{"id":"3b9216cc-4108-4caf-9b86-0a0418587735","entityType":"agent","slug":"clawhub-davida-ps-clawsec-scanner","name":"clawsec-scanner","canonicalUrl":"https://www.xpersona.co/agent/clawhub-davida-ps-clawsec-scanner","canonicalPath":"/agent/clawhub-davida-ps-clawsec-scanner","generatedAt":"2026-10-11T07:35:34.373Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T04:55:30.279Z","emptyReason":null},"description":"Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisor... Skill: clawsec-scanner Owner: davida-ps Summary: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisor... Tags: latest:0.0.7 Version history: v0.0.7 | 2026-06-23T08:26:16.764Z | user Release 0.0.7 via CI v0.0.5 | 2026-06-10T14:59:33.346Z | user Release 0.0.5 via CI v0.0.4 | 2026-06-07T10:07:44.927Z | user Release 0","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17ewxqmthh68xc4bv5vc6f30183jsf1:clawsec-scanner","sourceUrl":"https://clawhub.ai/davida-ps/clawsec-scanner","homepage":"https://clawhub.ai/davida-ps/skills/clawsec-scanner","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/davida-ps/clawsec-scanner","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/davida-ps/skills/clawsec-scanner","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisor..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T04:55:30.279Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T04:55:30.279Z","emptyReason":null},"stars":null,"forks":null,"downloads":1154,"packageName":null,"latestVersion":"0.0.7","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T04:55:30.204Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T04:55:30.279Z","lastCrawledAt":"2026-10-11T04:55:30.204Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T04:55:30.204Z","lastVerifiedAt":null,"highlights":[{"version":"0.0.7","createdAt":"2026-06-23T08:26:16.764Z","changelog":"Release 0.0.7 via CI","fileCount":24,"zipByteSize":57240},{"version":"0.0.5","createdAt":"2026-06-10T14:59:33.346Z","changelog":"Release 0.0.5 via CI","fileCount":24,"zipByteSize":57161},{"version":"0.0.4","createdAt":"2026-06-07T10:07:44.927Z","changelog":"Release 0.0.4 via CI","fileCount":23,"zipByteSize":56754},{"version":"0.0.3","createdAt":"2026-05-14T11:43:02.259Z","changelog":"Release 0.0.3 via CI","fileCount":23,"zipByteSize":57903},{"version":"0.0.2","createdAt":"2026-03-10T17:29:03.416Z","changelog":"Release 0.0.2 via CI","fileCount":22,"zipByteSize":56476},{"version":"0.0.1","createdAt":"2026-03-09T19:18:14.826Z","changelog":"Release 0.0.1 via CI","fileCount":20,"zipByteSize":49445}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17ewxqmthh68xc4bv5vc6f30183jsf1:clawsec-scanner","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T07:35:34.367Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-davida-ps-clawsec-scanner/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T04:55:30.279Z","emptyReason":null},"readme":"Skill: clawsec-scanner\n\nOwner: davida-ps\n\nSummary: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisor...\n\nTags: latest:0.0.7\n\nVersion history:\n\nv0.0.7 | 2026-06-23T08:26:16.764Z | user\n\nRelease 0.0.7 via CI\n\nv0.0.5 | 2026-06-10T14:59:33.346Z | user\n\nRelease 0.0.5 via CI\n\nv0.0.4 | 2026-06-07T10:07:44.927Z | user\n\nRelease 0.0.4 via CI\n\nv0.0.3 | 2026-05-14T11:43:02.259Z | user\n\nRelease 0.0.3 via CI\n\nv0.0.2 | 2026-03-10T17:29:03.416Z | user\n\nRelease 0.0.2 via CI\n\nv0.0.1 | 2026-03-09T19:18:14.826Z | user\n\nRelease 0.0.1 via CI\n\nArchive index:\n\nArchive v0.0.7: 24 files, 57240 bytes\n\nFiles: CHANGELOG.md (2189b), hooks/clawsec-scanner-hook/handler.ts (9535b), hooks/clawsec-scanner-hook/HOOK.md (3676b), lib/report.mjs (8204b), lib/types.ts (923b), lib/utils.mjs (3568b), README.md (451b), scripts/dast_hook_executor.mjs (3809b), scripts/dast_runner.mjs (15455b), scripts/query_cve_databases.mjs (8892b), scripts/runner.sh (9574b), scripts/sast_analyzer.mjs (8621b), scripts/scan_dependencies.mjs (10147b), scripts/setup_scanner_hook.mjs (3770b), skill-card.md (2654b), skill.json (3662b), SKILL.md (16498b), test/cve_integration.test.mjs (18916b), test/dast_harness.test.mjs (10309b), test/dependency_scanner.test.mjs (18770b), test/lib/test_harness.mjs (2426b), test/reviewer_regressions.test.mjs (7614b), test/sast_engine.test.mjs (17894b), _meta.json (134b)\n\nFile v0.0.7:SKILL.md\n\n---\nname: clawsec-scanner\nversion: 0.0.7\ndescription: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\nhomepage: https://clawsec.prompt.security\nclawdis:\n  emoji: \"🔍\"\n  requires:\n    bins: [node, npm, python3, pip-audit, semgrep, bandit, jq, curl]\n---\n\n# ClawSec Scanner\n\nComprehensive security scanner for agent platforms that automates vulnerability detection across multiple dimensions:\n\n- **Dependency Scanning**: Analyzes npm and Python dependencies using `npm audit` and `pip-audit` with structured JSON output parsing\n- **CVE Database Integration**: Queries OSV (primary), NVD 2.0, and GitHub Advisory Database for vulnerability enrichment\n- **SAST Analysis**: Static code analysis using Semgrep (JavaScript/TypeScript) and Bandit (Python) to detect hardcoded secrets, command injection, path traversal, and unsafe deserialization\n- **DAST Framework**: Agent-specific static analysis of OpenClaw hook metadata and handler source without importing or invoking target code\n- **Unified Reporting**: Consolidated vulnerability reports with severity classification and remediation guidance\n- **Continuous Monitoring**: OpenClaw hook integration for automated periodic scanning\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-scanner -a openclaw -y\n```\n\n## Features\n\n### Multi-Engine Scanning\n\nThe scanner orchestrates four complementary scan types to provide comprehensive vulnerability coverage:\n\n1. **Dependency Scanning**\n   - Executes `npm audit --json` and `pip-audit -f json` as subprocesses\n   - Parses structured output to extract CVE IDs, severity, affected versions\n   - Handles edge cases: missing package-lock.json, zero vulnerabilities, malformed JSON\n\n2. **CVE Database Queries**\n   - **OSV API** (primary): Free, no authentication, broad ecosystem support (npm, PyPI, Go, Maven)\n   - **NVD 2.0** (optional): Requires API key to avoid 6-second rate limiting\n   - **GitHub Advisory Database** (optional): GraphQL API with OAuth token\n   - Normalizes all API responses to unified `Vulnerability` schema\n\n3. **Static Analysis (SAST)**\n   - **Semgrep** for JavaScript/TypeScript: Detects security issues using `--config auto` or `--config p/security-audit`\n   - **Bandit** for Python: Leverages existing `pyproject.toml` configuration\n   - Identifies: hardcoded secrets (API keys, tokens), command injection (`eval`, `exec`), path traversal, unsafe deserialization\n\n4. **Dynamic Analysis (DAST)**\n   - Static hook inspection for OpenClaw hook handlers discovered from `HOOK.md` metadata\n   - Verifies coverage and source-level risk signals without importing, transpiling, or invoking target handlers\n   - Note: Traditional web DAST tools (ZAP, Burp) do not apply to agent platforms - this provides agent-specific testing\n\n### Unified Reporting\n\nAll scan types emit a consistent `ScanReport` JSON schema:\n\n```typescript\n{\n  scan_id: string;         // UUID\n  timestamp: string;       // ISO 8601\n  target: string;          // Scanned path\n  vulnerabilities: Vulnerability[];\n  summary: {\n    critical: number;\n    high: number;\n    medium: number;\n    low: number;\n    info: number;\n  }\n}\n```\n\nEach `Vulnerability` object includes:\n- `id`: CVE-2023-12345 or GHSA-xxxx-yyyy-zzzz\n- `source`: npm-audit | pip-audit | osv | nvd | github | sast | dast\n- `severity`: critical | high | medium | low | info\n- `package`: Package name (or 'N/A' for SAST/DAST)\n- `version`: Affected version\n- `fixed_version`: First version with fix (if available)\n- `title`: Short description\n- `description`: Full advisory text\n- `references`: URLs for more info\n- `discovered_at`: ISO 8601 timestamp\n\n### OpenClaw Integration\n\nAutomated continuous monitoring via hook:\n\n- Runs scanner on configurable interval (default: 86400s / 24 hours)\n- Triggers on `agent:bootstrap` and `command:new` events\n- Posts findings to `event.messages` array with severity summary\n- Rate-limited by `CLAWSEC_SCANNER_INTERVAL` environment variable\n\n## Installation\n\n### Prerequisites\n\nVerify required binaries are available:\n\n```bash\n# Core runtimes\nnode --version  # v20+\nnpm --version\npython3 --version  # 3.10+\n\n# Scanning tools\npip-audit --version  # Install: uv pip install pip-audit\nsemgrep --version    # Install: pip install semgrep OR brew install semgrep\nbandit --version     # Install: uv pip install bandit\n\n# Utilities\njq --version\ncurl --version\n```\n\n### Option A: Via clawhub (recommended)\n\n```bash\nnpx clawhub@latest install clawsec-scanner\n```\n\n### Option B: Manual installation with verification\n\n```bash\nset -euo pipefail\n\nVERSION=\"${SKILL_VERSION:?Set SKILL_VERSION (e.g. 0.1.0)}\"\nINSTALL_ROOT=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}\"\nDEST=\"$INSTALL_ROOT/clawsec-scanner\"\nBASE=\"https://github.com/prompt-security/clawsec/releases/download/clawsec-scanner-v${VERSION}\"\n\nTEMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TEMP_DIR\"' EXIT\n\n# Pinned release-signing public key\n# Fingerprint (SHA-256 of SPKI DER): 711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\ncat > \"$TEMP_DIR/release-signing-public.pem\" <<'PEM'\n-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEAS7nijfMcUoOBCj4yOXJX+GYGv2pFl2Yaha1P4v5Cm6A=\n-----END PUBLIC KEY-----\nPEM\n\nZIP_NAME=\"clawsec-scanner-v${VERSION}.zip\"\n\n# Download release archive + signed checksums\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TEMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TEMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TEMP_DIR/checksums.sig\"\n\n# Verify checksums manifest signature\nopenssl base64 -d -A -in \"$TEMP_DIR/checksums.sig\" -out \"$TEMP_DIR/checksums.sig.bin\"\nif ! openssl pkeyutl -verify \\\n  -pubin \\\n  -inkey \"$TEMP_DIR/release-signing-public.pem\" \\\n  -sigfile \"$TEMP_DIR/checksums.sig.bin\" \\\n  -rawin \\\n  -in \"$TEMP_DIR/checksums.json\" >/dev/null 2>&1; then\n  echo \"ERROR: checksums.json signature verification failed\" >&2\n  exit 1\nfi\n\nEXPECTED_SHA=\"$(jq -r '.archive.sha256 // empty' \"$TEMP_DIR/checksums.json\")\"\nif [ -z \"$EXPECTED_SHA\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\n\nACTUAL_SHA=\"$(shasum -a 256 \"$TEMP_DIR/$ZIP_NAME\" | awk '{print $1}')\"\nif [ \"$EXPECTED_SHA\" != \"$ACTUAL_SHA\" ]; then\n  echo \"ERROR: Archive checksum mismatch\" >&2\n  exit 1\nfi\n\necho \"Checksums verified. Installing...\"\n\nmkdir -p \"$INSTALL_ROOT\"\nrm -rf \"$DEST\"\nunzip -q \"$TEMP_DIR/$ZIP_NAME\" -d \"$INSTALL_ROOT\"\n\nchmod 600 \"$DEST/skill.json\"\nfind \"$DEST\" -type f ! -name \"skill.json\" -exec chmod 644 {} \\;\n\necho \"Installed clawsec-scanner v${VERSION} to: $DEST\"\necho \"Next step: Run a scan or set up continuous monitoring\"\n```\n\n## Usage\n\n### On-Demand CLI Scanning\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\n\n# Scan all skills with JSON output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./skills/ --output report.json --format json\n\n# Scan specific directory with human-readable output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./my-skill/ --format text\n\n# Check available flags\n\"$SCANNER_DIR/scripts/runner.sh\" --help\n```\n\n**CLI Flags:**\n- `--target <path>`: Directory to scan (required)\n- `--output <file>`: Write results to file (optional, defaults to stdout)\n- `--format <json|text>`: Output format (default: json)\n- `--check`: Verify all required binaries are installed\n\n### OpenClaw Hook Setup (Continuous Monitoring)\n\nEnable automated periodic scanning:\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\nnode \"$SCANNER_DIR/scripts/setup_scanner_hook.mjs\"\n```\n\nThis creates a hook that:\n- Scans on `agent:bootstrap` and `command:new` events\n- Respects `CLAWSEC_SCANNER_INTERVAL` rate limiting (default: 86400 seconds / 24 hours)\n- Posts findings to conversation with severity summary\n- Recommends remediation for high/critical vulnerabilities\n\nRestart the OpenClaw gateway after enabling the hook, then run `/new` to trigger an immediate scan.\n\n### Environment Variables\n\n```bash\n# Optional - NVD API key to avoid rate limiting (6-second delays without key)\nexport CLAWSEC_NVD_API_KEY=\"your-nvd-api-key\"\n\n# Optional - GitHub OAuth token for Advisory Database queries\nexport GITHUB_TOKEN=\"ghp_your_token_here\"\n\n# Optional - Scanner hook interval in seconds (default: 86400 / 24 hours)\nexport CLAWSEC_SCANNER_INTERVAL=\"86400\"\n\n# Optional - Allow unsigned advisory feed during development (from clawsec-suite)\nexport CLAWSEC_ALLOW_UNSIGNED_FEED=\"1\"\n```\n\n## Architecture\n\n### Modular Design\n\nEach scan type is an independent module that can run standalone or as part of unified scan:\n\n```\nscripts/runner.sh              # Orchestration layer\n├── scan_dependencies.mjs      # npm audit + pip-audit\n├── query_cve_databases.mjs    # OSV/NVD/GitHub API queries\n├── sast_analyzer.mjs          # Semgrep + Bandit static analysis\n├── dast_runner.mjs            # Static hook inspection orchestration\n└── dast_hook_executor.mjs     # Static hook source inspection helper\n\nlib/\n├── report.mjs                 # Result aggregation and formatting\n├── utils.mjs                  # Subprocess exec, JSON parsing, error handling\n└── types.ts                   # TypeScript schema definitions\n\nhooks/clawsec-scanner-hook/\n├── HOOK.md                    # OpenClaw hook metadata\n└── handler.ts                 # Periodic scan trigger\n```\n\n### Fail-Open Philosophy\n\nThe scanner prioritizes availability over strict failure propagation:\n\n- Network failures → emit partial results, log warnings\n- Missing tools → skip that scan type, continue with others\n- Malformed JSON → parse what's valid, log errors\n- API rate limits → implement exponential backoff, fallback to other sources\n- Zero vulnerabilities → emit success report with empty array\n\n**Critical failures** that exit immediately:\n- Target path does not exist\n- No scanning tools available (all bins missing)\n- Concurrent scan detected (lockfile present)\n\n### Subprocess Execution Pattern\n\nAll external tools run as subprocesses with structured JSON output:\n\n```javascript\nimport { spawn } from 'node:child_process';\n\n// Example: npm audit execution\nconst proc = spawn('npm', ['audit', '--json'], {\n  cwd: targetPath,\n  stdio: ['ignore', 'pipe', 'pipe']\n});\n\n// Handle non-zero exit codes gracefully\n// npm audit exits 1 when vulnerabilities found (not an error!)