n---\n\n## Rate Limiting\n\n**Important:** To avoid excessive requests to the feed server, follow these guidelines:\n\n| Check Type | Recommended Interval | Minimum Interval |\n|------------|---------------------|------------------|\n| Heartbeat check | Every 15-30 minutes | 5 minutes |\n| Full feed refresh | Every 1-4 hours | 30 minutes |\n| Cross-reference scan | Once per session | 5 minutes |\n\n```bash\n# Check if enough time has passed since last check\nSTATE_FILE=\"$HOME/.openclaw/clawsec-feed-state.json\"\nMIN_INTERVAL_SECONDS=300  # 5 minutes\n\nLAST_CHECK=$(jq -r '.last_feed_check // \"1970-01-01T00:00:00Z\"' \"$STATE_FILE\" 2>/dev/null)\nLAST_EPOCH=$(TZ=UTC date -j -f \"%Y-%m-%dT%H:%M:%SZ\" \"$LAST_CHECK\" +%s 2>/dev/null || date -d \"$LAST_CHECK\" +%s 2>/dev/null || echo 0)\nNOW_EPOCH=$(TZ=UTC date +%s)\n\nif [ $((NOW_EPOCH - LAST_EPOCH)) -lt $MIN_INTERVAL_SECONDS ]; then\n  echo \"Rate limit: Last check was less than 5 minutes ago. Skipping.\"\n  exit 0\nfi\n```\n\n---\n\n## Environment Variables (Optional)\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| `CLAWSEC_FEED_URL` | Custom advisory feed URL | Raw GitHub (`main` branch) |\n| `CLAWSEC_INSTALL_DIR` | Installation directory | `~/.openclaw/skills/clawsec-feed` |\n\n---\n\n## Updating ClawSec Feed\n\nCheck for and install newer versions:\n\n```bash\n# Check current installed version\nINSTALL_DIR=\"${CLAWSEC_INSTALL_DIR:-$HOME/.openclaw/skills/clawsec-feed}\"\nCURRENT_VERSION=$(jq -r '.version' \"$INSTALL_DIR/skill.json\" 2>/dev/null || echo \"unknown\")\necho \"Installed version: $CURRENT_VERSION\"\n\n# Check latest available version\nLATEST_URL=\"https://api.github.com/repos/prompt-security/ClawSec/releases\"\nLATEST_VERSION=$(curl -sSL --fail --show-error --retry 3 --retry-delay 1 \"$LATEST_URL\" 2>/dev/null | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name // empty' | \\\n  sed 's/clawsec-feed-v//')\n\nif [ -z \"$LATEST_VERSION\" ]; then\n  echo \"Warning: Could not determine latest version\"\nelse\n  echo \"Latest version: $LATEST_VERSION\"\n\n  if [ \"$CURRENT_VERSION\" != \"$LATEST_VERSION\" ]; then\n    echo \"Update available! Run the deployment steps with the new version.\"\n  else\n    echo \"You are running the latest version.\"\n  fi\nfi\n```\n\n---\n\n## Initial Download Integrity\n\n**Bootstrap Trust Problem:** The initial download of this skill cannot be verified by the skill itself. To establish trust:\n\n1. **Verify the source URL** - Ensure you are downloading from `https://clawsec.prompt.security`\n2. **Check release signatures** - GitHub signs our releases; verify the release is from the checksums.\n3. **Compare checksums** - After download, compare the SHA-256 hash against the published `checksums.json`:\n\n```bash\n# After downloading SKILL.md, verify its integrity\nEXPECTED_HASH=\"<hash-from-checksums.json>\"\nACTUAL_HASH=$(shasum -a 256 SKILL.md | cut -d' ' -f1)\n\nif [ \"$EXPECTED_HASH\" != \"$ACTUAL_HASH\" ]; then\n  echo \"ERROR: Skill file integrity check failed!\"\n  echo \"This file may have been tampered with. Do not proceed.\"\n  exit 1\nfi\n```\n\n**Note:** For maximum security, verify checksums.json via a separate trusted channel (e.g., direct from GitHub release page UI, not via curl).\n\n---\n\n## Related Skills\n\n- **openclaw-audit-watchdog** - Automated daily security audits\n- **clawtributor** - Report vulnerabilities to the community\n\n---\n\n## License\n\nMIT License - See repository for details.\n\nBuilt with 📡 by the [Prompt Security](https://prompt.security) team and the agent community.\n\nFile v0.0.4:README.md\n\n# ClawSec Feed 📡\n\nSecurity advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence and stay informed about emerging threats.\n\n## Features\n\n- **Real-time Advisories** - Get notified about malicious skills, vulnerabilities, and attack patterns\n- **Cross-Reference Detection** - Automatically checks if your installed skills are affected\n- **Community-Driven** - Advisories contributed and reviewed by the security community\n- **Heartbeat Integration** - Seamlessly integrates with your agent's routine checks\n\n## Quick Install\n\n```bash\ncurl -sLO https://github.com/prompt-security/clawsec/releases/latest/download/clawsec-feed.skill\n```\n\n## Advisory Types\n\n| Type | Description |\n|------|-------------|\n| `malicious_skill` | Skills identified as intentionally harmful |\n| `vulnerable_skill` | Skills with security vulnerabilities |\n| `prompt_injection` | Known prompt injection patterns |\n| `attack_pattern` | Observed attack techniques |\n\n## Feed Structure\n\n```json\n{\n  \"version\": \"1.0\",\n  \"updated\": \"2026-02-02T12:00:00Z\",\n  \"advisories\": [\n    {\n      \"id\": \"GA-2026-001\",\n      \"severity\": \"critical\",\n      \"type\": \"malicious_skill\",\n      \"title\": \"Data exfiltration in 'helper-plus'\",\n      \"affected\": [\"helper-plus@1.0.0\"],\n      \"action\": \"Remove immediately\"\n    }\n  ]\n}\n```\n\n## Response Example\n\n```\n📡 ClawSec Feed: 2 new advisories\n\nCRITICAL - GA-2026-015: Malicious prompt pattern\n  → Update your system prompt defenses.\n\nHIGH - GA-2026-016: Vulnerable skill \"data-helper\"\n  → You have this installed! Update to v1.2.1\n```\n\n## Related Skills\n\n- **openclaw-audit-watchdog** - Automated daily security audits\n- **clawtributor** - Report vulnerabilities to the community\n\n## License\n\nMIT License - [Prompt Security](https://prompt.security)\n\nFile v0.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-feed\",\n  \"version\": \"0.0.4\",\n  \"publishedAt\": 1770332088184\n}\n\nFile v0.0.4:advisories/feed.json\n\n{\n  \"version\": \"0.0.2\",\n  \"updated\": \"2026-02-05T12:53:37Z\",\n  \"description\": \"Community-driven security advisory feed for ClawSec. Automatically updated with OpenClaw-related CVEs from NVD and community-reported security incidents.\",\n  \"advisories\": [\n    {\n      \"id\": \"CVE-2026-25475\",\n      \"severity\": \"medium\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/...\",\n      \"description\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can read any file on the system by outputting MEDIA:/path/to/file, exfiltrating sensitive data to the user/channel. This issue has been patched in version 2026.1.30.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-04T20:16:07.287\",\n      \"references\": [\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-r8g4-86fx-92mq\"\n      ],\n      \"cvss_score\": 6.5,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-25475\"\n    },\n    {\n      \"id\": \"CVE-2026-25157\",\n      \"severity\": \"high\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vu...\",\n      \"description\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-04T20:16:06.577\",\n      \"references\": [\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-q284-4pvr-m585\"\n      ],\n      \"cvss_score\": 7.7,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-25157\"\n    },\n    {\n      \"id\": \"CLAW-2026-0001\",\n      \"severity\": \"high\",\n      \"type\": \"prompt_injection\",\n      \"title\": \"Data exfiltration attempt via helper-plus skill\",\n      \"description\": \"The helper-plus skill was observed sending conversation data to an external server (suspicious-domain.com) on every invocation. The skill makes undocumented network calls that transmit full conversation context to a domain not mentioned in the skill description.\",\n      \"affected\": [\n        \"helper-plus@1.0.0\",\n        \"helper-plus@1.0.1\"\n      ],\n      \"action\": \"Remove helper-plus immediately. Do not use versions 1.0.0 or 1.0.1. Wait for a verified patched version.\",\n      \"published\": \"2026-02-04T09:30:00Z\",\n      \"references\": [],\n      \"source\": \"Community Report\",\n      \"github_issue_url\": \"https://github.com/prompt-security/clawsec/issues/1\",\n      \"reporter\": {\n        \"agent_name\": \"SecurityBot\",\n        \"opener_type\": \"agent\"\n      }\n    },\n    {\n      \"id\": \"CVE-2026-24763\",\n      \"severity\": \"high\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw (formerly  Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026....\",\n      \"description\": \"OpenClaw (formerly  Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClaw's Docker sandbox execution mechanism due to unsafe handling of the PATH environment variable when constructing shell commands. An authenticated user able to control environment variables could influence command execution within the container context. This vulnerability is fixed in 2026.1.29.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-02T23:16:08.593\",\n      \"references\": [\n        \"https://github.com/openclaw/openclaw/commit/771f23d36b95ec2204cc9a0054045f5d8439ea75\",\n        \"https://github.com/openclaw/openclaw/releases/tag/v2026.1.29\",\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-mc68-q9jw-2h3v\"\n      ],\n      \"cvss_score\": 8.8,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-24763\"\n    },\n    {\n      \"id\": \"CVE-2026-25253\",\n      \"severity\": \"high\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string a...\",\n      \"description\": \"OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-01T23:15:49.717\",\n      \"references\": [\n        \"https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys\",\n        \"https://ethiack.com/news/blog/one-click-rce-moltbot\",\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-g8p2-7wf7-98mq\"\n      ],\n      \"cvss_score\": 8.8,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-25253\"\n    }\n  ]\n}\n\nFile v0.0.4:skill.json\n\n{\n  \"name\": \"clawsec-feed\",\n  \"version\": \"0.0.4\",\n  \"description\": \"Security advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"MIT\",\n  \"homepage\": \"https://clawsec.prompt.security\",\n  \"keywords\": [\n    \"security\",\n    \"advisory\",\n    \"feed\",\n    \"agents\",\n    \"ai\",\n    \"threat-intel\",\n    \"monitoring\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Advisory feed skill documentation\"\n      },\n      {\n        \"path\": \"advisories/feed.json\",\n        \"required\": true,\n        \"description\": \"Community security advisory feed\"\n      }\n    ]\n  },\n  \"openclaw\": {\n    \"emoji\": \"📡\",\n    \"category\": \"security\",\n    \"feed_url\": \"https://api.github.com/repos/prompt-security/ClawSec/releases?skill=clawsec-feed\",\n    \"requires\": {\n      \"bins\": [\n        \"curl\",\n        \"jq\"\n      ]\n    },\n    \"triggers\": [\n      \"security advisories\",\n      \"check advisories\",\n      \"clawsec\",\n      \"threat feed\",\n      \"security alerts\",\n      \"vulnerability feed\",\n      \"advisory feed\",\n      \"security news\"\n    ]\n  }\n}\n\nArchive v0.0.3: 5 files, 10941 bytes\n\nFiles: advisories/feed.json (5819b), README.md (1795b), skill.json (1168b), SKILL.md (21207b), _meta.json (131b)\n\nFile v0.0.3:SKILL.md\n\n---\nname: clawsec-feed\nversion: 0.0.3\ndescription: Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily.\nhomepage: https://clawsec.prompt.security\nmetadata: {\"openclaw\":{\"emoji\":\"📡\",\"category\":\"security\"}}\nclawdis:\n  emoji: \"📡\"\n  requires:\n    bins: [curl, jq]\n---\n\n# ClawSec Feed 📡\n\nSecurity advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence and stay informed about emerging threats.\n\nThis feed is automatically updated daily with CVEs related to OpenClaw, clawdbot, and Moltbot from the NIST National Vulnerability Database (NVD).\n\n**An open source project by [Prompt Security](https://prompt.security)**\n\n---\n\n## Installation Options\n\nYou can get clawsec-feed in two ways:\n\n### Option A: Bundled with ClawSec Suite (Recommended)\n\n**If you've installed clawsec-suite, you may already have this!**\n\nClawSec-feed is bundled alongside ClawSec Suite to provide crucial CVE and threat intelligence information. When you install the suite, if you don't already have the feed installed, it will be deployed from the bundled copy.\n\n**Advantages:**\n- Convenient - no separate download needed\n- Standard location - installed to `~/.openclaw/skills/clawsec-feed/`\n- Preserved - if you already have feed installed, it won't be overwritten\n- Single verification - integrity checked as part of suite package\n\n### Option B: Standalone Installation (This Page)\n\nInstall clawsec-feed independently without the full suite.\n\n**When to use standalone:**\n- You only need the advisory feed (not other suite components)\n- You want to install before installing the suite\n- You prefer explicit control over feed installation\n\n**Advantages:**\n- Lighter weight installation\n- Independent from suite\n- Direct control over installation process\n\nContinue below for standalone installation instructions.\n\n---\n\nInstallation Steps:\n\n```bash\n# Get latest clawsec-feed release tag\nLATEST_TAG=$(curl -sSL https://api.github.com/repos/prompt-security/ClawSec/releases | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name')\n\n# Download SKILL.md from latest release\nSKILL_URL=\"https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG/SKILL.md\"\ncurl -sSL --fail --show-error \"$SKILL_URL\"\n```\n\nOnce you have this skill file, proceed to **[Deploy ClawSec Feed](#deploy-clawsec-feed)** below.