\nproc.on('close', code => {\n  if (code !== 0 && stderr.includes('ERR!')) {\n    // Actual error\n    reject(new Error(stderr));\n  } else {\n    // Vulnerabilities found or success\n    resolve(JSON.parse(stdout));\n  }\n});\n```\n\n## Troubleshooting\n\n### Common Issues\n\n**\"Missing package-lock.json\" warning**\n- `npm audit` requires lockfile to run\n- Run `npm install` in target directory to generate\n- Scanner continues with other scan types if npm audit fails\n\n**\"NVD API rate limit exceeded\"**\n- Set `CLAWSEC_NVD_API_KEY` environment variable\n- Without API key: 6-second delays enforced between requests\n- OSV API used as primary source (no rate limits)\n\n**\"pip-audit not found\"**\n- Install: `uv pip install pip-audit` or `pip install pip-audit`\n- Verify: `which pip-audit`\n- Add to PATH if installed in non-standard location\n\n**\"Semgrep binary missing\"**\n- Install: `pip install semgrep` OR `brew install semgrep`\n- Requires Python 3.8+ runtime\n- Alternative: use Docker image `returntocorp/semgrep`\n\n**\"DAST static coverage finding\"**\n- The DAST harness does not execute target hook handlers.\n- JavaScript and TypeScript hook files are read as source and reported with `info`-level static coverage findings.\n- Review any listed static signals manually when deciding whether a hook needs deeper sandboxed testing.\n\n**\"Concurrent scan detected\"**\n- Lockfile exists: `/tmp/clawsec-scanner.lock`\n- Wait for running scan to complete or manually remove lockfile\n- Prevents overlapping scans that could produce inconsistent results\n\n### Verification\n\nCheck scanner is working correctly:\n\n```bash\n# Verify required binaries\n./scripts/runner.sh --check\n\n# Run unit tests\nnode test/dependency_scanner.test.mjs\nnode test/cve_integration.test.mjs\nnode test/sast_engine.test.mjs\nnode test/dast_harness.test.mjs\n\n# Validate skill structure\npython ../../utils/validate_skill.py .\n\n# Scan test fixtures (should detect known vulnerabilities)\n./scripts/runner.sh --target test/fixtures/ --format text\n```\n\n## Development\n\n### Running Tests\n\n```bash\n# All tests (vanilla Node.js, no framework)\nfor test in test/*.test.mjs; do\n  node \"$test\" || exit 1\ndone\n\n# Individual test suites\nnode test/dependency_scanner.test.mjs  # Dependency scanning\nnode test/cve_integration.test.mjs     # CVE database APIs\nnode test/sast_engine.test.mjs         # Static analysis\nnode test/dast_harness.test.mjs        # DAST static hook inspection\n```\n\n### Linting\n\n```bash\n# JavaScript/TypeScript\nnpx eslint . --ext .ts,.tsx,.js,.jsx,.mjs --max-warnings 0\n\n# Python (Bandit already configured in pyproject.toml)\nruff check .\nbandit -r . -ll\n\n# Shell scripts\nshellcheck scripts/*.sh\n```\n\n### Adding Custom Semgrep Rules\n\nCreate custom rules in `.semgrep/rules/`:\n\n```yaml\nrules:\n  - id: custom-security-rule\n    pattern: dangerous_function($ARG)\n    message: Avoid dangerous_function - use safe_alternative instead\n    severity: WARNING\n    languages: [javascript, typescript]\n```\n\nUpdate `scripts/sast_analyzer.mjs` to include custom rules:\n\n```javascript\nconst proc = spawn('semgrep', [\n  'scan',\n  '--config', 'auto',\n  '--config', '.semgrep/rules/',  // Add custom rules\n  '--json',\n  targetPath\n]);\n```\n\n## Integration with ClawSec Suite\n\nThe scanner works standalone or as part of the ClawSec ecosystem:\n\n- **clawsec-suite**: Meta-skill that can install and manage clawsec-scanner\n- **clawsec-feed**: Advisory feed for malicious skill detection (complementary)\n- **openclaw-audit-watchdog**: Cron-based audit automation (similar pattern)\n\nInstall the full ClawSec suite:\n\n```bash\nnpx clawhub@latest install clawsec-suite\n# Then use clawsec-suite to discover and install clawsec-scanner\n```\n\n## Security Considerations\n\n### Scanner Security\n\n- No hardcoded secrets in scanner code\n- API keys read from environment variables only (never logged or committed)\n- Subprocess arguments use arrays to prevent shell injection\n- All external tool output parsed with try/catch error handling\n\n### Vulnerability Prioritization\n\n**Critical/High severity findings** should be addressed immediately:\n- Known exploits in dependencies (CVSS 9.0+)\n- Hardcoded API keys or credentials in code\n- Command injection vulnerabilities\n- Path traversal without validation\n\n**Medium/Low severity findings** can be addressed in normal sprint cycles:\n- Outdated dependencies without known exploits\n- Missing security headers\n- Weak cryptography usage\n\n**Info findings** are advisory only:\n- Deprecated API usage\n- Code quality issues flagged by linters\n\n## Roadmap\n\n### v0.0.4 (Current)\n- [x] Dependency scanning (npm audit, pip-audit)\n- [x] CVE database integration (OSV, NVD, GitHub Advisory)\n- [x] SAST analysis (Semgrep, Bandit)\n- [x] Static OpenClaw hook inspection for DAST without target code execution\n- [x] Unified JSON reporting\n- [x] OpenClaw hook integration\n\n### Future Enhancements\n- [ ] Automatic remediation (dependency upgrades, code fixes)\n- [ ] SARIF output format for GitHub Code Scanning integration\n- [ ] Web dashboard for vulnerability tracking over time\n- [ ] CI/CD GitHub Action for PR blocking on high-severity findings\n- [ ] Container image scanning (Docker, OCI)\n- [ ] Infrastructure-as-Code scanning (Terraform, CloudFormation)\n- [ ] Comprehensive agent workflow DAST (requires deeper platform integration)\n\n## Contributing\n\nFound a security issue? Please report privately to security@prompt.security.\n\nFor feature requests and bug reports, open an issue at:\nhttps://github.com/prompt-security/clawsec/issues\n\n## License\n\nAGPL-3.0-or-later\n\nSee LICENSE file in repository root for full text.\n\n## Resources\n\n- **ClawSec Homepage**: https://clawsec.prompt.security\n- **Documentation**: https://clawsec.prompt.security/scanner\n- **GitHub Repository**: https://github.com/prompt-security/clawsec\n- **OSV API Docs**: https://osv.dev/docs/\n- **NVD API Docs**: https://nvd.nist.gov/developers/vulnerabilities\n- **Semgrep Registry**: https://semgrep.dev/explore\n- **Bandit Documentation**: https://bandit.readthedocs.io/\n\nFile v0.0.7:README.md\n\n# Clawsec Scanner\n\nAutomated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-scanner -a openclaw -y\n```\n\nFile v0.0.7:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-scanner\",\n  \"version\": \"0.0.7\",\n  \"publishedAt\": 1782203176764\n}\n\nFile v0.0.7:CHANGELOG.md\n\n# Changelog\n\n## [0.0.7] - 2026-06-23\n\n### Changed\n\n- Re-released skill metadata to run through the corrected normal tag publish pipeline without runtime changes.\n\n## [0.0.6] - 2026-06-22\n\n### Changed\n\n- Re-released skill metadata to publish through the updated ClawHub pipeline without runtime changes.\n\n## [0.0.5] - 2026-06-10\n\n### Changed\n\n- Re-released skill package with updated marketplace grouping and signed release trust artifacts for Vercel-compatible skill installation.\n\n## [0.0.4] - 2026-06-07\n\n### Security\n- Replaced DAST target hook execution with static hook source inspection so scanner runs never import, transpile, or invoke untrusted handler code.\n\n## [0.0.3] - 2026-05-13\n\n### Changed\n- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.\n\nAll notable changes to the ClawSec Scanner will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.0.2] - 2026-03-10\n\n### Changed\n\n- Replaced simulated DAST checks with real OpenClaw hook execution harness testing\n- Updated DAST semantics so high-severity findings are emitted for actual hook execution failures/timeouts, not static payload pattern matches\n- Reclassified DAST harness capability limitations (for example missing TypeScript compiler for `.ts` hooks) to `info` coverage findings instead of high severity\n- Added DAST harness mode guard to prevent recursive scanner execution when hook handlers are tested in isolation\n\n### Added\n\n- New DAST helper executor script for isolated per-hook execution and timeout enforcement\n- DAST harness regression tests covering no-false-positive baseline and malicious-input crash detection\n\n## [0.0.1] - 2026-02-27\n\n### Added\n\n- Initial release of ClawSec Scanner skill\n- Automated vulnerability scanning for OpenClaw skill installations\n- Integration with advisory feed for real-time security alerts\n- Support for scanning skill dependencies and detecting known CVEs\n- Configurable scan policies and risk thresholds\n- Detailed vulnerability reporting with remediation guidance\n\nFile v0.0.7:hooks/clawsec-scanner-hook/HOOK.md\n\n---\nname: clawsec-scanner-hook\ndescription: Periodic vulnerability scanning for installed skills and dependencies with configurable scan intervals.\nmetadata: { \"openclaw\": { \"events\": [\"agent:bootstrap\", \"command:new\"] } }\n---\n\n# ClawSec Scanner Hook\n\nThis hook performs comprehensive vulnerability scanning on installed skills and their dependencies on:\n\n- `agent:bootstrap`\n- `command:new`\n\nWhen triggered, it runs all configured scanning engines (dependency scan, SAST, DAST, CVE database lookup) and posts findings as conversation messages. Scans are rate-limited by configurable interval to avoid performance impact.\n\n## Scanning Capabilities\n\nThe hook orchestrates four independent scanning engines:\n\n1. **Dependency Scanning**: Executes `npm audit` and `pip-audit` to detect known vulnerabilities in JavaScript and Python dependencies\n2. **SAST (Static Analysis)**: Runs Semgrep (JS/TS) and Bandit (Python) to detect security issues like hardcoded secrets, command injection, and path traversal\n3. **CVE Database Lookup**: Queries OSV API (primary), NVD 2.0 (optional), and GitHub Advisory Database (optional) for vulnerability enrichment\n4. **DAST (Dynamic Analysis)**: Executes real OpenClaw hook handlers in an isolated harness and tests malicious-input resilience, timeout behavior, output bounds, and event mutation safety\n\n## Safety Contract\n\n- The hook does not modify or delete skills.\n- It only reports findings and provides remediation guidance.\n- Scanning is non-blocking and runs on a configurable interval (default 24 hours).\n- Failed scans (network errors, missing tools) produce warnings but do not block execution.\n- Findings are deduplicated to avoid alert fatigue.\n\n## Optional Environment Variables\n\n### Core Configuration\n\n- `CLAWSEC_SCANNER_INTERVAL`: Minimum interval between hook scans in seconds (default `86400` / 24 hours).\n- `CLAWSEC_SCANNER_TARGET`: Override default scan target path (default: installed skills root).\n- `CLAWSEC_SCANNER_STATE_FILE`: Override state file path for deduplication (default `~/.openclaw/clawsec-scanner-state.json`).\n- `CLAWSEC_INSTALL_ROOT`: Override installed skills root directory.\n\n### CVE Database Integration\n\n- `CLAWSEC_NVD_API_KEY`: NVD API key for rate-limit-free access (without this, 6-second delays apply).\n- `GITHUB_TOKEN`: GitHub OAuth token for GitHub Advisory Database queries (optional enhancement).\n\n### Selective Scanning\n\n- `CLAWSEC_SKIP_DEPENDENCY_SCAN`: Set to `1` to disable dependency scanning (npm audit, pip-audit).\n- `CLAWSEC_SKIP_SAST`: Set to `1` to disable static analysis (Semgrep, Bandit).\n- `CLAWSEC_SKIP_DAST`: Set to `1` to disable dynamic analysis (hook security tests).\n- `CLAWSEC_SKIP_CVE_LOOKUP`: Set to `1` to disable CVE database enrichment.\n\n### Advanced Options\n\n- `CLAWSEC_SCANNER_TIMEOUT`: Maximum scan duration in seconds before timeout (default `300` / 5 minutes).\n- `CLAWSEC_SCANNER_FORMAT`: Output format for findings (`json` or `text`, default `text`).\n- `CLAWSEC_SCANNER_MIN_SEVERITY`: Minimum severity to report (`critical`, `high`, `medium`, `low`, `info`, default `medium`).\n- `CLAWSEC_SCANNER_OUTPUT_FILE`: Optional path to write full scan report JSON (default: conversation only).\n\n## Required Binaries\n\nThe hook requires the following binaries to be available on `PATH`:\n\n- `node` (20+) - JavaScript runtime\n- `npm` - For npm audit execution\n- `python3` (3.10+) - Python runtime\n- `pip-audit` - Python dependency scanner\n- `semgrep` - JavaScript/TypeScript static analysis\n- `bandit` - Python static analysis\n- `jq` - JSON parsing and merging\n- `curl` - API requests (fallback)\n\nMissing binaries will be logged as warnings; available tools will still run.\n\nFile v0.0.7:skill-card.md\n\n## Description:\n\nAutomated vulnerability scanner for agent platforms that performs dependency scanning, multi-database CVE lookup, SAST analysis, and agent-specific static hook inspection for OpenClaw hooks.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[davida-ps](https://clawhub.ai/user/davida-ps)\n\n### License/Terms of Use:\n\nAGPL-3.0-or-later\n\n## Use Case:\n\nDevelopers and security engineers use this skill to scan agent skill directories and OpenClaw installations for dependency vulnerabilities, CVE context, SAST findings, and hook inspection results.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The continuous hook can inject untrusted scan findings as system-level messages.