\n\n---\n\n## Deploy ClawSec Feed\n\nInstallation steps:\n\n### Step 1: Create skill directory and save this file\n\n```bash\nmkdir -p ~/.openclaw/skills/clawsec-feed\n# Save this SKILL.md as SKILL.md in the directory above\n```\n\n### Step 2: Install skill files\n\n```bash\n# Get latest release tag with retry logic\nLATEST_TAG=$(curl -sSL --retry 3 --retry-delay 1 \\\n  https://api.github.com/repos/prompt-security/ClawSec/releases | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name')\n\nBASE_URL=\"https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG\"\nINSTALL_DIR=\"${CLAWSEC_INSTALL_DIR:-$HOME/.openclaw/skills/clawsec-feed}\"\nTEMP_DIR=$(mktemp -d)\ntrap \"rm -rf '$TEMP_DIR'\" EXIT\n\n# Download checksums.json (REQUIRED for integrity verification)\necho \"Downloading checksums...\"\nif ! curl -sSL --fail --show-error --retry 3 --retry-delay 1 \\\n     \"$BASE_URL/checksums.json\" -o \"$TEMP_DIR/checksums.json\"; then\n  echo \"ERROR: Failed to download checksums.json\"\n  exit 1\nfi\n\n# Validate checksums.json structure\nif ! jq -e '.skill and .version and .files' \"$TEMP_DIR/checksums.json\" >/dev/null 2>&1; then\n  echo \"ERROR: Invalid checksums.json structure\"\n  exit 1\nfi\n\n# PRIMARY: Try .skill artifact\necho \"Attempting .skill artifact installation...\"\nif curl -sSL --fail --show-error --retry 3 --retry-delay 1 \\\n   \"$BASE_URL/clawsec-feed.skill\" -o \"$TEMP_DIR/clawsec-feed.skill\" 2>/dev/null; then\n\n  # Security: Check artifact size (prevent DoS)\n  ARTIFACT_SIZE=$(stat -c%s \"$TEMP_DIR/clawsec-feed.skill\" 2>/dev/null || stat -f%z \"$TEMP_DIR/clawsec-feed.skill\")\n  MAX_SIZE=$((50 * 1024 * 1024))  # 50MB\n\n  if [ \"$ARTIFACT_SIZE\" -gt \"$MAX_SIZE\" ]; then\n    echo \"WARNING: Artifact too large ($(( ARTIFACT_SIZE / 1024 / 1024 ))MB), falling back to individual files\"\n  else\n    echo \"Extracting artifact ($(( ARTIFACT_SIZE / 1024 ))KB)...\"\n\n    # Security: Check for path traversal before extraction\n    if unzip -l \"$TEMP_DIR/clawsec-feed.skill\" | grep -qE '\\.\\./|^/|~/'; then\n      echo \"ERROR: Path traversal detected in artifact - possible security issue!\"\n      exit 1\n    fi\n\n    # Security: Check file count (prevent zip bomb)\n    FILE_COUNT=$(unzip -l \"$TEMP_DIR/clawsec-feed.skill\" | grep -c \"^[[:space:]]*[0-9]\" || echo 0)\n    if [ \"$FILE_COUNT\" -gt 100 ]; then\n      echo \"ERROR: Artifact contains too many files ($FILE_COUNT) - possible zip bomb\"\n      exit 1\n    fi\n\n    # Extract to temp directory\n    unzip -q \"$TEMP_DIR/clawsec-feed.skill\" -d \"$TEMP_DIR/extracted\"\n\n    # Verify skill.json exists\n    if [ ! -f \"$TEMP_DIR/extracted/clawsec-feed/skill.json\" ]; then\n      echo \"ERROR: skill.json not found in artifact\"\n      exit 1\n    fi\n\n    # Verify checksums for all extracted files\n    echo \"Verifying checksums...\"\n    CHECKSUM_FAILED=0\n    for file in $(jq -r '.files | keys[]' \"$TEMP_DIR/checksums.json\"); do\n      EXPECTED=$(jq -r --arg f \"$file\" '.files[$f].sha256' \"$TEMP_DIR/checksums.json\")\n      FILE_PATH=$(jq -r --arg f \"$file\" '.files[$f].path' \"$TEMP_DIR/checksums.json\")\n\n      # Try nested path first, then flat filename\n      if [ -f \"$TEMP_DIR/extracted/clawsec-feed/$FILE_PATH\" ]; then\n        ACTUAL=$(shasum -a 256 \"$TEMP_DIR/extracted/clawsec-feed/$FILE_PATH\" | cut -d' ' -f1)\n      elif [ -f \"$TEMP_DIR/extracted/clawsec-feed/$file\" ]; then\n        ACTUAL=$(shasum -a 256 \"$TEMP_DIR/extracted/clawsec-feed/$file\" | cut -d' ' -f1)\n      else\n        echo \"  ✗ $file (not found in artifact)\"\n        CHECKSUM_FAILED=1\n        continue\n      fi\n\n      if [ \"$EXPECTED\" != \"$ACTUAL\" ]; then\n        echo \"  ✗ $file (checksum mismatch)\"\n        CHECKSUM_FAILED=1\n      else\n        echo \"  ✓ $file\"\n      fi\n    done\n\n    if [ \"$CHECKSUM_FAILED\" -eq 0 ]; then\n      # Validate feed.json structure (skill-specific)\n      if [ -f \"$TEMP_DIR/extracted/clawsec-feed/advisories/feed.json\" ]; then\n        FEED_FILE=\"$TEMP_DIR/extracted/clawsec-feed/advisories/feed.json\"\n      elif [ -f \"$TEMP_DIR/extracted/clawsec-feed/feed.json\" ]; then\n        FEED_FILE=\"$TEMP_DIR/extracted/clawsec-feed/feed.json\"\n      else\n        echo \"ERROR: feed.json not found in artifact\"\n        exit 1\n      fi\n\n      if ! jq -e '.version and .advisories' \"$FEED_FILE\" >/dev/null 2>&1; then\n        echo \"ERROR: feed.json missing required fields (version, advisories)\"\n        exit 1\n      fi\n\n      # SUCCESS: Install from artifact\n      echo \"Installing from artifact...\"\n      mkdir -p \"$INSTALL_DIR\"\n      cp -r \"$TEMP_DIR/extracted/clawsec-feed\"/* \"$INSTALL_DIR/\"\n      chmod 600 \"$INSTALL_DIR/skill.json\"\n      find \"$INSTALL_DIR\" -type f ! -name \"skill.json\" -exec chmod 644 {} \\;\n      echo \"SUCCESS: Skill installed from .skill artifact\"\n      exit 0\n    else\n      echo \"WARNING: Checksum verification failed, falling back to individual files\"\n    fi\n  fi\nfi\n\n# FALLBACK: Download individual files\necho \"Downloading individual files from checksums.json manifest...\"\nmkdir -p \"$TEMP_DIR/downloads\"\n\nDOWNLOAD_FAILED=0\nfor file in $(jq -r '.files | keys[]' \"$TEMP_DIR/checksums.json\"); do\n  FILE_URL=$(jq -r --arg f \"$file\" '.files[$f].url' \"$TEMP_DIR/checksums.json\")\n  EXPECTED=$(jq -r --arg f \"$file\" '.files[$f].sha256' \"$TEMP_DIR/checksums.json\")\n\n  echo \"Downloading: $file\"\n  if ! curl -sSL --fail --show-error --retry 3 --retry-delay 1 \\\n       \"$FILE_URL\" -o \"$TEMP_DIR/downloads/$file\"; then\n    echo \"ERROR: Failed to download $file\"\n    DOWNLOAD_FAILED=1\n    continue\n  fi\n\n  # Verify checksum immediately\n  ACTUAL=$(shasum -a 256 \"$TEMP_DIR/downloads/$file\" | cut -d' ' -f1)\n  if [ \"$EXPECTED\" != \"$ACTUAL\" ]; then\n    echo \"ERROR: Checksum mismatch for $file\"\n    DOWNLOAD_FAILED=1\n  else\n    echo \"  ✓ Verified: $file\"\n  fi\ndone\n\nif [ \"$DOWNLOAD_FAILED\" -eq 1 ]; then\n  echo \"ERROR: Individual file download failed\"\n  exit 1\nfi\n\n# Validate JSON files structure\nif ! jq -e '.name and .version' \"$TEMP_DIR/downloads/skill.json\" >/dev/null 2>&1; then\n  echo \"ERROR: skill.json missing required fields (name, version)\"\n  exit 1\nfi\n\nif ! jq -e '.version and .advisories' \"$TEMP_DIR/downloads/feed.json\" >/dev/null 2>&1; then\n  echo \"ERROR: feed.json missing required fields (version, advisories)\"\n  exit 1\nfi\n\n# Install files\necho \"Installing from individual files...