\n\nMitigation: Review hook behavior before installation and keep continuous hook mode disabled until system-role reporting is fixed.\n\nRisk: A broad scan target can expose more local skill or dependency content than intended.\n\nMitigation: Set CLAWSEC_SCANNER_TARGET to the narrow directory that should be scanned.\n\nRisk: Some stated security coverage does not match the code behavior.\n\nMitigation: Treat DAST results as static inspection rather than runtime validation and review listed static signals manually.\n\nRisk: Unpinned or unsigned installation paths increase supply-chain review burden.\n\nMitigation: Prefer the signed manual installation path or exact pinned package versions.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/davida-ps/skills/clawsec-scanner)\n- [ClawSec Homepage](https://clawsec.prompt.security)\n- [ClawSec Scanner Documentation](https://clawsec.prompt.security/scanner)\n- [OSV API Documentation](https://osv.dev/docs/)\n- [NVD Vulnerabilities API](https://nvd.nist.gov/developers/vulnerabilities)\n- [Semgrep Registry](https://semgrep.dev/explore)\n- [Bandit Documentation](https://bandit.readthedocs.io/)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with JSON or text scan reports and shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can write JSON report files when configured; continuous hook mode can add severity summaries to conversation messages.]\n\n## Skill Version(s):\n\n0.0.7 (source: frontmatter, skill.json, changelog released 2026-06-23, evidence release)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.0.7:skill.json\n\n{\n  \"name\": \"clawsec-scanner\",\n  \"version\": \"0.0.7\",\n  \"description\": \"Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"keywords\": [\n    \"security\",\n    \"vulnerability\",\n    \"scanner\",\n    \"dependency\",\n    \"cve\",\n    \"sast\",\n    \"dast\",\n    \"audit\",\n    \"agents\",\n    \"ai\",\n    \"openclaw\",\n    \"semgrep\",\n    \"bandit\",\n    \"osv\",\n    \"nvd\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Scanner skill documentation and usage guide\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and feature changelog\"\n      },\n      {\n        \"path\": \"scripts/runner.sh\",\n        \"required\": true,\n        \"description\": \"Main orchestration script for running all scanner engines\"\n      },\n      {\n        \"path\": \"scripts/scan_dependencies.mjs\",\n        \"required\": true,\n        \"description\": \"Dependency scanner using npm audit and pip-audit with JSON parsing\"\n      },\n      {\n        \"path\": \"scripts/query_cve_databases.mjs\",\n        \"required\": true,\n        \"description\": \"Multi-database CVE lookup (OSV primary, NVD/GitHub fallback)\"\n      },\n      {\n        \"path\": \"scripts/sast_analyzer.mjs\",\n        \"required\": true,\n        \"description\": \"Static analysis engine running Semgrep and Bandit as subprocesses\"\n      },\n      {\n        \"path\": \"scripts/dast_runner.mjs\",\n        \"required\": true,\n        \"description\": \"Static OpenClaw hook inspection harness that does not execute target handlers\"\n      },\n      {\n        \"path\": \"scripts/dast_hook_executor.mjs\",\n        \"required\": true,\n        \"description\": \"Static hook source inspection helper used by DAST without importing target handlers\"\n      },\n      {\n        \"path\": \"scripts/setup_scanner_hook.mjs\",\n        \"required\": false,\n        \"description\": \"Hook installer for continuous monitoring integration\"\n      },\n      {\n        \"path\": \"lib/report.mjs\",\n        \"required\": true,\n        \"description\": \"Unified vulnerability report generator (JSON and human-readable formats)\"\n      },\n      {\n        \"path\": \"lib/utils.mjs\",\n        \"required\": true,\n        \"description\": \"Shared utility functions for subprocess execution and JSON parsing\"\n      },\n      {\n        \"path\": \"lib/types.ts\",\n        \"required\": true,\n        \"description\": \"TypeScript type definitions for Vulnerability and ScanReport schemas\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/HOOK.md\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook metadata for continuous scanning integration\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/handler.ts\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook handler for periodic vulnerability scanning\"\n      }\n    ]\n  },\n  \"openclaw\": {\n    \"emoji\": \"🔍\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"node\",\n        \"npm\",\n        \"python3\",\n        \"pip-audit\",\n        \"semgrep\",\n        \"bandit\",\n        \"jq\",\n        \"curl\"\n      ]\n    },\n    \"triggers\": [\n      \"vulnerability scan\",\n      \"security scan\",\n      \"dependency scan\",\n      \"cve scan\",\n      \"sast scan\",\n      \"run scanner\",\n      \"scan vulnerabilities\",\n      \"check vulnerabilities\",\n      \"audit dependencies\",\n      \"security check\"\n    ]\n  }\n}\n\nArchive v0.0.5: 24 files, 57161 bytes\n\nFiles: CHANGELOG.md (1898b), hooks/clawsec-scanner-hook/handler.ts (9535b), hooks/clawsec-scanner-hook/HOOK.md (3676b), lib/report.mjs (8204b), lib/types.ts (923b), lib/utils.mjs (3568b), README.md (451b), scripts/dast_hook_executor.mjs (3809b), scripts/dast_runner.mjs (15455b), scripts/query_cve_databases.mjs (8892b), scripts/runner.sh (9574b), scripts/sast_analyzer.mjs (8621b), scripts/scan_dependencies.mjs (10147b), scripts/setup_scanner_hook.mjs (3770b), skill-card.md (2744b), skill.json (3662b), SKILL.md (16498b), test/cve_integration.test.mjs (18916b), test/dast_harness.test.mjs (10309b), test/dependency_scanner.test.mjs (18770b), test/lib/test_harness.mjs (2426b), test/reviewer_regressions.test.mjs (7614b), test/sast_engine.test.mjs (17894b), _meta.json (134b)\n\nFile v0.0.5:SKILL.md\n\n---\nname: clawsec-scanner\nversion: 0.0.5\ndescription: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\nhomepage: https://clawsec.prompt.security\nclawdis:\n  emoji: \"🔍\"\n  requires:\n    bins: [node, npm, python3, pip-audit, semgrep, bandit, jq, curl]\n---\n\n# ClawSec Scanner\n\nComprehensive security scanner for agent platforms that automates vulnerability detection across multiple dimensions:\n\n- **Dependency Scanning**: Analyzes npm and Python dependencies using `npm audit` and `pip-audit` with structured JSON output parsing\n- **CVE Database Integration**: Queries OSV (primary), NVD 2.0, and GitHub Advisory Database for vulnerability enrichment\n- **SAST Analysis**: Static code analysis using Semgrep (JavaScript/TypeScript) and Bandit (Python) to detect hardcoded secrets, command injection, path traversal, and unsafe deserialization\n- **DAST Framework**: Agent-specific static analysis of OpenClaw hook metadata and handler source without importing or invoking target code\n- **Unified Reporting**: Consolidated vulnerability reports with severity classification and remediation guidance\n- **Continuous Monitoring**: OpenClaw hook integration for automated periodic scanning\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-scanner -a openclaw -y\n```\n\n## Features\n\n### Multi-Engine Scanning\n\nThe scanner orchestrates four complementary scan types to provide comprehensive vulnerability coverage:\n\n1. **Dependency Scanning**\n   - Executes `npm audit --json` and `pip-audit -f json` as subprocesses\n   - Parses structured output to extract CVE IDs, severity, affected versions\n   - Handles edge cases: missing package-lock.json, zero vulnerabilities, malformed JSON\n\n2. **CVE Database Queries**\n   - **OSV API** (primary): Free, no authentication, broad ecosystem support (npm, PyPI, Go, Maven)\n   - **NVD 2.0** (optional): Requires API key to avoid 6-second rate limiting\n   - **GitHub Advisory Database** (optional): GraphQL API with OAuth token\n   - Normalizes all API responses to unified `Vulnerability` schema\n\n3. **Static Analysis (SAST)**\n   - **Semgrep** for JavaScript/TypeScript: Detects security issues using `--config auto` or `--config p/security-audit`\n   - **Bandit** for Python: Leverages existing `pyproject.toml` configuration\n   - Identifies: hardcoded secrets (API keys, tokens), command injection (`eval`, `exec`), path traversal, unsafe deserialization\n\n4. **Dynamic Analysis (DAST)**\n   - Static hook inspection for OpenClaw hook handlers discovered from `HOOK.md` metadata\n   - Verifies coverage and source-level risk signals without importing, transpiling, or invoking target handlers\n   - Note: Traditional web DAST tools (ZAP, Burp) do not apply to agent platforms - this provides agent-specific testing\n\n### Unified Reporting\n\nAll scan types emit a consistent `ScanReport` JSON schema:\n\n```typescript\n{\n  scan_id: string;         // UUID\n  timestamp: string;       // ISO 8601\n  target: string;          // Scanned path\n  vulnerabilities: Vulnerability[];\n  summary: {\n    critical: number;\n    high: number;\n    medium: number;\n    low: number;\n    info: number;\n  }\n}\n```\n\nEach `Vulnerability` object includes:\n- `id`: CVE-2023-12345 or GHSA-xxxx-yyyy-zzzz\n- `source`: npm-audit | pip-audit | osv | nvd | github | sast | dast\n- `severity`: critical | high | medium | low | info\n- `package`: Package name (or 'N/A' for SAST/DAST)\n- `version`: Affected version\n- `fixed_version`: First version with fix (if available)\n- `title`: Short description\n- `description`: Full advisory text\n- `references`: URLs for more info\n- `discovered_at`: ISO 8601 timestamp\n\n### OpenClaw Integration\n\nAutomated continuous monitoring via hook:\n\n- Runs scanner on configurable interval (default: 86400s / 24 hours)\n- Triggers on `agent:bootstrap` and `command:new` events\n- Posts findings to `event.messages` array with severity summary\n- Rate-limited by `CLAWSEC_SCANNER_INTERVAL` environment variable\n\n## Installation\n\n### Prerequisites\n\nVerify required binaries are available:\n\n```bash\n# Core runtimes\nnode --version  # v20+\nnpm --version\npython3 --version  # 3.10+\n\n# Scanning tools\npip-audit --version  # Install: uv pip install pip-audit\nsemgrep --version    # Install: pip install semgrep OR brew install semgrep\nbandit --version     # Install: uv pip install bandit\n\n# Utilities\njq --version\ncurl --version\n```\n\n### Option A: Via clawhub (recommended)\n\n```bash\nnpx clawhub@latest install clawsec-scanner\n```\n\n### Option B: Manual installation with verification\n\n```bash\nset -euo pipefail\n\nVERSION=\"${SKILL_VERSION:?Set SKILL_VERSION (e.g. 0.1.0)}\"\nINSTALL_ROOT=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}\"\nDEST=\"$INSTALL_ROOT/clawsec-scanner\"\nBASE=\"https://github.com/prompt-security/clawsec/releases/download/clawsec-scanner-v${VERSION}\"\n\nTEMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TEMP_DIR\"' EXIT\n\n# Pinned release-signing public key\n# Fingerprint (SHA-256 of SPKI DER): 711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\ncat > \"$TEMP_DIR/release-signing-public.pem\" <<'PEM'\n-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEAS7nijfMcUoOBCj4yOXJX+GYGv2pFl2Yaha1P4v5Cm6A=\n-----END PUBLIC KEY-----\nPEM\n\nZIP_NAME=\"clawsec-scanner-v${VERSION}.zip\"\n\n# Download release archive + signed checksums\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TEMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TEMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TEMP_DIR/checksums.sig\"\n\n# Verify checksums manifest signature\nopenssl base64 -d -A -in \"$TEMP_DIR/checksums.sig\" -out \"$TEMP_DIR/checksums.sig.bin\"\nif ! openssl pkeyutl -verify \\\n  -pubin \\\n  -inkey \"$TEMP_DIR/release-signing-public.pem\" \\\n  -sigfile \"$TEMP_DIR/checksums.sig.bin\" \\\n  -rawin \\\n  -in \"$TEMP_DIR/checksums.json\" >/dev/null 2>&1; then\n  echo \"ERROR: checksums.json signature verification failed\" >&2\n  exit 1\nfi\n\nEXPECTED_SHA=\"$(jq -r '.archive.sha256 // empty' \"$TEMP_DIR/checksums.json\")\"\nif [ -z \"$EXPECTED_SHA\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\n\nACTUAL_SHA=\"$(shasum -a 256 \"$TEMP_DIR/$ZIP_NAME\" | awk '{print $1}')\"\nif [ \"$EXPECTED_SHA\" != \"$ACTUAL_SHA\" ]; then\n  echo \"ERROR: Archive checksum mismatch\" >&2\n  exit 1\nfi\n\necho \"Checksums verified. Installing...\"\n\nmkdir -p \"$INSTALL_ROOT\"\nrm -rf \"$DEST\"\nunzip -q \"$TEMP_DIR/$ZIP_NAME\" -d \"$INSTALL_ROOT\"\n\nchmod 600 \"$DEST/skill.json\"\nfind \"$DEST\" -type f ! -name \"skill.json\" -exec chmod 644 {} \\;\n\necho \"Installed clawsec-scanner v${VERSION} to: $DEST\"\necho \"Next step: Run a scan or set up continuous monitoring\"\n```\n\n## Usage\n\n### On-Demand CLI Scanning\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\n\n# Scan all skills with JSON output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./skills/ --output report.json --format json\n\n# Scan specific directory with human-readable output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./my-skill/ --format text\n\n# Check available flags\n\"$SCANNER_DIR/scripts/runner.sh\" --help\n```\n\n**CLI Flags:**\n- `--target <path>`: Directory to scan (required)\n- `--output <file>`: Write results to file (optional, defaults to stdout)\n- `--format <json|text>`: Output format (default: json)\n- `--check`: Verify all required binaries are installed\n\n### OpenClaw Hook Setup (Continuous Monitoring)\n\nEnable automated periodic scanning:\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\nnode \"$SCANNER_DIR/scripts/setup_scanner_hook.mjs\"\n```\n\nThis creates a hook that:\n- Scans on `agent:bootstrap` and `command:new` events\n- Respects `CLAWSEC_SCANNER_INTERVAL` rate limiting (default: 86400 seconds / 24 hours)\n- Posts findings to conversation with severity summary\n- Recommends remediation for high/critical vulnerabilities\n\nRestart the OpenClaw gateway after enabling the hook, then run `/new` to trigger an immediate scan.