\"\nmkdir -p \"$INSTALL_DIR\"\ncp \"$TEMP_DIR/downloads\"/* \"$INSTALL_DIR/\"\nchmod 600 \"$INSTALL_DIR/skill.json\"\nfind \"$INSTALL_DIR\" -type f ! -name \"skill.json\" -exec chmod 644 {} \\;\necho \"SUCCESS: Skill installed from individual files\"\n```\n\n### Step 3: Add to your heartbeat\n\nAdd ClawSec Feed to your heartbeat routine:\n\n```markdown\n## ClawSec Feed (every heartbeat)\n1. Check advisory feed for new security alerts\n2. Cross-reference with installed skills\n3. Notify user if action is required\n```\n\n### Step 4: Confirm deployment\n\nTell your user:\n```\nClawSec Feed deployed successfully. I will now:\n- Monitor the community advisory feed for threats\n- Alert you to any security issues affecting your environment\n- Keep you informed of emerging attack patterns\n```\n\n---\n\n## What ClawSec Feed Does\n\n### Advisory Feed Monitoring\n\nSubscribes to the community advisory feed for:\n\n- **Known malicious skills/plugins** - Skills that have been identified as harmful\n- **Prompt injection patterns** - Attack patterns observed in the wild\n- **Vulnerable skill versions** - Skills with known security flaws\n- **Security best practice updates** - New recommendations for agent safety\n\nWhen a relevant advisory is published, your agent will notify you.\n\n---\n\n## Checking the Advisory Feed\n\n```bash\n# Use environment variable if set, otherwise use raw GitHub feed (always up-to-date)\nDEFAULT_FEED_URL=\"https://raw.githubusercontent.com/prompt-security/ClawSec/main/advisories/feed.json\"\nFEED_URL=\"${CLAWSEC_FEED_URL:-$DEFAULT_FEED_URL}\"\n\n# Fetch with error handling and retry logic\ncurl -sSL --fail --show-error --retry 3 --retry-delay 1 \"$FEED_URL\"\n```\n\n**Feed structure:**\n\n```json\n{\n  \"version\": \"1.0\",\n  \"updated\": \"2026-02-02T12:00:00Z\",\n  \"advisories\": [\n    {\n      \"id\": \"GA-2026-001\",\n      \"severity\": \"critical\",\n      \"type\": \"malicious_skill\",\n      \"title\": \"Malicious data exfiltration in skill 'helper-plus'\",\n      \"description\": \"Skill sends user data to external server\",\n      \"affected\": [\"helper-plus@1.0.0\", \"helper-plus@1.0.1\"],\n      \"action\": \"Remove immediately\",\n      \"published\": \"2026-02-01T10:00:00Z\"\n    }\n  ]\n}\n```\n\n---\n\n## Parsing the Feed\n\n### Get advisory count\n\n```bash\n# Use environment variable if set, otherwise use raw GitHub feed (always up-to-date)\nDEFAULT_FEED_URL=\"https://raw.githubusercontent.com/prompt-security/ClawSec/main/advisories/feed.json\"\nFEED_URL=\"${CLAWSEC_FEED_URL:-$DEFAULT_FEED_URL}\"\n\nTEMP_FEED=$(mktemp)\ntrap \"rm -f '$TEMP_FEED'\" EXIT\n\nif ! curl -sSL --fail --show-error --retry 3 --retry-delay 1 \"$FEED_URL\" -o \"$TEMP_FEED\"; then\n  echo \"Error: Failed to fetch advisory feed\"\n  exit 1\nfi\n\n# Validate JSON before parsing\nif ! jq empty \"$TEMP_FEED\" 2>/dev/null; then\n  echo \"Error: Invalid JSON in feed\"\n  exit 1\nfi\n\nFEED=$(cat \"$TEMP_FEED\")\n\n# Get advisory count with error handling\nCOUNT=$(echo \"$FEED\" | jq '.advisories | length')\nif [ $? -ne 0 ]; then\n  echo \"Error: Failed to parse advisories\"\n  exit 1\nfi\necho \"Advisory count: $COUNT\"\n```\n\n### Get critical advisories\n\n```bash\n# Parse critical advisories with jq error handling\nCRITICAL=$(echo \"$FEED\" | jq '.advisories[] | select(.severity == \"critical\")')\nif [ $? -ne 0 ]; then\n  echo \"Error: Failed to filter critical advisories\"\n  exit 1\nfi\necho \"$CRITICAL\"\n```\n\n### Get advisories from the last 7 days\n\n```bash\n# Use UTC timezone for consistent date handling\nWEEK_AGO=$(TZ=UTC date -v-7d +%Y-%m-%dT00:00:00Z 2>/dev/null || TZ=UTC date -d '7 days ago' +%Y-%m-%dT00:00:00Z)\nRECENT=$(echo \"$FEED\" | jq --arg since \"$WEEK_AGO\" '.advisories[] | select(.published > $since)')\nif [ $? -ne 0 ]; then\n  echo \"Error: Failed to filter recent advisories\"\n  exit 1\nfi\necho \"$RECENT\"\n```\n\n---\n\n## Cross-Reference Installed Skills\n\nCheck if any of your installed skills are affected by advisories:\n\n```bash\n# List your installed skills (adjust path for your platform)\nINSTALL_DIR=\"${CLAWSEC_INSTALL_DIR:-$HOME/.openclaw/skills}\"\n\n# Use environment variable if set, otherwise use raw GitHub feed (always up-to-date)\nDEFAULT_FEED_URL=\"https://raw.githubusercontent.com/prompt-security/ClawSec/main/advisories/feed.json\"\nFEED_URL=\"${CLAWSEC_FEED_URL:-$DEFAULT_FEED_URL}\"\n\nTEMP_FEED=$(mktemp)\ntrap \"rm -f '$TEMP_FEED'\" EXIT\n\nif ! curl -sSL --fail --show-error --retry 3 --retry-delay 1 \"$FEED_URL\" -o \"$TEMP_FEED\"; then\n  echo \"Error: Failed to fetch advisory feed\"\n  exit 1\nfi\n\n# Validate and parse feed\nif ! jq empty \"$TEMP_FEED\" 2>/dev/null; then\n  echo \"Error: Invalid JSON in feed\"\n  exit 1\nfi\n\nFEED=$(cat \"$TEMP_FEED\")\nAFFECTED=$(echo \"$FEED\" | jq -r '.advisories[].affected[]?' 2>/dev/null | sort -u)\nif [ $? -ne 0 ]; then\n  echo \"Error: Failed to parse affected skills from feed\"\n  exit 1\nfi\n\n# Safely validate all installed skills before processing\n# This prevents shell injection via malicious filenames\nVALIDATED_SKILLS=()\nwhile IFS= read -r -d '' skill_path; do\n  skill=$(basename \"$skill_path\")\n\n  # Validate skill name BEFORE adding to array (prevents injection)\n  if [[ \"$skill\" =~ ^[a-zA-Z0-9_-]+$ ]]; then\n    VALIDATED_SKILLS+=(\"$skill\")\n  else\n    echo \"Warning: Skipping invalid skill name: $skill\" >&2\n  fi\ndone < <(find \"$INSTALL_DIR\" -mindepth 1 -maxdepth 1 -type d -print0 2>/dev/null)\n\n# Check each validated skill against affected list\n# Use grep -qF for fixed string matching (prevents regex injection)\nfor skill in \"${VALIDATED_SKILLS[@]}\"; do\n  # At this point, $skill is guaranteed to match ^[a-zA-Z0-9_-]+$\n  if echo \"$AFFECTED\" | grep -qF \"$skill\"; then\n    echo \"WARNING: Installed skill '$skill' has a security advisory!\"\n    # Get advisory details for this skill\n    echo \"$FEED\" | jq --arg s \"$skill\" '.advisories[] | select(.affected[] | contains($s))'\n  fi\ndone\n```\n\n**If you find affected skills:**\n1. Check the advisory for details and severity\n2. Notify your user immediately for critical/high severity\n3. Include the recommended action from the advisory\n\n---\n\n## Advisory Types\n\n| Type | Description |\n|------|-------------|\n| `malicious_skill` | Skill identified as intentionally harmful |\n| `vulnerable_skill` | Skill with security vulnerabilities |\n| `prompt_injection` | Known prompt injection pattern |\n| `attack_pattern` | Observed attack technique |\n| `best_practice` | Security recommendation |\n\n---\n\n## Severity Levels\n\n| Severity | Action Required |\n|----------|-----------------|\n| `critical` | Notify user immediately, take action |\n| `high` | Notify user soon, plan remediation |\n| `medium` | Notify at next interaction |\n| `low` | Log for reference |\n\n---\n\n## When to Notify Your User\n\n**Notify Immediately (Critical):**\n- New critical advisory affecting an installed skill\n- Active exploitation detected\n\n**Notify Soon (High):**\n- New high-severity advisory affecting installed skills\n- Failed to fetch advisory feed (network issue?)