\n\n### Environment Variables\n\n```bash\n# Optional - NVD API key to avoid rate limiting (6-second delays without key)\nexport CLAWSEC_NVD_API_KEY=\"your-nvd-api-key\"\n\n# Optional - GitHub OAuth token for Advisory Database queries\nexport GITHUB_TOKEN=\"ghp_your_token_here\"\n\n# Optional - Scanner hook interval in seconds (default: 86400 / 24 hours)\nexport CLAWSEC_SCANNER_INTERVAL=\"86400\"\n\n# Optional - Allow unsigned advisory feed during development (from clawsec-suite)\nexport CLAWSEC_ALLOW_UNSIGNED_FEED=\"1\"\n```\n\n## Architecture\n\n### Modular Design\n\nEach scan type is an independent module that can run standalone or as part of unified scan:\n\n```\nscripts/runner.sh              # Orchestration layer\n├── scan_dependencies.mjs      # npm audit + pip-audit\n├── query_cve_databases.mjs    # OSV/NVD/GitHub API queries\n├── sast_analyzer.mjs          # Semgrep + Bandit static analysis\n├── dast_runner.mjs            # Static hook inspection orchestration\n└── dast_hook_executor.mjs     # Static hook source inspection helper\n\nlib/\n├── report.mjs                 # Result aggregation and formatting\n├── utils.mjs                  # Subprocess exec, JSON parsing, error handling\n└── types.ts                   # TypeScript schema definitions\n\nhooks/clawsec-scanner-hook/\n├── HOOK.md                    # OpenClaw hook metadata\n└── handler.ts                 # Periodic scan trigger\n```\n\n### Fail-Open Philosophy\n\nThe scanner prioritizes availability over strict failure propagation:\n\n- Network failures → emit partial results, log warnings\n- Missing tools → skip that scan type, continue with others\n- Malformed JSON → parse what's valid, log errors\n- API rate limits → implement exponential backoff, fallback to other sources\n- Zero vulnerabilities → emit success report with empty array\n\n**Critical failures** that exit immediately:\n- Target path does not exist\n- No scanning tools available (all bins missing)\n- Concurrent scan detected (lockfile present)\n\n### Subprocess Execution Pattern\n\nAll external tools run as subprocesses with structured JSON output:\n\n```javascript\nimport { spawn } from 'node:child_process';\n\n// Example: npm audit execution\nconst proc = spawn('npm', ['audit', '--json'], {\n  cwd: targetPath,\n  stdio: ['ignore', 'pipe', 'pipe']\n});\n\n// Handle non-zero exit codes gracefully\n// npm audit exits 1 when vulnerabilities found (not an error!)\nproc.on('close', code => {\n  if (code !== 0 && stderr.includes('ERR!')) {\n    // Actual error\n    reject(new Error(stderr));\n  } else {\n    // Vulnerabilities found or success\n    resolve(JSON.parse(stdout));\n  }\n});\n```\n\n## Troubleshooting\n\n### Common Issues\n\n**\"Missing package-lock.json\" warning**\n- `npm audit` requires lockfile to run\n- Run `npm install` in target directory to generate\n- Scanner continues with other scan types if npm audit fails\n\n**\"NVD API rate limit exceeded\"**\n- Set `CLAWSEC_NVD_API_KEY` environment variable\n- Without API key: 6-second delays enforced between requests\n- OSV API used as primary source (no rate limits)\n\n**\"pip-audit not found\"**\n- Install: `uv pip install pip-audit` or `pip install pip-audit`\n- Verify: `which pip-audit`\n- Add to PATH if installed in non-standard location\n\n**\"Semgrep binary missing\"**\n- Install: `pip install semgrep` OR `brew install semgrep`\n- Requires Python 3.8+ runtime\n- Alternative: use Docker image `returntocorp/semgrep`\n\n**\"DAST static coverage finding\"**\n- The DAST harness does not execute target hook handlers.\n- JavaScript and TypeScript hook files are read as source and reported with `info`-level static coverage findings.\n- Review any listed static signals manually when deciding whether a hook needs deeper sandboxed testing.\n\n**\"Concurrent scan detected\"**\n- Lockfile exists: `/tmp/clawsec-scanner.lock`\n- Wait for running scan to complete or manually remove lockfile\n- Prevents overlapping scans that could produce inconsistent results\n\n### Verification\n\nCheck scanner is working correctly:\n\n```bash\n# Verify required binaries\n./scripts/runner.sh --check\n\n# Run unit tests\nnode test/dependency_scanner.test.mjs\nnode test/cve_integration.test.mjs\nnode test/sast_engine.test.mjs\nnode test/dast_harness.test.mjs\n\n# Validate skill structure\npython ../../utils/validate_skill.py .\n\n# Scan test fixtures (should detect known vulnerabilities)\n./scripts/runner.sh --target test/fixtures/ --format text\n```\n\n## Development\n\n### Running Tests\n\n```bash\n# All tests (vanilla Node.js, no framework)\nfor test in test/*.test.mjs; do\n  node \"$test\" || exit 1\ndone\n\n# Individual test suites\nnode test/dependency_scanner.test.mjs  # Dependency scanning\nnode test/cve_integration.test.mjs     # CVE database APIs\nnode test/sast_engine.test.mjs         # Static analysis\nnode test/dast_harness.test.mjs        # DAST static hook inspection\n```\n\n### Linting\n\n```bash\n# JavaScript/TypeScript\nnpx eslint . --ext .ts,.tsx,.js,.jsx,.mjs --max-warnings 0\n\n# Python (Bandit already configured in pyproject.toml)\nruff check .\nbandit -r . -ll\n\n# Shell scripts\nshellcheck scripts/*.sh\n```\n\n### Adding Custom Semgrep Rules\n\nCreate custom rules in `.semgrep/rules/`:\n\n```yaml\nrules:\n  - id: custom-security-rule\n    pattern: dangerous_function($ARG)\n    message: Avoid dangerous_function - use safe_alternative instead\n    severity: WARNING\n    languages: [javascript, typescript]\n```\n\nUpdate `scripts/sast_analyzer.mjs` to include custom rules:\n\n```javascript\nconst proc = spawn('semgrep', [\n  'scan',\n  '--config', 'auto',\n  '--config', '.semgrep/rules/',  // Add custom rules\n  '--json',\n  targetPath\n]);\n```\n\n## Integration with ClawSec Suite\n\nThe scanner works standalone or as part of the ClawSec ecosystem:\n\n- **clawsec-suite**: Meta-skill that can install and manage clawsec-scanner\n- **clawsec-feed**: Advisory feed for malicious skill detection (complementary)\n- **openclaw-audit-watchdog**: Cron-based audit automation (similar pattern)\n\nInstall the full ClawSec suite:\n\n```bash\nnpx clawhub@latest install clawsec-suite\n# Then use clawsec-suite to discover and install clawsec-scanner\n```\n\n## Security Considerations\n\n### Scanner Security\n\n- No hardcoded secrets in scanner code\n- API keys read from environment variables only (never logged or committed)\n- Subprocess arguments use arrays to prevent shell injection\n- All external tool output parsed with try/catch error handling\n\n### Vulnerability Prioritization\n\n**Critical/High severity findings** should be addressed immediately:\n- Known exploits in dependencies (CVSS 9.0+)\n- Hardcoded API keys or credentials in code\n- Command injection vulnerabilities\n- Path traversal without validation\n\n**Medium/Low severity findings** can be addressed in normal sprint cycles:\n- Outdated dependencies without known exploits\n- Missing security headers\n- Weak cryptography usage\n\n**Info findings** are advisory only:\n- Deprecated API usage\n- Code quality issues flagged by linters\n\n## Roadmap\n\n### v0.0.4 (Current)\n- [x] Dependency scanning (npm audit, pip-audit)\n- [x] CVE database integration (OSV, NVD, GitHub Advisory)\n- [x] SAST analysis (Semgrep, Bandit)\n- [x] Static OpenClaw hook inspection for DAST without target code execution\n- [x] Unified JSON reporting\n- [x] OpenClaw hook integration\n\n### Future Enhancements\n- [ ] Automatic remediation (dependency upgrades, code fixes)\n- [ ] SARIF output format for GitHub Code Scanning integration\n- [ ] Web dashboard for vulnerability tracking over time\n- [ ] CI/CD GitHub Action for PR blocking on high-severity findings\n- [ ] Container image scanning (Docker, OCI)\n- [ ] Infrastructure-as-Code scanning (Terraform, CloudFormation)\n- [ ] Comprehensive agent workflow DAST (requires deeper platform integration)\n\n## Contributing\n\nFound a security issue? Please report privately to security@prompt.security.\n\nFor feature requests and bug reports, open an issue at:\nhttps://github.com/prompt-security/clawsec/issues\n\n## License\n\nAGPL-3.0-or-later\n\nSee LICENSE file in repository root for full text.\n\n## Resources\n\n- **ClawSec Homepage**: https://clawsec.prompt.security\n- **Documentation**: https://clawsec.prompt.security/scanner\n- **GitHub Repository**: https://github.com/prompt-security/clawsec\n- **OSV API Docs**: https://osv.dev/docs/\n- **NVD API Docs**: https://nvd.nist.gov/developers/vulnerabilities\n- **Semgrep Registry**: https://semgrep.dev/explore\n- **Bandit Documentation**: https://bandit.readthedocs.io/\n\nFile v0.0.5:README.md\n\n# Clawsec Scanner\n\nAutomated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-scanner -a openclaw -y\n```\n\nFile v0.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-scanner\",\n  \"version\": \"0.0.5\",\n  \"publishedAt\": 1781103573346\n}\n\nFile v0.0.5:CHANGELOG.md\n\n# Changelog\n\n## [0.0.5] - 2026-06-10\n\n### Changed\n\n- Re-released skill package with updated marketplace grouping and signed release trust artifacts for Vercel-compatible skill installation.\n\n## [0.0.4] - 2026-06-07\n\n### Security\n- Replaced DAST target hook execution with static hook source inspection so scanner runs never import, transpile, or invoke untrusted handler code.\n\n## [0.0.3] - 2026-05-13\n\n### Changed\n- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.\n\nAll notable changes to the ClawSec Scanner will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.0.2] - 2026-03-10\n\n### Changed\n\n- Replaced simulated DAST checks with real OpenClaw hook execution harness testing\n- Updated DAST semantics so high-severity findings are emitted for actual hook execution failures/timeouts, not static payload pattern matches\n- Reclassified DAST harness capability limitations (for example missing TypeScript compiler for `.ts` hooks) to `info` coverage findings instead of high severity\n- Added DAST harness mode guard to prevent recursive scanner execution when hook handlers are tested in isolation\n\n### Added\n\n- New DAST helper executor script for isolated per-hook execution and timeout enforcement\n- DAST harness regression tests covering no-false-positive baseline and malicious-input crash detection\n\n## [0.0.1] - 2026-02-27\n\n### Added\n\n- Initial release of ClawSec Scanner skill\n- Automated vulnerability scanning for OpenClaw skill installations\n- Integration with advisory feed for real-time security alerts\n- Support for scanning skill dependencies and detecting known CVEs\n- Configurable scan policies and risk thresholds\n- Detailed vulnerability reporting with remediation guidance\n\nFile v0.0.5:hooks/clawsec-scanner-hook/HOOK.md\n\n---\nname: clawsec-scanner-hook\ndescription: Periodic vulnerability scanning for installed skills and dependencies with configurable scan intervals.\nmetadata: { \"openclaw\": { \"events\": [\"agent:bootstrap\", \"command:new\"] } }\n---\n\n# ClawSec Scanner Hook\n\nThis hook performs comprehensive vulnerability scanning on installed skills and their dependencies on:\n\n- `agent:bootstrap`\n- `command:new`\n\nWhen triggered, it runs all configured scanning engines (dependency scan, SAST, DAST, CVE database lookup) and posts findings as conversation messages. Scans are rate-limited by configurable interval to avoid performance impact.\n\n## Scanning Capabilities\n\nThe hook orchestrates four independent scanning engines:\n\n1. **Dependency Scanning**: Executes `npm audit` and `pip-audit` to detect known vulnerabilities in JavaScript and Python dependencies\n2. **SAST (Static Analysis)**: Runs Semgrep (JS/TS) and Bandit (Python) to detect security issues like hardcoded secrets, command injection, and path traversal\n3. **CVE Database Lookup**: Queries OSV API (primary), NVD 2.0 (optional), and GitHub Advisory Database (optional) for vulnerability enrichment\n4. **DAST (Dynamic Analysis)**: Executes real OpenClaw hook handlers in an isolated harness and tests malicious-input resilience, timeout behavior, output bounds, and event mutation safety\n\n## Safety Contract\n\n- The hook does not modify or delete skills.\n- It only reports findings and provides remediation guidance.\n- Scanning is non-blocking and runs on a configurable interval (default 24 hours).\n- Failed scans (network errors, missing tools) produce warnings but do not block execution.\n- Findings are deduplicated to avoid alert fatigue.\n\n## Optional Environment Variables\n\n### Core Configuration\n\n- `CLAWSEC_SCANNER_INTERVAL`: Minimum interval between hook scans in seconds (default `86400` / 24 hours).\n- `CLAWSEC_SCANNER_TARGET`: Override default scan target path (default: installed skills root).\n- `CLAWSEC_SCANNER_STATE_FILE`: Override state file path for deduplication (default `~/.openclaw/clawsec-scanner-state.json`).\n- `CLAWSEC_INSTALL_ROOT`: Override installed skills root directory.\n\n### CVE Database Integration\n\n- `CLAWSEC_NVD_API_KEY`: NVD API key for rate-limit-free access (without this, 6-second delays apply).\n- `GITHUB_TOKEN`: GitHub OAuth token for GitHub Advisory Database queries (optional enhancement).\n\n### Selective Scanning\n\n- `CLAWSEC_SKIP_DEPENDENCY_SCAN`: Set to `1` to disable dependency scanning (npm audit, pip-audit).\n- `CLAWSEC_SKIP_SAST`: Set to `1` to disable static analysis (Semgrep, Bandit).\n- `CLAWSEC_SKIP_DAST`: Set to `1` to disable dynamic analysis (hook security tests).\n- `CLAWSEC_SKIP_CVE_LOOKUP`: Set to `1` to disable CVE database enrichment.\n\n### Advanced Options\n\n- `CLAWSEC_SCANNER_TIMEOUT`: Maximum scan duration in seconds before timeout (default `300` / 5 minutes).\n- `CLAWSEC_SCANNER_FORMAT`: Output format for findings (`json` or `text`, default `text`).\n- `CLAWSEC_SCANNER_MIN_SEVERITY`: Minimum severity to report (`critical`, `high`, `medium`, `low`, `info`, default `medium`).\n- `CLAWSEC_SCANNER_OUTPUT_FILE`: Optional path to write full scan report JSON (default: conversation only).\n\n## Required Binaries\n\nThe hook requires the following binaries to be available on `PATH`:\n\n- `node` (20+) - JavaScript runtime\n- `npm` - For npm audit execution\n- `python3` (3.10+) - Python runtime\n- `pip-audit` - Python dependency scanner\n- `semgrep` - JavaScript/TypeScript static analysis\n- `bandit` - Python static analysis\n- `jq` - JSON parsing and merging\n- `curl` - API requests (fallback)\n\nMissing binaries will be logged as warnings; available tools will still run.\n\nFile v0.0.5:skill-card.md\n\n## Description: <br>\nAutomated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[davida-ps](https://clawhub.ai/user/davida-ps) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill to scan agent skills and dependencies for known vulnerabilities, static-analysis findings, CVE enrichment, and OpenClaw hook risks. It can run on demand or through an OpenClaw hook for periodic monitoring. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Automatic hook behavior can run periodic local scans and surface findings in conversation messages. <br>\nMitigation: Review hook setup and scan interval settings before enabling continuous monitoring. <br>\nRisk: Broad target or output paths can expose more local files or reports than intended. <br>\nMitigation: Use narrow scan targets and output paths, and review generated reports before sharing them. <br>\nRisk: DAST claims may not prove real runtime hook execution for every target. <br>\nMitigation: Treat DAST results as one signal and perform deeper sandboxed testing for high-risk hooks. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/davida-ps/clawsec-scanner) <br>\n- [ClawSec homepage](https://clawsec.prompt.security) <br>\n- [ClawSec scanner documentation](https://clawsec.prompt.security/scanner) <br>\n- [OSV API documentation](https://osv.dev/docs/) <br>\n- [NVD vulnerability API documentation](https://nvd.nist.gov/developers/vulnerabilities) <br>\n- [Semgrep rule registry](https://semgrep.dev/explore) <br>\n- [Bandit documentation](https://bandit.readthedocs.io/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, JSON, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [JSON or human-readable text/Markdown security reports with remediation guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May post findings to OpenClaw conversation messages and optionally write a report file.] <br>\n\n## Skill Version(s): <br>\n0.0.5 (source: server release metadata, SKILL.md frontmatter, skill.json, CHANGELOG.md released 2026-06-10) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.0.5:skill.json\n\n{\n  \"name\": \"clawsec-scanner\",\n  \"version\": \"0.0.5\",\n  \"description\": \"Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"keywords\": [\n    \"security\",\n    \"vulnerability\",\n    \"scanner\",\n    \"dependency\",\n    \"cve\",\n    \"sast\",\n    \"dast\",\n    \"audit\",\n    \"agents\",\n    \"ai\",\n    \"openclaw\",\n    \"semgrep\",\n    \"bandit\",\n    \"osv\",\n    \"nvd\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Scanner skill documentation and usage guide\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and feature changelog\"\n      },\n      {\n        \"path\": \"scripts/runner.sh\",\n        \"required\": true,\n        \"description\": \"Main orchestration script for running all scanner engines\"\n      },\n      {\n        \"path\": \"scripts/scan_dependencies.mjs\",\n        \"required\": true,\n        \"description\": \"Dependency scanner using npm audit and pip-audit with JSON parsing\"\n      },\n      {\n        \"path\": \"scripts/query_cve_databases.mjs\",\n        \"required\": true,\n        \"description\": \"Multi-database CVE lookup (OSV primary, NVD/GitHub fallback)\"\n      },\n      {\n        \"path\": \"scripts/sast_analyzer.mjs\",\n        \"required\": true,\n        \"description\": \"Static analysis engine running Semgrep and Bandit as subprocesses\"\n      },\n      {\n        \"path\": \"scripts/dast_runner.mjs\",\n        \"required\": true,\n        \"description\": \"Static OpenClaw hook inspection harness that does not execute target handlers\"\n      },\n      {\n        \"path\": \"scripts/dast_hook_executor.mjs\",\n        \"required\": true,\n        \"description\": \"Static hook source inspection helper used by DAST without importing target handlers\"\n      },\n      {\n        \"path\": \"scripts/setup_scanner_hook.mjs\",\n        \"required\": false,\n        \"description\": \"Hook installer for continuous monitoring integration\"\n      },\n      {\n        \"path\": \"lib/report.mjs\",\n        \"required\": true,\n        \"description\": \"Unified vulnerability report generator (JSON and human-readable formats)\"\n      },\n      {\n        \"path\": \"lib/utils.mjs\",\n        \"required\": true,\n        \"description\": \"Shared utility functions for subprocess execution and JSON parsing\"\n      },\n      {\n        \"path\": \"lib/types.ts\",\n        \"required\": true,\n        \"description\": \"TypeScript type definitions for Vulnerability and ScanReport schemas\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/HOOK.md\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook metadata for continuous scanning integration\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/handler.ts\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook handler for periodic vulnerability scanning\"\n      }\n    ]\n  },\n  \"openclaw\": {\n    \"emoji\": \"🔍\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"node\",\n        \"npm\",\n        \"python3\",\n        \"pip-audit\",\n        \"semgrep\",\n        \"bandit\",\n        \"jq\",\n        \"curl\"\n      ]\n    },\n    \"triggers\": [\n      \"vulnerability scan\",\n      \"security scan\",\n      \"dependency scan\",\n      \"cve scan\",\n      \"sast scan\",\n      \"run scanner\",\n      \"scan vulnerabilities\",\n      \"check vulnerabilities\",\n      \"audit dependencies\",\n      \"security check\"\n    ]\n  }\n}\n\nArchive v0.0.4: 23 files, 56754 bytes\n\nFiles: CHANGELOG.md (1720b), hooks/clawsec-scanner-hook/handler.ts (9535b), hooks/clawsec-scanner-hook/HOOK.md (3676b), lib/report.mjs (8204b), lib/types.ts (923b), lib/utils.mjs (3568b), scripts/dast_hook_executor.mjs (3809b), scripts/dast_runner.mjs (15455b), scripts/query_cve_databases.mjs (8892b), scripts/runner.sh (9574b), scripts/sast_analyzer.mjs (8621b), scripts/scan_dependencies.mjs (10147b), scripts/setup_scanner_hook.mjs (3770b), skill-card.md (2969b), skill.json (3662b), SKILL.md (16322b), test/cve_integration.test.mjs (18916b), test/dast_harness.test.mjs (10309b), test/dependency_scanner.test.mjs (18770b), test/lib/test_harness.mjs (2426b), test/reviewer_regressions.test.mjs (7614b), test/sast_engine.test.mjs (17894b), _meta.json (134b)\n\nFile v0.0.4:SKILL.md\n\n---\nname: clawsec-scanner\nversion: 0.0.4\ndescription: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\nhomepage: https://clawsec.prompt.security\nclawdis:\n  emoji: \"🔍\"\n  requires:\n    bins: [node, npm, python3, pip-audit, semgrep, bandit, jq, curl]\n---\n\n# ClawSec Scanner\n\nComprehensive security scanner for agent platforms that automates vulnerability detection across multiple dimensions:\n\n- **Dependency Scanning**: Analyzes npm and Python dependencies using `npm audit` and `pip-audit` with structured JSON output parsing\n- **CVE Database Integration**: Queries OSV (primary), NVD 2.0, and GitHub Advisory Database for vulnerability enrichment\n- **SAST Analysis**: Static code analysis using Semgrep (JavaScript/TypeScript) and Bandit (Python) to detect hardcoded secrets, command injection, path traversal, and unsafe deserialization\n- **DAST Framework**: Agent-specific static analysis of OpenClaw hook metadata and handler source without importing or invoking target code\n- **Unified Reporting**: Consolidated vulnerability reports with severity classification and remediation guidance\n- **Continuous Monitoring**: OpenClaw hook integration for automated periodic scanning\n\n## Features\n\n### Multi-Engine Scanning\n\nThe scanner orchestrates four complementary scan types to provide comprehensive vulnerability coverage:\n\n1. **Dependency Scanning**\n   - Executes `npm audit --json` and `pip-audit -f json` as subprocesses\n   - Parses structured output to extract CVE IDs, severity, affected versions\n   - Handles edge cases: missing package-lock.json, zero vulnerabilities, malformed JSON\n\n2. **CVE Database Queries**\n   - **OSV API** (primary): Free, no authentication, broad ecosystem support (npm, PyPI, Go, Maven)\n   - **NVD 2.0** (optional): Requires API key to avoid 6-second rate limiting\n   - **GitHub Advisory Database** (optional): GraphQL API with OAuth token\n   - Normalizes all API responses to unified `Vulnerability` schema\n\n3. **Static Analysis (SAST)**\n   - **Semgrep** for JavaScript/TypeScript: Detects security issues using `--config auto` or `--config p/security-audit`\n   - **Bandit** for Python: Leverages existing `pyproject.toml` configuration\n   - Identifies: hardcoded secrets (API keys, tokens), command injection (`eval`, `exec`), path traversal, unsafe deserialization\n\n4. **Dynamic Analysis (DAST)**\n   - Static hook inspection for OpenClaw hook handlers discovered from `HOOK.md` metadata\n   - Verifies coverage and source-level risk signals without importing, transpiling, or invoking target handlers\n   - Note: Traditional web DAST tools (ZAP, Burp) do not apply to agent platforms - this provides agent-specific testing\n\n### Unified Reporting\n\nAll scan types emit a consistent `ScanReport` JSON schema:\n\n```typescript\n{\n  scan_id: string;         // UUID\n  timestamp: string;       // ISO 8601\n  target: string;          // Scanned path\n  vulnerabilities: Vulnerability[];\n  summary: {\n    critical: number;\n    high: number;\n    medium: number;\n    low: number;\n    info: number;\n  }\n}\n```\n\nEach `Vulnerability` object includes:\n- `id`: CVE-2023-12345 or GHSA-xxxx-yyyy-zzzz\n- `source`: npm-audit | pip-audit | osv | nvd | github | sast | dast\n- `severity`: critical | high | medium | low | info\n- `package`: Package name (or 'N/A' for SAST/DAST)\n- `version`: Affected version\n- `fixed_version`: First version with fix (if available)\n- `title`: Short description\n- `description`: Full advisory text\n- `references`: URLs for more info\n- `discovered_at`: ISO 8601 timestamp\n\n### OpenClaw Integration\n\nAutomated continuous monitoring via hook:\n\n- Runs scanner on configurable interval (default: 86400s / 24 hours)\n- Triggers on `agent:bootstrap` and `command:new` events\n- Posts findings to `event.messages` array with severity summary\n- Rate-limited by `CLAWSEC_SCANNER_INTERVAL` environment variable\n\n## Installation\n\n### Prerequisites\n\nVerify required binaries are available:\n\n```bash\n# Core runtimes\nnode --version  # v20+\nnpm --version\npython3 --version  # 3.10+\n\n# Scanning tools\npip-audit --version  # Install: uv pip install pip-audit\nsemgrep --version    # Install: pip install semgrep OR brew install semgrep\nbandit --version     # Install: uv pip install bandit\n\n# Utilities\njq --version\ncurl --version\n```\n\n### Option A: Via clawhub (recommended)\n\n```bash\nnpx clawhub@latest install clawsec-scanner\n```\n\n### Option B: Manual installation with verification\n\n```bash\nset -euo pipefail\n\nVERSION=\"${SKILL_VERSION:?Set SKILL_VERSION (e.g. 0.1.0)}\"\nINSTALL_ROOT=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}\"\nDEST=\"$INSTALL_ROOT/clawsec-scanner\"\nBASE=\"https://github.com/prompt-security/clawsec/releases/download/clawsec-scanner-v${VERSION}\"\n\nTEMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TEMP_DIR\"' EXIT\n\n# Pinned release-signing public key\n# Fingerprint (SHA-256 of SPKI DER): 711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\ncat > \"$TEMP_DIR/release-signing-public.pem\" <<'PEM'\n-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEAS7nijfMcUoOBCj4yOXJX+GYGv2pFl2Yaha1P4v5Cm6A=\n-----END PUBLIC KEY-----\nPEM\n\nZIP_NAME=\"clawsec-scanner-v${VERSION}.zip\"\n\n# Download release archive + signed checksums\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TEMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TEMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TEMP_DIR/checksums.sig\"\n\n# Verify checksums manifest signature\nopenssl base64 -d -A -in \"$TEMP_DIR/checksums.sig\" -out \"$TEMP_DIR/checksums.sig.bin\"\nif ! openssl pkeyutl -verify \\\n  -pubin \\\n  -inkey \"$TEMP_DIR/release-signing-public.pem\" \\\n  -sigfile \"$TEMP_DIR/checksums.sig.bin\" \\\n  -rawin \\\n  -in \"$TEMP_DIR/checksums.json\" >/dev/null 2>&1; then\n  echo \"ERROR: checksums.json signature verification failed\" >&2\n  exit 1\nfi\n\nEXPECTED_SHA=\"$(jq -r '.archive.sha256 // empty' \"$TEMP_DIR/checksums.json\")\"\nif [ -z \"$EXPECTED_SHA\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\n\nACTUAL_SHA=\"$(shasum -a 256 \"$TEMP_DIR/$ZIP_NAME\" | awk '{print $1}')\"\nif [ \"$EXPECTED_SHA\" != \"$ACTUAL_SHA\" ]; then\n  echo \"ERROR: Archive checksum mismatch\" >&2\n  exit 1\nfi\n\necho \"Checksums verified. Installing...\"\n\nmkdir -p \"$INSTALL_ROOT\"\nrm -rf \"$DEST\"\nunzip -q \"$TEMP_DIR/$ZIP_NAME\" -d \"$INSTALL_ROOT\"\n\nchmod 600 \"$DEST/skill.json\"\nfind \"$DEST\" -type f ! -name \"skill.json\" -exec chmod 644 {} \\;\n\necho \"Installed clawsec-scanner v${VERSION} to: $DEST\"\necho \"Next step: Run a scan or set up continuous monitoring\"\n```\n\n## Usage\n\n### On-Demand CLI Scanning\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\n\n# Scan all skills with JSON output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./skills/ --output report.json --format json\n\n# Scan specific directory with human-readable output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./my-skill/ --format text\n\n# Check available flags\n\"$SCANNER_DIR/scripts/runner.sh\" --help\n```\n\n**CLI Flags:**\n- `--target <path>`: Directory to scan (required)\n- `--output <file>`: Write results to file (optional, defaults to stdout)\n- `--format <json|text>`: Output format (default: json)\n- `--check`: Verify all required binaries are installed\n\n### OpenClaw Hook Setup (Continuous Monitoring)\n\nEnable automated periodic scanning:\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\nnode \"$SCANNER_DIR/scripts/setup_scanner_hook.mjs\"\n```\n\nThis creates a hook that:\n- Scans on `agent:bootstrap` and `command:new` events\n- Respects `CLAWSEC_SCANNER_INTERVAL` rate limiting (default: 86400 seconds / 24 hours)\n- Posts findings to conversation with severity summary\n- Recommends remediation for high/critical vulnerabilities\n\nRestart the OpenClaw gateway after enabling the hook, then run `/new` to trigger an immediate scan.