\n\n**Notify at Next Interaction (Medium):**\n- New medium-severity advisories\n- General security updates\n\n**Log Only (Low/Info):**\n- Low-severity advisories (mention if user asks)\n- Feed checked, no new advisories\n\n---\n\n## Response Format\n\n### If there are new advisories:\n\n```\n📡 ClawSec Feed: 2 new advisories since last check\n\nCRITICAL - GA-2026-015: Malicious prompt pattern \"ignore-all\"\n  → Detected prompt injection technique. Update your system prompt defenses.\n\nHIGH - GA-2026-016: Vulnerable skill \"data-helper\" v1.2.0\n  → You have this installed! Recommended action: Update to v1.2.1 or remove.\n```\n\n### If nothing new:\n\n```\nFEED_OK - Advisory feed checked, no new alerts. 📡\n```\n\n---\n\n## State Tracking\n\nTrack the last feed check to identify new advisories:\n\n```json\n{\n  \"schema_version\": \"1.0\",\n  \"last_feed_check\": \"2026-02-02T15:00:00Z\",\n  \"last_feed_updated\": \"2026-02-02T12:00:00Z\",\n  \"known_advisories\": [\"GA-2026-001\", \"GA-2026-002\"]\n}\n```\n\nSave to: `~/.openclaw/clawsec-feed-state.json`\n\n### State File Operations\n\n```bash\nSTATE_FILE=\"$HOME/.openclaw/clawsec-feed-state.json\"\n\n# Create state file with secure permissions if it doesn't exist\nif [ ! -f \"$STATE_FILE\" ]; then\n  echo '{\"schema_version\":\"1.0\",\"last_feed_check\":null,\"last_feed_updated\":null,\"known_advisories\":[]}' > \"$STATE_FILE\"\n  chmod 600 \"$STATE_FILE\"\nfi\n\n# Validate state file before reading\nif ! jq -e '.schema_version' \"$STATE_FILE\" >/dev/null 2>&1; then\n  echo \"Warning: State file corrupted or invalid schema. Creating backup and resetting.\"\n  cp \"$STATE_FILE\" \"${STATE_FILE}.bak.$(TZ=UTC date +%Y%m%d%H%M%S)\"\n  echo '{\"schema_version\":\"1.0\",\"last_feed_check\":null,\"last_feed_updated\":null,\"known_advisories\":[]}' > \"$STATE_FILE\"\n  chmod 600 \"$STATE_FILE\"\nfi\n\n# Check for major version compatibility\nSCHEMA_VER=$(jq -r '.schema_version // \"0\"' \"$STATE_FILE\")\nif [[ \"${SCHEMA_VER%%.*}\" != \"1\" ]]; then\n  echo \"Warning: State file schema version $SCHEMA_VER may not be compatible with this version\"\nfi\n\n# Update last check time (always use UTC)\nTEMP_STATE=$(mktemp)\nif jq --arg t \"$(TZ=UTC date +%Y-%m-%dT%H:%M:%SZ)\" '.last_feed_check = $t' \"$STATE_FILE\" > \"$TEMP_STATE\"; then\n  mv \"$TEMP_STATE\" \"$STATE_FILE\"\n  chmod 600 \"$STATE_FILE\"\nelse\n  echo \"Error: Failed to update state file\"\n  rm -f \"$TEMP_STATE\"\nfi\n```\n\n---\n\n## Rate Limiting\n\n**Important:** To avoid excessive requests to the feed server, follow these guidelines:\n\n| Check Type | Recommended Interval | Minimum Interval |\n|------------|---------------------|------------------|\n| Heartbeat check | Every 15-30 minutes | 5 minutes |\n| Full feed refresh | Every 1-4 hours | 30 minutes |\n| Cross-reference scan | Once per session | 5 minutes |\n\n```bash\n# Check if enough time has passed since last check\nSTATE_FILE=\"$HOME/.openclaw/clawsec-feed-state.json\"\nMIN_INTERVAL_SECONDS=300  # 5 minutes\n\nLAST_CHECK=$(jq -r '.last_feed_check // \"1970-01-01T00:00:00Z\"' \"$STATE_FILE\" 2>/dev/null)\nLAST_EPOCH=$(TZ=UTC date -j -f \"%Y-%m-%dT%H:%M:%SZ\" \"$LAST_CHECK\" +%s 2>/dev/null || date -d \"$LAST_CHECK\" +%s 2>/dev/null || echo 0)\nNOW_EPOCH=$(TZ=UTC date +%s)\n\nif [ $((NOW_EPOCH - LAST_EPOCH)) -lt $MIN_INTERVAL_SECONDS ]; then\n  echo \"Rate limit: Last check was less than 5 minutes ago. Skipping.\"\n  exit 0\nfi\n```\n\n---\n\n## Environment Variables (Optional)\n\n| Variable | Description | Default |\n|----------|-------------|---------|\n| `CLAWSEC_FEED_URL` | Custom advisory feed URL | Raw GitHub (`main` branch) |\n| `CLAWSEC_INSTALL_DIR` | Installation directory | `~/.openclaw/skills/clawsec-feed` |\n\n---\n\n## Updating ClawSec Feed\n\nCheck for and install newer versions:\n\n```bash\n# Check current installed version\nINSTALL_DIR=\"${CLAWSEC_INSTALL_DIR:-$HOME/.openclaw/skills/clawsec-feed}\"\nCURRENT_VERSION=$(jq -r '.version' \"$INSTALL_DIR/skill.json\" 2>/dev/null || echo \"unknown\")\necho \"Installed version: $CURRENT_VERSION\"\n\n# Check latest available version\nLATEST_URL=\"https://api.github.com/repos/prompt-security/ClawSec/releases\"\nLATEST_VERSION=$(curl -sSL --fail --show-error --retry 3 --retry-delay 1 \"$LATEST_URL\" 2>/dev/null | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name // empty' | \\\n  sed 's/clawsec-feed-v//')\n\nif [ -z \"$LATEST_VERSION\" ]; then\n  echo \"Warning: Could not determine latest version\"\nelse\n  echo \"Latest version: $LATEST_VERSION\"\n\n  if [ \"$CURRENT_VERSION\" != \"$LATEST_VERSION\" ]; then\n    echo \"Update available! Run the deployment steps with the new version.\"\n  else\n    echo \"You are running the latest version.\"\n  fi\nfi\n```\n\n---\n\n## Initial Download Integrity\n\n**Bootstrap Trust Problem:** The initial download of this skill cannot be verified by the skill itself. To establish trust:\n\n1. **Verify the source URL** - Ensure you are downloading from `github.com/prompt-security/clawsec`\n2. **Check GitHub release signatures** - GitHub signs releases; verify the release is from the `prompt-security` organization\n3. **Compare checksums** - After download, compare the SHA-256 hash against the published `checksums.json`:\n\n```bash\n# After downloading SKILL.md, verify its integrity\nEXPECTED_HASH=\"<hash-from-checksums.json>\"\nACTUAL_HASH=$(shasum -a 256 SKILL.md | cut -d' ' -f1)\n\nif [ \"$EXPECTED_HASH\" != \"$ACTUAL_HASH\" ]; then\n  echo \"ERROR: Skill file integrity check failed!\"\n  echo \"This file may have been tampered with. Do not proceed.\"\n  exit 1\nfi\n```\n\n**Note:** For maximum security, verify checksums.json via a separate trusted channel (e.g., direct from GitHub release page UI, not via curl).\n\n---\n\n## Related Skills\n\n- **openclaw-audit-watchdog** - Automated daily security audits\n- **clawtributor** - Report vulnerabilities to the community\n\n---\n\n## License\n\nMIT License - See repository for details.\n\nBuilt with 📡 by the [Prompt Security](https://prompt.security) team and the agent community.\n\nFile v0.0.3:README.md\n\n# ClawSec Feed 📡\n\nSecurity advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence and stay informed about emerging threats.