\n\n### Environment Variables\n\n```bash\n# Optional - NVD API key to avoid rate limiting (6-second delays without key)\nexport CLAWSEC_NVD_API_KEY=\"your-nvd-api-key\"\n\n# Optional - GitHub OAuth token for Advisory Database queries\nexport GITHUB_TOKEN=\"ghp_your_token_here\"\n\n# Optional - Scanner hook interval in seconds (default: 86400 / 24 hours)\nexport CLAWSEC_SCANNER_INTERVAL=\"86400\"\n\n# Optional - Allow unsigned advisory feed during development (from clawsec-suite)\nexport CLAWSEC_ALLOW_UNSIGNED_FEED=\"1\"\n```\n\n## Architecture\n\n### Modular Design\n\nEach scan type is an independent module that can run standalone or as part of unified scan:\n\n```\nscripts/runner.sh              # Orchestration layer\n├── scan_dependencies.mjs      # npm audit + pip-audit\n├── query_cve_databases.mjs    # OSV/NVD/GitHub API queries\n├── sast_analyzer.mjs          # Semgrep + Bandit static analysis\n├── dast_runner.mjs            # Static hook inspection orchestration\n└── dast_hook_executor.mjs     # Static hook source inspection helper\n\nlib/\n├── report.mjs                 # Result aggregation and formatting\n├── utils.mjs                  # Subprocess exec, JSON parsing, error handling\n└── types.ts                   # TypeScript schema definitions\n\nhooks/clawsec-scanner-hook/\n├── HOOK.md                    # OpenClaw hook metadata\n└── handler.ts                 # Periodic scan trigger\n```\n\n### Fail-Open Philosophy\n\nThe scanner prioritizes availability over strict failure propagation:\n\n- Network failures → emit partial results, log warnings\n- Missing tools → skip that scan type, continue with others\n- Malformed JSON → parse what's valid, log errors\n- API rate limits → implement exponential backoff, fallback to other sources\n- Zero vulnerabilities → emit success report with empty array\n\n**Critical failures** that exit immediately:\n- Target path does not exist\n- No scanning tools available (all bins missing)\n- Concurrent scan detected (lockfile present)\n\n### Subprocess Execution Pattern\n\nAll external tools run as subprocesses with structured JSON output:\n\n```javascript\nimport { spawn } from 'node:child_process';\n\n// Example: npm audit execution\nconst proc = spawn('npm', ['audit', '--json'], {\n  cwd: targetPath,\n  stdio: ['ignore', 'pipe', 'pipe']\n});\n\n// Handle non-zero exit codes gracefully\n// npm audit exits 1 when vulnerabilities found (not an error!)\nproc.on('close', code => {\n  if (code !== 0 && stderr.includes('ERR!')) {\n    // Actual error\n    reject(new Error(stderr));\n  } else {\n    // Vulnerabilities found or success\n    resolve(JSON.parse(stdout));\n  }\n});\n```\n\n## Troubleshooting\n\n### Common Issues\n\n**\"Missing package-lock.json\" warning**\n- `npm audit` requires lockfile to run\n- Run `npm install` in target directory to generate\n- Scanner continues with other scan types if npm audit fails\n\n**\"NVD API rate limit exceeded\"**\n- Set `CLAWSEC_NVD_API_KEY` environment variable\n- Without API key: 6-second delays enforced between requests\n- OSV API used as primary source (no rate limits)\n\n**\"pip-audit not found\"**\n- Install: `uv pip install pip-audit` or `pip install pip-audit`\n- Verify: `which pip-audit`\n- Add to PATH if installed in non-standard location\n\n**\"Semgrep binary missing\"**\n- Install: `pip install semgrep` OR `brew install semgrep`\n- Requires Python 3.8+ runtime\n- Alternative: use Docker image `returntocorp/semgrep`\n\n**\"DAST static coverage finding\"**\n- The DAST harness does not execute target hook handlers.\n- JavaScript and TypeScript hook files are read as source and reported with `info`-level static coverage findings.\n- Review any listed static signals manually when deciding whether a hook needs deeper sandboxed testing.\n\n**\"Concurrent scan detected\"**\n- Lockfile exists: `/tmp/clawsec-scanner.lock`\n- Wait for running scan to complete or manually remove lockfile\n- Prevents overlapping scans that could produce inconsistent results\n\n### Verification\n\nCheck scanner is working correctly:\n\n```bash\n# Verify required binaries\n./scripts/runner.sh --check\n\n# Run unit tests\nnode test/dependency_scanner.test.mjs\nnode test/cve_integration.test.mjs\nnode test/sast_engine.test.mjs\nnode test/dast_harness.test.mjs\n\n# Validate skill structure\npython ../../utils/validate_skill.py .\n\n# Scan test fixtures (should detect known vulnerabilities)\n./scripts/runner.sh --target test/fixtures/ --format text\n```\n\n## Development\n\n### Running Tests\n\n```bash\n# All tests (vanilla Node.js, no framework)\nfor test in test/*.test.mjs; do\n  node \"$test\" || exit 1\ndone\n\n# Individual test suites\nnode test/dependency_scanner.test.mjs  # Dependency scanning\nnode test/cve_integration.test.mjs     # CVE database APIs\nnode test/sast_engine.test.mjs         # Static analysis\nnode test/dast_harness.test.mjs        # DAST static hook inspection\n```\n\n### Linting\n\n```bash\n# JavaScript/TypeScript\nnpx eslint . --ext .ts,.tsx,.js,.jsx,.mjs --max-warnings 0\n\n# Python (Bandit already configured in pyproject.toml)\nruff check .\nbandit -r . -ll\n\n# Shell scripts\nshellcheck scripts/*.sh\n```\n\n### Adding Custom Semgrep Rules\n\nCreate custom rules in `.semgrep/rules/`:\n\n```yaml\nrules:\n  - id: custom-security-rule\n    pattern: dangerous_function($ARG)\n    message: Avoid dangerous_function - use safe_alternative instead\n    severity: WARNING\n    languages: [javascript, typescript]\n```\n\nUpdate `scripts/sast_analyzer.mjs` to include custom rules:\n\n```javascript\nconst proc = spawn('semgrep', [\n  'scan',\n  '--config', 'auto',\n  '--config', '.semgrep/rules/',  // Add custom rules\n  '--json',\n  targetPath\n]);\n```\n\n## Integration with ClawSec Suite\n\nThe scanner works standalone or as part of the ClawSec ecosystem:\n\n- **clawsec-suite**: Meta-skill that can install and manage clawsec-scanner\n- **clawsec-feed**: Advisory feed for malicious skill detection (complementary)\n- **openclaw-audit-watchdog**: Cron-based audit automation (similar pattern)\n\nInstall the full ClawSec suite:\n\n```bash\nnpx clawhub@latest install clawsec-suite\n# Then use clawsec-suite to discover and install clawsec-scanner\n```\n\n## Security Considerations\n\n### Scanner Security\n\n- No hardcoded secrets in scanner code\n- API keys read from environment variables only (never logged or committed)\n- Subprocess arguments use arrays to prevent shell injection\n- All external tool output parsed with try/catch error handling\n\n### Vulnerability Prioritization\n\n**Critical/High severity findings** should be addressed immediately:\n- Known exploits in dependencies (CVSS 9.0+)\n- Hardcoded API keys or credentials in code\n- Command injection vulnerabilities\n- Path traversal without validation\n\n**Medium/Low severity findings** can be addressed in normal sprint cycles:\n- Outdated dependencies without known exploits\n- Missing security headers\n- Weak cryptography usage\n\n**Info findings** are advisory only:\n- Deprecated API usage\n- Code quality issues flagged by linters\n\n## Roadmap\n\n### v0.0.4 (Current)\n- [x] Dependency scanning (npm audit, pip-audit)\n- [x] CVE database integration (OSV, NVD, GitHub Advisory)\n- [x] SAST analysis (Semgrep, Bandit)\n- [x] Static OpenClaw hook inspection for DAST without target code execution\n- [x] Unified JSON reporting\n- [x] OpenClaw hook integration\n\n### Future Enhancements\n- [ ] Automatic remediation (dependency upgrades, code fixes)\n- [ ] SARIF output format for GitHub Code Scanning integration\n- [ ] Web dashboard for vulnerability tracking over time\n- [ ] CI/CD GitHub Action for PR blocking on high-severity findings\n- [ ] Container image scanning (Docker, OCI)\n- [ ] Infrastructure-as-Code scanning (Terraform, CloudFormation)\n- [ ] Comprehensive agent workflow DAST (requires deeper platform integration)\n\n## Contributing\n\nFound a security issue? Please report privately to security@prompt.security.\n\nFor feature requests and bug reports, open an issue at:\nhttps://github.com/prompt-security/clawsec/issues\n\n## License\n\nAGPL-3.0-or-later\n\nSee LICENSE file in repository root for full text.\n\n## Resources\n\n- **ClawSec Homepage**: https://clawsec.prompt.security\n- **Documentation**: https://clawsec.prompt.security/scanner\n- **GitHub Repository**: https://github.com/prompt-security/clawsec\n- **OSV API Docs**: https://osv.dev/docs/\n- **NVD API Docs**: https://nvd.nist.gov/developers/vulnerabilities\n- **Semgrep Registry**: https://semgrep.dev/explore\n- **Bandit Documentation**: https://bandit.readthedocs.io/\n\nFile v0.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-scanner\",\n  \"version\": \"0.0.4\",\n  \"publishedAt\": 1780826864927\n}\n\nFile v0.0.4:CHANGELOG.md\n\n# Changelog\n\n## [0.0.4] - 2026-06-07\n\n### Security\n- Replaced DAST target hook execution with static hook source inspection so scanner runs never import, transpile, or invoke untrusted handler code.\n\n## [0.0.3] - 2026-05-13\n\n### Changed\n- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.\n\nAll notable changes to the ClawSec Scanner will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.0.2] - 2026-03-10\n\n### Changed\n\n- Replaced simulated DAST checks with real OpenClaw hook execution harness testing\n- Updated DAST semantics so high-severity findings are emitted for actual hook execution failures/timeouts, not static payload pattern matches\n- Reclassified DAST harness capability limitations (for example missing TypeScript compiler for `.ts` hooks) to `info` coverage findings instead of high severity\n- Added DAST harness mode guard to prevent recursive scanner execution when hook handlers are tested in isolation\n\n### Added\n\n- New DAST helper executor script for isolated per-hook execution and timeout enforcement\n- DAST harness regression tests covering no-false-positive baseline and malicious-input crash detection\n\n## [0.0.1] - 2026-02-27\n\n### Added\n\n- Initial release of ClawSec Scanner skill\n- Automated vulnerability scanning for OpenClaw skill installations\n- Integration with advisory feed for real-time security alerts\n- Support for scanning skill dependencies and detecting known CVEs\n- Configurable scan policies and risk thresholds\n- Detailed vulnerability reporting with remediation guidance\n\nFile v0.0.4:hooks/clawsec-scanner-hook/HOOK.md\n\n---\nname: clawsec-scanner-hook\ndescription: Periodic vulnerability scanning for installed skills and dependencies with configurable scan intervals.\nmetadata: { \"openclaw\": { \"events\": [\"agent:bootstrap\", \"command:new\"] } }\n---\n\n# ClawSec Scanner Hook\n\nThis hook performs comprehensive vulnerability scanning on installed skills and their dependencies on:\n\n- `agent:bootstrap`\n- `command:new`\n\nWhen triggered, it runs all configured scanning engines (dependency scan, SAST, DAST, CVE database lookup) and posts findings as conversation messages. Scans are rate-limited by configurable interval to avoid performance impact.\n\n## Scanning Capabilities\n\nThe hook orchestrates four independent scanning engines:\n\n1. **Dependency Scanning**: Executes `npm audit` and `pip-audit` to detect known vulnerabilities in JavaScript and Python dependencies\n2. **SAST (Static Analysis)**: Runs Semgrep (JS/TS) and Bandit (Python) to detect security issues like hardcoded secrets, command injection, and path traversal\n3. **CVE Database Lookup**: Queries OSV API (primary), NVD 2.0 (optional), and GitHub Advisory Database (optional) for vulnerability enrichment\n4. **DAST (Dynamic Analysis)**: Executes real OpenClaw hook handlers in an isolated harness and tests malicious-input resilience, timeout behavior, output bounds, and event mutation safety\n\n## Safety Contract\n\n- The hook does not modify or delete skills.\n- It only reports findings and provides remediation guidance.\n- Scanning is non-blocking and runs on a configurable interval (default 24 hours).\n- Failed scans (network errors, missing tools) produce warnings but do not block execution.\n- Findings are deduplicated to avoid alert fatigue.\n\n## Optional Environment Variables\n\n### Core Configuration\n\n- `CLAWSEC_SCANNER_INTERVAL`: Minimum interval between hook scans in seconds (default `86400` / 24 hours).\n- `CLAWSEC_SCANNER_TARGET`: Override default scan target path (default: installed skills root).\n- `CLAWSEC_SCANNER_STATE_FILE`: Override state file path for deduplication (default `~/.openclaw/clawsec-scanner-state.json`).\n- `CLAWSEC_INSTALL_ROOT`: Override installed skills root directory.\n\n### CVE Database Integration\n\n- `CLAWSEC_NVD_API_KEY`: NVD API key for rate-limit-free access (without this, 6-second delays apply).\n- `GITHUB_TOKEN`: GitHub OAuth token for GitHub Advisory Database queries (optional enhancement).\n\n### Selective Scanning\n\n- `CLAWSEC_SKIP_DEPENDENCY_SCAN`: Set to `1` to disable dependency scanning (npm audit, pip-audit).\n- `CLAWSEC_SKIP_SAST`: Set to `1` to disable static analysis (Semgrep, Bandit).\n- `CLAWSEC_SKIP_DAST`: Set to `1` to disable dynamic analysis (hook security tests).\n- `CLAWSEC_SKIP_CVE_LOOKUP`: Set to `1` to disable CVE database enrichment.