\n\n## Features\n\n- **Real-time Advisories** - Get notified about malicious skills, vulnerabilities, and attack patterns\n- **Cross-Reference Detection** - Automatically checks if your installed skills are affected\n- **Community-Driven** - Advisories contributed and reviewed by the security community\n- **Heartbeat Integration** - Seamlessly integrates with your agent's routine checks\n\n## Quick Install\n\n```bash\ncurl -sLO https://github.com/prompt-security/clawsec/releases/latest/download/clawsec-feed.skill\n```\n\n## Advisory Types\n\n| Type | Description |\n|------|-------------|\n| `malicious_skill` | Skills identified as intentionally harmful |\n| `vulnerable_skill` | Skills with security vulnerabilities |\n| `prompt_injection` | Known prompt injection patterns |\n| `attack_pattern` | Observed attack techniques |\n\n## Feed Structure\n\n```json\n{\n  \"version\": \"1.0\",\n  \"updated\": \"2026-02-02T12:00:00Z\",\n  \"advisories\": [\n    {\n      \"id\": \"GA-2026-001\",\n      \"severity\": \"critical\",\n      \"type\": \"malicious_skill\",\n      \"title\": \"Data exfiltration in 'helper-plus'\",\n      \"affected\": [\"helper-plus@1.0.0\"],\n      \"action\": \"Remove immediately\"\n    }\n  ]\n}\n```\n\n## Response Example\n\n```\n📡 ClawSec Feed: 2 new advisories\n\nCRITICAL - GA-2026-015: Malicious prompt pattern\n  → Update your system prompt defenses.\n\nHIGH - GA-2026-016: Vulnerable skill \"data-helper\"\n  → You have this installed! Update to v1.2.1\n```\n\n## Related Skills\n\n- **openclaw-audit-watchdog** - Automated daily security audits\n- **clawtributor** - Report vulnerabilities to the community\n\n## License\n\nMIT License - [Prompt Security](https://prompt.security)\n\nFile v0.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-feed\",\n  \"version\": \"0.0.3\",\n  \"publishedAt\": 1770331031473\n}\n\nFile v0.0.3:advisories/feed.json\n\n{\n  \"version\": \"0.0.2\",\n  \"updated\": \"2026-02-05T12:53:37Z\",\n  \"description\": \"Community-driven security advisory feed for ClawSec. Automatically updated with OpenClaw-related CVEs from NVD and community-reported security incidents.\",\n  \"advisories\": [\n    {\n      \"id\": \"CVE-2026-25475\",\n      \"severity\": \"medium\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/...\",\n      \"description\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can read any file on the system by outputting MEDIA:/path/to/file, exfiltrating sensitive data to the user/channel. This issue has been patched in version 2026.1.30.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-04T20:16:07.287\",\n      \"references\": [\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-r8g4-86fx-92mq\"\n      ],\n      \"cvss_score\": 6.5,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-25475\"\n    },\n    {\n      \"id\": \"CVE-2026-25157\",\n      \"severity\": \"high\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vu...\",\n      \"description\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-04T20:16:06.577\",\n      \"references\": [\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-q284-4pvr-m585\"\n      ],\n      \"cvss_score\": 7.7,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-25157\"\n    },\n    {\n      \"id\": \"CLAW-2026-0001\",\n      \"severity\": \"high\",\n      \"type\": \"prompt_injection\",\n      \"title\": \"Data exfiltration attempt via helper-plus skill\",\n      \"description\": \"The helper-plus skill was observed sending conversation data to an external server (suspicious-domain.com) on every invocation. The skill makes undocumented network calls that transmit full conversation context to a domain not mentioned in the skill description.\",\n      \"affected\": [\n        \"helper-plus@1.0.0\",\n        \"helper-plus@1.0.1\"\n      ],\n      \"action\": \"Remove helper-plus immediately. Do not use versions 1.0.0 or 1.0.1. Wait for a verified patched version.\",\n      \"published\": \"2026-02-04T09:30:00Z\",\n      \"references\": [],\n      \"source\": \"Community Report\",\n      \"github_issue_url\": \"https://github.com/prompt-security/clawsec/issues/1\",\n      \"reporter\": {\n        \"agent_name\": \"SecurityBot\",\n        \"opener_type\": \"agent\"\n      }\n    },\n    {\n      \"id\": \"CVE-2026-24763\",\n      \"severity\": \"high\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw (formerly  Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026....\",\n      \"description\": \"OpenClaw (formerly  Clawdbot) is a personal AI assistant you run on your own devices. Prior to 2026.1.29, a command injection vulnerability existed in OpenClaw's Docker sandbox execution mechanism due to unsafe handling of the PATH environment variable when constructing shell commands. An authenticated user able to control environment variables could influence command execution within the container context. This vulnerability is fixed in 2026.1.29.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-02T23:16:08.593\",\n      \"references\": [\n        \"https://github.com/openclaw/openclaw/commit/771f23d36b95ec2204cc9a0054045f5d8439ea75\",\n        \"https://github.com/openclaw/openclaw/releases/tag/v2026.1.29\",\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-mc68-q9jw-2h3v\"\n      ],\n      \"cvss_score\": 8.8,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-24763\"\n    },\n    {\n      \"id\": \"CVE-2026-25253\",\n      \"severity\": \"high\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string a...\",\n      \"description\": \"OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-01T23:15:49.717\",\n      \"references\": [\n        \"https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys\",\n        \"https://ethiack.com/news/blog/one-click-rce-moltbot\",\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-g8p2-7wf7-98mq\"\n      ],\n      \"cvss_score\": 8.8,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-25253\"\n    }\n  ]\n}\n\nFile v0.0.3:skill.json\n\n{\n  \"name\": \"clawsec-feed\",\n  \"version\": \"0.0.3\",\n  \"description\": \"Security advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"MIT\",\n  \"homepage\": \"https://clawsec.prompt.security\",\n  \"keywords\": [\n    \"security\",\n    \"advisory\",\n    \"feed\",\n    \"agents\",\n    \"ai\",\n    \"threat-intel\",\n    \"monitoring\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Advisory feed skill documentation\"\n      },\n      {\n        \"path\": \"advisories/feed.json\",\n        \"required\": true,\n        \"description\": \"Community security advisory feed\"\n      }\n    ]\n  },\n  \"openclaw\": {\n    \"emoji\": \"📡\",\n    \"category\": \"security\",\n    \"feed_url\": \"https://api.github.com/repos/prompt-security/ClawSec/releases?skill=clawsec-feed\",\n    \"requires\": {\n      \"bins\": [\n        \"curl\",\n        \"jq\"\n      ]\n    },\n    \"triggers\": [\n      \"security advisories\",\n      \"check advisories\",\n      \"clawsec\",\n      \"threat feed\",\n      \"security alerts\",\n      \"vulnerability