\n\n### Advanced Options\n\n- `CLAWSEC_SCANNER_TIMEOUT`: Maximum scan duration in seconds before timeout (default `300` / 5 minutes).\n- `CLAWSEC_SCANNER_FORMAT`: Output format for findings (`json` or `text`, default `text`).\n- `CLAWSEC_SCANNER_MIN_SEVERITY`: Minimum severity to report (`critical`, `high`, `medium`, `low`, `info`, default `medium`).\n- `CLAWSEC_SCANNER_OUTPUT_FILE`: Optional path to write full scan report JSON (default: conversation only).\n\n## Required Binaries\n\nThe hook requires the following binaries to be available on `PATH`:\n\n- `node` (20+) - JavaScript runtime\n- `npm` - For npm audit execution\n- `python3` (3.10+) - Python runtime\n- `pip-audit` - Python dependency scanner\n- `semgrep` - JavaScript/TypeScript static analysis\n- `bandit` - Python static analysis\n- `jq` - JSON parsing and merging\n- `curl` - API requests (fallback)\n\nMissing binaries will be logged as warnings; available tools will still run.\n\nFile v0.0.4:skill-card.md\n\n## Description: <br>\nAutomated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[davida-ps](https://clawhub.ai/user/davida-ps) <br>\n\n### License/Terms of Use: <br>\nAGPL-3.0-or-later <br>\n\n\n## Use Case: <br>\nDevelopers and security engineers use this skill to scan agent skill directories for dependency, CVE, static-analysis, and hook-inspection findings, then review remediation-oriented reports. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The security review marks the release as suspicious because the optional hook has broad automatic runtime authority and some behavior is under-scoped or inconsistently documented. <br>\nMitigation: Run on-demand scans first, review the hook installer before enabling it, and enable continuous monitoring only in environments where automatic scan messages are expected. <br>\nRisk: The scanner uses subprocesses, filesystem access, and optional external advisory lookups that may use sensitive credentials. <br>\nMitigation: Install only the required scanning tools, provide API tokens only when needed, and keep credentials scoped through environment variables. <br>\nRisk: Automatic hook scans may inspect a broad default target and add findings into normal agent conversations. <br>\nMitigation: Set a narrow CLAWSEC_SCANNER_TARGET, tune CLAWSEC_SCANNER_INTERVAL, and review generated findings before acting on remediation advice. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/davida-ps/clawsec-scanner) <br>\n- [ClawSec homepage](https://clawsec.prompt.security) <br>\n- [ClawSec scanner documentation](https://clawsec.prompt.security/scanner) <br>\n- [OSV API documentation](https://osv.dev/docs/) <br>\n- [NVD vulnerability API documentation](https://nvd.nist.gov/developers/vulnerabilities) <br>\n- [Semgrep registry](https://semgrep.dev/explore) <br>\n- [Bandit documentation](https://bandit.readthedocs.io/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [JSON or text reports with remediation guidance and optional conversation summaries] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Can write reports to a file or post summarized findings when the OpenClaw hook is enabled.] <br>\n\n## Skill Version(s): <br>\n0.0.4 (source: frontmatter, changelog, skill.json) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.0.4:skill.json\n\n{\n  \"name\": \"clawsec-scanner\",\n  \"version\": \"0.0.4\",\n  \"description\": \"Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"keywords\": [\n    \"security\",\n    \"vulnerability\",\n    \"scanner\",\n    \"dependency\",\n    \"cve\",\n    \"sast\",\n    \"dast\",\n    \"audit\",\n    \"agents\",\n    \"ai\",\n    \"openclaw\",\n    \"semgrep\",\n    \"bandit\",\n    \"osv\",\n    \"nvd\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Scanner skill documentation and usage guide\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and feature changelog\"\n      },\n      {\n        \"path\": \"scripts/runner.sh\",\n        \"required\": true,\n        \"description\": \"Main orchestration script for running all scanner engines\"\n      },\n      {\n        \"path\": \"scripts/scan_dependencies.mjs\",\n        \"required\": true,\n        \"description\": \"Dependency scanner using npm audit and pip-audit with JSON parsing\"\n      },\n      {\n        \"path\": \"scripts/query_cve_databases.mjs\",\n        \"required\": true,\n        \"description\": \"Multi-database CVE lookup (OSV primary, NVD/GitHub fallback)\"\n      },\n      {\n        \"path\": \"scripts/sast_analyzer.mjs\",\n        \"required\": true,\n        \"description\": \"Static analysis engine running Semgrep and Bandit as subprocesses\"\n      },\n      {\n        \"path\": \"scripts/dast_runner.mjs\",\n        \"required\": true,\n        \"description\": \"Static OpenClaw hook inspection harness that does not execute target handlers\"\n      },\n      {\n        \"path\": \"scripts/dast_hook_executor.mjs\",\n        \"required\": true,\n        \"description\": \"Static hook source inspection helper used by DAST without importing target handlers\"\n      },\n      {\n        \"path\": \"scripts/setup_scanner_hook.mjs\",\n        \"required\": false,\n        \"description\": \"Hook installer for continuous monitoring integration\"\n      },\n      {\n        \"path\": \"lib/report.mjs\",\n        \"required\": true,\n        \"description\": \"Unified vulnerability report generator (JSON and human-readable formats)\"\n      },\n      {\n        \"path\": \"lib/utils.mjs\",\n        \"required\": true,\n        \"description\": \"Shared utility functions for subprocess execution and JSON parsing\"\n      },\n      {\n        \"path\": \"lib/types.ts\",\n        \"required\": true,\n        \"description\": \"TypeScript type definitions for Vulnerability and ScanReport schemas\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/HOOK.md\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook metadata for continuous scanning integration\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/handler.ts\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook handler for periodic vulnerability scanning\"\n      }\n    ]\n  },\n  \"openclaw\": {\n    \"emoji\": \"🔍\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"node\",\n        \"npm\",\n        \"python3\",\n        \"pip-audit\",\n        \"semgrep\",\n        \"bandit\",\n        \"jq\",\n        \"curl\"\n      ]\n    },\n    \"triggers\": [\n      \"vulnerability scan\",\n      \"security scan\",\n      \"dependency scan\",\n      \"cve scan\",\n      \"sast scan\",\n      \"run scanner\",\n      \"scan vulnerabilities\",\n      \"check vulnerabilities\",\n      \"audit dependencies\",\n      \"security check\"\n    ]\n  }\n}\n\nArchive v0.0.3: 23 files, 57903 bytes\n\nFiles: CHANGELOG.md (1533b), hooks/clawsec-scanner-hook/handler.ts (9541b), hooks/clawsec-scanner-hook/HOOK.md (3676b), lib/report.mjs (8204b), lib/types.ts (923b), lib/utils.mjs (3568b), scripts/dast_hook_executor.mjs (6598b), scripts/dast_runner.mjs (20551b), scripts/query_cve_databases.mjs (8892b), scripts/runner.sh (9574b), scripts/sast_analyzer.mjs (8621b), scripts/scan_dependencies.mjs (10147b), scripts/setup_scanner_hook.mjs (3770b), skill-card.md (2869b), skill.json (3681b), SKILL.md (16423b), test/cve_integration.test.mjs (18916b), test/dast_harness.test.mjs (7159b), test/dependency_scanner.test.mjs (18770b), test/lib/test_harness.mjs (2426b), test/reviewer_regressions.test.mjs (7614b), test/sast_engine.test.mjs (17894b), _meta.json (134b)\n\nFile v0.0.3:SKILL.md\n\n---\nname: clawsec-scanner\nversion: 0.0.3\ndescription: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific DAST hook execution testing for OpenClaw hooks.\nhomepage: https://clawsec.prompt.security\nclawdis:\n  emoji: \"🔍\"\n  requires:\n    bins: [node, npm, python3, pip-audit, semgrep, bandit, jq, curl]\n---\n\n# ClawSec Scanner\n\nComprehensive security scanner for agent platforms that automates vulnerability detection across multiple dimensions:\n\n- **Dependency Scanning**: Analyzes npm and Python dependencies using `npm audit` and `pip-audit` with structured JSON output parsing\n- **CVE Database Integration**: Queries OSV (primary), NVD 2.0, and GitHub Advisory Database for vulnerability enrichment\n- **SAST Analysis**: Static code analysis using Semgrep (JavaScript/TypeScript) and Bandit (Python) to detect hardcoded secrets, command injection, path traversal, and unsafe deserialization\n- **DAST Framework**: Agent-specific dynamic analysis with real OpenClaw hook execution harness (malicious input, timeout, output bounds, event mutation safety)\n- **Unified Reporting**: Consolidated vulnerability reports with severity classification and remediation guidance\n- **Continuous Monitoring**: OpenClaw hook integration for automated periodic scanning\n\n## Features\n\n### Multi-Engine Scanning\n\nThe scanner orchestrates four complementary scan types to provide comprehensive vulnerability coverage:\n\n1. **Dependency Scanning**\n   - Executes `npm audit --json` and `pip-audit -f json` as subprocesses\n   - Parses structured output to extract CVE IDs, severity, affected versions\n   - Handles edge cases: missing package-lock.json, zero vulnerabilities, malformed JSON\n\n2. **CVE Database Queries**\n   - **OSV API** (primary): Free, no authentication, broad ecosystem support (npm, PyPI, Go, Maven)\n   - **NVD 2.0** (optional): Requires API key to avoid 6-second rate limiting\n   - **GitHub Advisory Database** (optional): GraphQL API with OAuth token\n   - Normalizes all API responses to unified `Vulnerability` schema\n\n3. **Static Analysis (SAST)**\n   - **Semgrep** for JavaScript/TypeScript: Detects security issues using `--config auto` or `--config p/security-audit`\n   - **Bandit** for Python: Leverages existing `pyproject.toml` configuration\n   - Identifies: hardcoded secrets (API keys, tokens), command injection (`eval`, `exec`), path traversal, unsafe deserialization\n\n4. **Dynamic Analysis (DAST)**\n   - Real hook execution harness for OpenClaw hook handlers discovered from `HOOK.md` metadata\n   - Verifies: malicious input resilience, timeout behavior, output amplification bounds, and core event mutation safety\n   - Note: Traditional web DAST tools (ZAP, Burp) do not apply to agent platforms - this provides agent-specific testing\n\n### Unified Reporting\n\nAll scan types emit a consistent `ScanReport` JSON schema:\n\n```typescript\n{\n  scan_id: string;         // UUID\n  timestamp: string;       // ISO 8601\n  target: string;          // Scanned path\n  vulnerabilities: Vulnerability[];\n  summary: {\n    critical: number;\n    high: number;\n    medium: number;\n    low: number;\n    info: number;\n  }\n}\n```\n\nEach `Vulnerability` object includes:\n- `id`: CVE-2023-12345 or GHSA-xxxx-yyyy-zzzz\n- `source`: npm-audit | pip-audit | osv | nvd | github | sast | dast\n- `severity`: critical | high | medium | low | info\n- `package`: Package name (or 'N/A' for SAST/DAST)\n- `version`: Affected version\n- `fixed_version`: First version with fix (if available)\n- `title`: Short description\n- `description`: Full advisory text\n- `references`: URLs for more info\n- `discovered_at`: ISO 8601 timestamp\n\n### OpenClaw Integration\n\nAutomated continuous monitoring via hook:\n\n- Runs scanner on configurable interval (default: 86400s / 24 hours)\n- Triggers on `agent:bootstrap` and `command:new` events\n- Posts findings to `event.messages` array with severity summary\n- Rate-limited by `CLAWSEC_SCANNER_INTERVAL` environment variable\n\n## Installation\n\n### Prerequisites\n\nVerify required binaries are available:\n\n```bash\n# Core runtimes\nnode --version  # v20+\nnpm --version\npython3 --version  # 3.10+\n\n# Scanning tools\npip-audit --version  # Install: uv pip install pip-audit\nsemgrep --version    # Install: pip install semgrep OR brew install semgrep\nbandit --version     # Install: uv pip install bandit\n\n# Utilities\njq --version\ncurl --version\n```\n\n### Option A: Via clawhub (recommended)\n\n```bash\nnpx clawhub@latest install clawsec-scanner\n```\n\n### Option B: Manual installation with verification\n\n```bash\nset -euo pipefail\n\nVERSION=\"${SKILL_VERSION:?Set SKILL_VERSION (e.g. 0.1.0)}\"\nINSTALL_ROOT=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}\"\nDEST=\"$INSTALL_ROOT/clawsec-scanner\"\nBASE=\"https://github.com/prompt-security/clawsec/releases/download/clawsec-scanner-v${VERSION}\"\n\nTEMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TEMP_DIR\"' EXIT\n\n# Pinned release-signing public key\n# Fingerprint (SHA-256 of SPKI DER): 711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\ncat > \"$TEMP_DIR/release-signing-public.pem\" <<'PEM'\n-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEAS7nijfMcUoOBCj4yOXJX+GYGv2pFl2Yaha1P4v5Cm6A=\n-----END PUBLIC KEY-----\nPEM\n\nZIP_NAME=\"clawsec-scanner-v${VERSION}.zip\"\n\n# Download release archive + signed checksums\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TEMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TEMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TEMP_DIR/checksums.sig\"\n\n# Verify checksums manifest signature\nopenssl base64 -d -A -in \"$TEMP_DIR/checksums.sig\" -out \"$TEMP_DIR/checksums.sig.bin\"\nif ! openssl pkeyutl -verify \\\n  -pubin \\\n  -inkey \"$TEMP_DIR/release-signing-public.pem\" \\\n  -sigfile \"$TEMP_DIR/checksums.sig.bin\" \\\n  -rawin \\\n  -in \"$TEMP_DIR/checksums.json\" >/dev/null 2>&1; then\n  echo \"ERROR: checksums.json signature verification failed\" >&2\n  exit 1\nfi\n\nEXPECTED_SHA=\"$(jq -r '.archive.sha256 // empty' \"$TEMP_DIR/checksums.json\")\"\nif [ -z \"$EXPECTED_SHA\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\n\nACTUAL_SHA=\"$(shasum -a 256 \"$TEMP_DIR/$ZIP_NAME\" | awk '{print $1}')\"\nif [ \"$EXPECTED_SHA\" != \"$ACTUAL_SHA\" ]; then\n  echo \"ERROR: Archive checksum mismatch\" >&2\n  exit 1\nfi\n\necho \"Checksums verified. Installing...