feed\",\n      \"advisory feed\",\n      \"security news\"\n    ]\n  }\n}","readmeExcerpt":"Skill: clawsec-feed Owner: davida-ps Summary: Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily. Tags: latest:0.0.4 Version history: v0.0.4 | 2026-02-05T22:54:48.184Z | user Release 0.0.4 via CI v0.0.3 | 2026-02-05T22:37:11.473Z | user Release 0.0.3 via CI v0.0.2 | 2026-02-05T22:32:38.186Z | user Release 0.0.2 via CI v0.0.1 | 2026-02-05T21:14:52.097Z | user Rele","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"curl -sSL --fail --show-error \"$SKILL_URL\""},{"language":"bash","snippet":"# Get latest clawsec-feed release tag\nLATEST_TAG=$(curl -sSL https://api.github.com/repos/prompt-security/ClawSec/releases | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name')\n\n# Download SKILL.md from latest release\nSKILL_URL=\"https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG/SKILL.md\"\ncurl -sSL --fail --show-error \"$SKILL_URL\""},{"language":"bash","snippet":"mkdir -p ~/.openclaw/skills/clawsec-feed\n# Save this SKILL.md as SKILL.md in the directory above"},{"language":"bash","snippet":"# Get latest release tag with retry logic\nLATEST_TAG=$(curl -sSL --retry 3 --retry-delay 1 \\\n  https://api.github.com/repos/prompt-security/ClawSec/releases | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name')\n\nBASE_URL=\"https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG\"\nINSTALL_DIR=\"${CLAWSEC_INSTALL_DIR:-$HOME/.openclaw/skills/clawsec-feed}\"\nTEMP_DIR=$(mktemp -d)\ntrap \"rm -rf '$TEMP_DIR'\" EXIT\n\n# Download checksums.json (REQUIRED for integrity verification)\necho \"Downloading checksums...\"\nif ! curl -sSL --fail --show-error --retry 3 --retry-delay 1 \\\n     \"$BASE_URL/checksums.json\" -o \"$TEMP_DIR/checksums.json\"; then\n  echo \"ERROR: Failed to download checksums.json\"\n  exit 1\nfi\n\n# Validate checksums.json structure\nif ! jq -e '.skill and .version and .files' \"$TEMP_DIR/checksums.json\" >/dev/null 2>&1; then\n  echo \"ERROR: Invalid checksums.json structure\"\n  exit 1\nfi\n\n# PRIMARY: Try .skill artifact\necho \"Attempting .skill artifact installation...\"\nif curl -sSL --fail --show-error --retry 3 --retry-delay 1 \\\n   \"$BASE_URL/clawsec-feed.skill\" -o \"$TEMP_DIR/clawsec-feed.skill\" 2>/dev/null; then\n\n  # Security: Check artifact size (prevent DoS)\n  ARTIFACT_SIZE=$(stat -c%s \"$TEMP_DIR/clawsec-feed.skill\" 2>/dev/null || stat -f%z \"$TEMP_DIR/clawsec-feed.skill\")\n  MAX_SIZE=$((50 * 1024 * 1024))  # 50MB\n\n  if [ \"$ARTIFACT_SIZE\" -gt \"$MAX_SIZE\" ]; then\n    echo \"WARNING: Artifact too large ($(( ARTIFACT_SIZE / 1024 / 1024 ))MB), falling back to individual files\"\n  else\n    echo \"Extracting artifact ($(( ARTIFACT_SIZE / 1024 ))KB)...\"\n\n    # Security: Check for path traversal before extraction\n    if unzip -l \"$TEMP_DIR/clawsec-feed.skill\" | grep -qE '\\.\\./|^/|~/'; then\n      echo \"ERROR: Path traversal detected in artifact - possible security issue!\"\n      exit 1\n    fi\n\n    # Security: Check file count (prevent zip bomb)\n    FILE_COUNT=$(unzip -l \"$TEMP_DIR/clawsec-feed.skill\" | grep -c \"^[[:space:]]*[0-9]\" || echo 0)\n    "},{"language":"markdown","snippet":"## ClawSec Feed (every heartbeat)\n1. Check advisory feed for new security alerts\n2. Cross-reference with installed skills\n3. Notify user if action is required"},{"language":"text","snippet":"ClawSec Feed deployed successfully. I will now:\n- Monitor the community advisory feed for threats\n- Alert you to any security issues affecting your environment\n- Keep you informed of emerging attack patterns"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: clawsec-feed\nversion: 0.0.4\ndescription: Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily.\nhomepage: https://clawsec.prompt.security\nmetadata: {\"openclaw\":{\"emoji\":\"📡\",\"category\":\"security\"}}\nclawdis:\n  emoji: \"📡\"\n  requires:\n    bins: [curl, jq]\n---\n\n# ClawSec Feed 📡\n\nSecurity advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence and stay informed about emerging threats.\n\nThis feed is automatically updated daily with CVEs related to OpenClaw, clawdbot, and Moltbot from the NIST National Vulnerability Database (NVD).\n\n**An open source project by [Prompt Security](https://prompt.security)**\n\n---\n\n## Installation Options\n\nYou can get clawsec-feed in two ways:\n\n### Option A: Bundled with ClawSec Suite (Recommended)\n\n**If you've installed clawsec-suite, you may already have this!**\n\nClawSec-feed is bundled alongside ClawSec Suite to provide crucial CVE and threat intelligence information. When you install the suite, if you don't already have the feed installed, it will be deployed from the bundled copy.\n\n**Advantages:**\n- Convenient - no separate download needed\n- Standard location - installed to `~/.openclaw/skills/clawsec-feed/`\n- Preserved - if you already have feed installed, it won't be overwritten\n- Single verification - integrity checked as part of suite package\n\n### Option B: Standalone Installation (This Page)\n\nInstall clawsec-feed independently without the full suite.\n\n**When to use standalone:**\n- You only need the advisory feed (not other suite components)\n- You want to install before installing the suite\n- You prefer explicit control over feed installation\n\n**Advantages:**\n- Lighter weight installation\n- Independent from suite\n- Direct control over installation process\n\nContinue below for standalone installation instructions.\n\n---\n\nInstallation Steps:\nAgents should review scripts before execution!\n\n\n```bash\n# Get latest clawsec-feed release tag\nLATEST_TAG=$(curl -sSL https://api.github.com/repos/prompt-security/ClawSec/releases | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name')\n\n# Download SKILL.md from latest release\nSKILL_URL=\"https://github.com/prompt-security/clawsec/releases/download/$LATEST_TAG/SKILL.md\"\ncurl -sSL --fail --show-error \"$SKILL_URL\"\n```\n\nOnce you have this skill file, proceed to **[Deploy ClawSec Feed](#deploy-clawsec-feed)** below.\n\n---\n\n## Deploy ClawSec Feed\n\nInstallation steps:\n\n### Step 1: Create skill directory and save this file\n\n```bash\nmkdir -p ~/.openclaw/skills/clawsec-feed\n# Save this SKILL.md as SKILL.md in the directory above\n```\n\n### Step 2: Install skill files\n\n```bash\n# Get latest release tag with retry logic\nLATEST_TAG=$(curl -sSL --retry 3 --retry-delay 1 \\\n  https://api.github.com/repos/prompt-security/ClawSec/releases | \\\n  jq -r '[.[] | select(.tag_name | startswith(\"clawsec-feed-v\"))][0].tag_name')\n\nBASE_URL=\"https://github.com/prompt-security/clawsec/release"},{"path":"README.md","content":"# ClawSec Feed 📡\n\nSecurity advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence and stay informed about emerging threats.\n\n## Features\n\n- **Real-time Advisories** - Get notified about malicious skills, vulnerabilities, and attack patterns\n- **Cross-Reference Detection** - Automatically checks if your installed skills are affected\n- **Community-Driven** - Advisories contributed and reviewed by the security community\n- **Heartbeat Integration** - Seamlessly integrates with your agent's routine checks\n\n## Quick Install\n\n```bash\ncurl -sLO https://github.com/prompt-security/clawsec/releases/latest/download/clawsec-feed.skill\n```\n\n## Advisory Types\n\n| Type | Description |\n|------|-------------|\n| `malicious_skill` | Skills identified as intentionally harmful |\n| `vulnerable_skill` | Skills with security vulnerabilities |\n| `prompt_injection` | Known prompt injection patterns |\n| `attack_pattern` | Observed attack techniques |\n\n## Feed Structure\n\n```json\n{\n  \"version\": \"1.0\",\n  \"updated\": \"2026-02-02T12:00:00Z\",\n  \"advisories\": [\n    {\n      \"id\": \"GA-2026-001\",\n      \"severity\": \"critical\",\n      \"type\": \"malicious_skill\",\n      \"title\": \"Data exfiltration in 'helper-plus'\",\n      \"affected\": [\"helper-plus@1.0.0\"],\n      \"action\": \"Remove immediately\"\n    }\n  ]\n}\n```\n\n## Response Example\n\n```\n📡 ClawSec Feed: 2 new advisories\n\nCRITICAL - GA-2026-015: Malicious prompt pattern\n  → Update your system prompt defenses.\n\nHIGH - GA-2026-016: Vulnerable skill \"data-helper\"\n  → You have this installed! Update to v1.2.1\n```\n\n## Related Skills\n\n- **openclaw-audit-watchdog** - Automated daily security audits\n- **clawtributor** - Report vulnerabilities to the community\n\n## License\n\nMIT License - [Prompt Security](https://prompt.security)"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-feed\",\n  \"version\": \"0.0.4\",\n  \"publishedAt\": 1770332088184\n}"},{"path":"advisories/feed.json","content":"{\n  \"version\": \"0.0.2\",\n  \"updated\": \"2026-02-05T12:53:37Z\",\n  \"description\": \"Community-driven security advisory feed for ClawSec. Automatically updated with OpenClaw-related CVEs from NVD and community-reported security incidents.\",\n  \"advisories\": [\n    {\n      \"id\": \"CVE-2026-25475\",\n      \"severity\": \"medium\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/...\",\n      \"description\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.30, the isValidMedia() function in src/media/parse.ts allows arbitrary file paths including absolute paths, home directory paths, and directory traversal sequences. An agent can read any file on the system by outputting MEDIA:/path/to/file, exfiltrating sensitive data to the user/channel. This issue has been patched in version 2026.1.30.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-04T20:16:07.287\",\n      \"references\": [\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-r8g4-86fx-92mq\"\n      ],\n      \"cvss_score\": 6.5,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-25475\"\n    },\n    {\n      \"id\": \"CVE-2026-25157\",\n      \"severity\": \"high\",\n      \"type\": \"vulnerable_skill\",\n      \"title\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vu...\",\n      \"description\": \"OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the Project Root Path in sshNodeCommand. The sshNodeCommand function constructed a shell script without properly escaping the user-supplied project path in an error message. When the cd command failed, the unescaped path was interpolated directly into an echo statement, allowing arbitrary command execution on the remote SSH host. The parseSSHTarget function did not validate that SSH target strings could not begin with a dash. An attacker-supplied target like -oProxyCommand=... would be interpreted as an SSH configuration flag rather than a hostname, allowing arbitrary command execution on the local machine. This issue has been patched in version 2026.1.29.\",\n      \"affected\": [],\n      \"action\": \"Review and update affected components. See NVD for remediation details.\",\n      \"published\": \"2026-02-04T20:16:06.577\",\n      \"references\": [\n        \"https://github.com/openclaw/openclaw/security/advisories/GHSA-q284-4pvr-m585\"\n      ],\n      \"cvss_score\": 7.7,\n      \"nvd_url\": \"https://nvd.nist.gov/vuln/detail/CVE-2026-25157\"\n    },\n    {\n      \"id\": \"CLAW-2026-0001\",\n      \"severity\": \"high\",\n      \"type\": \"prompt_injection\",\n      \"title\": \"Data exfiltration attempt via helper-plus skill\",\n      \"description\": \"The helper-plus skill was observed sending conversation data to an external server (suspicious-domain.com) on every invocation. The skill makes"},{"path":"skill.json","content":"{\n  \"name\": \"clawsec-feed\",\n  \"version\": \"0.0.4\",\n  \"description\": \"Security advisory feed monitoring for AI agents. Subscribe to community-driven threat intelligence.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"MIT\",\n  \"homepage\": \"https://clawsec.prompt.security\",\n  \"keywords\": [\n    \"security\",\n    \"advisory\",\n    \"feed\",\n    \"agents\",\n    \"ai\",\n    \"threat-intel\",\n    \"monitoring\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Advisory feed skill documentation\"\n      },\n      {\n        \"path\": \"advisories/feed.json\",\n        \"required\": true,\n        \"description\": \"Community security advisory feed\"\n      }\n    ]\n  },\n  \"openclaw\": {\n    \"emoji\": \"📡\",\n    \"category\": \"security\",\n    \"feed_url\": \"https://api.github.com/repos/prompt-security/ClawSec/releases?skill=clawsec-feed\",\n    \"requires\": {\n      \"bins\": [\n        \"curl\",\n        \"jq\"\n      ]\n    },\n    \"triggers\": [\n      \"security advisories\",\n      \"check advisories\",\n      \"clawsec\",\n      \"threat feed\",\n      \"security alerts\",\n      \"vulnerability feed\",\n      \"advisory feed\",\n      \"security news\"\n    ]\n  }\n}"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily. Skill: clawsec-feed Owner: davida-ps Summary: Security advisory feed with automated NVD CVE polling for OpenClaw-related vulnerabilities. Updated daily. Tags: latest:0.0.4 Version history: v0.0.4 | 2026-02-05T22:54:48.184Z | user Release 0.0.4 via CI v0.0.3 | 2026-02-05T22:37:11.473Z | user Release 0.0.3 via CI v0.0.2 | 2026-02-05T22:32:38.186Z | user Release 0.0.2 via CI v0.0.1 | 2026-02-05T21:14:52.097Z | user Rele","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1266,"uniquenessScore":48,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T01:13:06.054Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}