\"\n\nmkdir -p \"$INSTALL_ROOT\"\nrm -rf \"$DEST\"\nunzip -q \"$TEMP_DIR/$ZIP_NAME\" -d \"$INSTALL_ROOT\"\n\nchmod 600 \"$DEST/skill.json\"\nfind \"$DEST\" -type f ! -name \"skill.json\" -exec chmod 644 {} \\;\n\necho \"Installed clawsec-scanner v${VERSION} to: $DEST\"\necho \"Next step: Run a scan or set up continuous monitoring\"\n```\n\n## Usage\n\n### On-Demand CLI Scanning\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\n\n# Scan all skills with JSON output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./skills/ --output report.json --format json\n\n# Scan specific directory with human-readable output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./my-skill/ --format text\n\n# Check available flags\n\"$SCANNER_DIR/scripts/runner.sh\" --help\n```\n\n**CLI Flags:**\n- `--target <path>`: Directory to scan (required)\n- `--output <file>`: Write results to file (optional, defaults to stdout)\n- `--format <json|text>`: Output format (default: json)\n- `--check`: Verify all required binaries are installed\n\n### OpenClaw Hook Setup (Continuous Monitoring)\n\nEnable automated periodic scanning:\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\nnode \"$SCANNER_DIR/scripts/setup_scanner_hook.mjs\"\n```\n\nThis creates a hook that:\n- Scans on `agent:bootstrap` and `command:new` events\n- Respects `CLAWSEC_SCANNER_INTERVAL` rate limiting (default: 86400 seconds / 24 hours)\n- Posts findings to conversation with severity summary\n- Recommends remediation for high/critical vulnerabilities\n\nRestart the OpenClaw gateway after enabling the hook, then run `/new` to trigger an immediate scan.\n\n### Environment Variables\n\n```bash\n# Optional - NVD API key to avoid rate limiting (6-second delays without key)\nexport CLAWSEC_NVD_API_KEY=\"your-nvd-api-key\"\n\n# Optional - GitHub OAuth token for Advisory Database queries\nexport GITHUB_TOKEN=\"ghp_your_token_here\"\n\n# Optional - Scanner hook interval in seconds (default: 86400 / 24 hours)\nexport CLAWSEC_SCANNER_INTERVAL=\"86400\"\n\n# Optional - Allow unsigned advisory feed during development (from clawsec-suite)\nexport CLAWSEC_ALLOW_UNSIGNED_FEED=\"1\"\n```\n\n## Architecture\n\n### Modular Design\n\nEach scan type is an independent module that can run standalone or as part of unified scan:\n\n```\nscripts/runner.sh              # Orchestration layer\n├── scan_dependencies.mjs      # npm audit + pip-audit\n├── query_cve_databases.mjs    # OSV/NVD/GitHub API queries\n├── sast_analyzer.mjs          # Semgrep + Bandit static analysis\n├── dast_runner.mjs            # Dynamic security testing orchestration\n└── dast_hook_executor.mjs     # Isolated real hook execution harness\n\nlib/\n├── report.mjs                 # Result aggregation and formatting\n├── utils.mjs                  # Subprocess exec, JSON parsing, error handling\n└── types.ts                   # TypeScript schema definitions\n\nhooks/clawsec-scanner-hook/\n├── HOOK.md                    # OpenClaw hook metadata\n└── handler.ts                 # Periodic scan trigger\n```\n\n### Fail-Open Philosophy\n\nThe scanner prioritizes availability over strict failure propagation:\n\n- Network failures → emit partial results, log warnings\n- Missing tools → skip that scan type, continue with others\n- Malformed JSON → parse what's valid, log errors\n- API rate limits → implement exponential backoff, fallback to other sources\n- Zero vulnerabilities → emit success report with empty array\n\n**Critical failures** that exit immediately:\n- Target path does not exist\n- No scanning tools available (all bins missing)\n- Concurrent scan detected (lockfile present)\n\n### Subprocess Execution Pattern\n\nAll external tools run as subprocesses with structured JSON output:\n\n```javascript\nimport { spawn } from 'node:child_process';\n\n// Example: npm audit execution\nconst proc = spawn('npm', ['audit', '--json'], {\n  cwd: targetPath,\n  stdio: ['ignore', 'pipe', 'pipe']\n});\n\n// Handle non-zero exit codes gracefully\n// npm audit exits 1 when vulnerabilities found (not an error!)\nproc.on('close', code => {\n  if (code !== 0 && stderr.includes('ERR!')) {\n    // Actual error\n    reject(new Error(stderr));\n  } else {\n    // Vulnerabilities found or success\n    resolve(JSON.parse(stdout));\n  }\n});\n```\n\n## Troubleshooting\n\n### Common Issues\n\n**\"Missing package-lock.json\" warning**\n- `npm audit` requires lockfile to run\n- Run `npm install` in target directory to generate\n- Scanner continues with other scan types if npm audit fails\n\n**\"NVD API rate limit exceeded\"**\n- Set `CLAWSEC_NVD_API_KEY` environment variable\n- Without API key: 6-second delays enforced between requests\n- OSV API used as primary source (no rate limits)\n\n**\"pip-audit not found\"**\n- Install: `uv pip install pip-audit` or `pip install pip-audit`\n- Verify: `which pip-audit`\n- Add to PATH if installed in non-standard location\n\n**\"Semgrep binary missing\"**\n- Install: `pip install semgrep` OR `brew install semgrep`\n- Requires Python 3.8+ runtime\n- Alternative: use Docker image `returntocorp/semgrep`\n\n**\"TypeScript hook not executable in DAST harness\"**\n- The DAST harness executes real hook handlers and transpiles `handler.ts` files when a TypeScript compiler is available\n- Install TypeScript in the scanner environment: `npm install -D typescript` (or provide `handler.js`/`handler.mjs`)\n- Without a compiler, scanner reports an `info`-level coverage finding instead of a high-severity vulnerability\n\n**\"Concurrent scan detected\"**\n- Lockfile exists: `/tmp/clawsec-scanner.lock`\n- Wait for running scan to complete or manually remove lockfile\n- Prevents overlapping scans that could produce inconsistent results\n\n### Verification\n\nCheck scanner is working correctly:\n\n```bash\n# Verify required binaries\n./scripts/runner.sh --check\n\n# Run unit tests\nnode test/dependency_scanner.test.mjs\nnode test/cve_integration.test.mjs\nnode test/sast_engine.test.mjs\nnode test/dast_harness.test.mjs\n\n# Validate skill structure\npython ../../utils/validate_skill.py .\n\n# Scan test fixtures (should detect known vulnerabilities)\n./scripts/runner.sh --target test/fixtures/ --format text\n```\n\n## Development\n\n### Running Tests\n\n```bash\n# All tests (vanilla Node.js, no framework)\nfor test in test/*.test.mjs; do\n  node \"$test\" || exit 1\ndone\n\n# Individual test suites\nnode test/dependency_scanner.test.mjs  # Dependency scanning\nnode test/cve_integration.test.mjs     # CVE database APIs\nnode test/sast_engine.test.mjs         # Static analysis\nnode test/dast_harness.test.mjs        # DAST harness execution\n```\n\n### Linting\n\n```bash\n# JavaScript/TypeScript\nnpx eslint . --ext .ts,.tsx,.js,.jsx,.mjs --max-warnings 0\n\n# Python (Bandit already configured in pyproject.toml)\nruff check .\nbandit -r . -ll\n\n# Shell scripts\nshellcheck scripts/*.sh\n```\n\n### Adding Custom Semgrep Rules\n\nCreate custom rules in `.semgrep/rules/`:\n\n```yaml\nrules:\n  - id: custom-security-rule\n    pattern: dangerous_function($ARG)\n    message: Avoid dangerous_function - use safe_alternative instead\n    severity: WARNING\n    languages: [javascript, typescript]\n```\n\nUpdate `scripts/sast_analyzer.mjs` to include custom rules:\n\n```javascript\nconst proc = spawn('semgrep', [\n  'scan',\n  '--config', 'auto',\n  '--config', '.semgrep/rules/',  // Add custom rules\n  '--json',\n  targetPath\n]);\n```\n\n## Integration with ClawSec Suite\n\nThe scanner works standalone or as part of the ClawSec ecosystem:\n\n- **clawsec-suite**: Meta-skill that can install and manage clawsec-scanner\n- **clawsec-feed**: Advisory feed for malicious skill detection (complementary)\n- **openclaw-audit-watchdog**: Cron-based audit automation (similar pattern)\n\nInstall the full ClawSec suite:\n\n```bash\nnpx clawhub@latest install clawsec-suite\n# Then use clawsec-suite to discover and install clawsec-scanner\n```\n\n## Security Considerations\n\n### Scanner Security\n\n- No hardcoded secrets in scanner code\n- API keys read from environment variables only (never logged or committed)\n- Subprocess arguments use arrays to prevent shell injection\n- All external tool output parsed with try/catch error handling\n\n### Vulnerability Prioritization\n\n**Critical/High severity findings** should be addressed immediately:\n- Known exploits in dependencies (CVSS 9.0+)\n- Hardcoded API keys or credentials in code\n- Command injection vulnerabilities\n- Path traversal without validation\n\n**Medium/Low severity findings** can be addressed in normal sprint cycles:\n- Outdated dependencies without known exploits\n- Missing security headers\n- Weak cryptography usage\n\n**Info findings** are advisory only:\n- Deprecated API usage\n- Code quality issues flagged by linters\n\n## Roadmap\n\n### v0.0.2 (Current)\n- [x] Dependency scanning (npm audit, pip-audit)\n- [x] CVE database integration (OSV, NVD, GitHub Advisory)\n- [x] SAST analysis (Semgrep, Bandit)\n- [x] Real OpenClaw hook execution harness for DAST\n- [x] Unified JSON reporting\n- [x] OpenClaw hook integration\n\n### Future Enhancements\n- [ ] Automatic remediation (dependency upgrades, code fixes)\n- [ ] SARIF output format for GitHub Code Scanning integration\n- [ ] Web dashboard for vulnerability tracking over time\n- [ ] CI/CD GitHub Action for PR blocking on high-severity findings\n- [ ] Container image scanning (Docker, OCI)\n- [ ] Infrastructure-as-Code scanning (Terraform, CloudFormation)\n- [ ] Comprehensive agent workflow DAST (requires deeper platform integration)\n\n## Contributing\n\nFound a security issue? Please report privately to security@prompt.security.\n\nFor feature requests and bug reports, open an issue at:\nhttps://github.com/prompt-security/clawsec/issues\n\n## License\n\nAGPL-3.0-or-later\n\nSee LICENSE file in repository root for full text.\n\n## Resources\n\n- **ClawSec Homepage**: https://clawsec.prompt.security\n- **Documentation**: https://clawsec.prompt.security/scanner\n- **GitHub Repository**: https://github.com/prompt-security/clawsec\n- **OSV API Docs**: https://osv.dev/docs/\n- **NVD API Docs**: https://nvd.nist.gov/developers/vulnerabilities\n- **Semgrep Registry**: https://semgrep.dev/explore\n- **Bandit Documentation**: https://bandit.readthedocs.io/\n\nFile v0.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-scanner\",\n  \"version\": \"0.0.3\",\n  \"publishedAt\": 1778758982259\n}\n\nFile v0.0.3:CHANGELOG.md\n\n# Changelog\n\n## [0.0.3] - 2026-05-13\n\n### Changed\n- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.\n\nAll notable changes to the ClawSec Scanner will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.0.2] - 2026-03-10\n\n### Changed\n\n- Replaced simulated DAST checks with real OpenClaw hook execution harness testing\n- Updated DAST semantics so high-severity findings are emitted for actual hook execution failures/timeouts, not static payload pattern matches\n- Reclassified DAST harness capability limitations (for example missing TypeScript compiler for `.ts` hooks) to `info` coverage findings instead of high severity\n- Added DAST harness mode guard to prevent recursive scanner execution when hook handlers are tested in isolation\n\n### Added\n\n- New DAST helper executor script for isolated per-hook execution and timeout enforcement\n- DAST harness regression tests covering no-false-positive baseline and malicious-input crash detection\n\n## [0.0.1] - 2026-02-27\n\n### Added\n\n- Initial release of ClawSec Scanner skill\n- Automated vulnerability scanning for OpenClaw skill installations\n- Integration with advisory feed for real-time security alerts\n- Support for scanning skill dependencies and detecting known CVEs\n- Configurable scan policies and risk thresholds\n- Detailed vulnerability reporting with remediation guidance\n\nFile v0.0.3:hooks/clawsec-scanner-hook/HOOK.md\n\n---\nname: clawsec-scanner-hook\ndescription: Periodic vulnerability scanning for installed skills and dependencies with configurable scan intervals.\nmetadata: { \"openclaw\": { \"events\": [\"agent:bootstrap\", \"command:new\"] } }\n---\n\n# ClawSec Scanner Hook\n\nThis hook performs comprehensive vulnerability scanning on installed skills and their dependencies on:\n\n- `agent:bootstrap`\n- `command:new`\n\nWhen triggered, it runs all configured scanning engines (dependency scan, SAST, DAST, CVE database lookup) and posts findings as conversation messages. Scans are rate-limited by configurable interval to avoid performance impact.\n\n## Scanning Capabilities\n\nThe hook orchestrates four independent scanning engines:\n\n1. **Dependency Scanning**: Executes `npm audit` and `pip-audit` to detect known vulnerabilities in JavaScript and Python dependencies\n2. **SAST (Static Analysis)**: Runs Semgrep (JS/TS) and Bandit (Python) to detect security issues like hardcoded secrets, command injection, and path traversal\n3. **CVE Database Lookup**: Queries OSV API (primary), NVD 2.0 (optional), and GitHub Advisory Database (optional) for vulnerability enrichment\n4. **DAST (Dynamic Analysis)**: Executes real OpenClaw hook handlers in an isolated harness and tests malicious-input resilience, timeout behavior, output bounds, and event mutation safety\n\n## Safety Contract\n\n- The hook does not modify or delete skills.\n- It only reports findings and provides remediation guidance.\n- Scanning is non-blocking and runs on a configurable interval (default 24 hours).\n- Failed scans (network errors, missing tools) produce warnings but do not block execution.\n- Findings are deduplicated to avoid alert fatigue.\n\n## Optional Environment Variables\n\n### Core Configuration\n\n- `CLAWSEC_SCANNER_INTERVAL`: Minimum interval between hook scans in seconds (default `86400` / 24 hours).\n- `CLAWSEC_SCANNER_TARGET`: Override default scan target path (default: installed skills root).\n- `CLAWSEC_SCANNER_STATE_FILE`: Override state file path for deduplication (default `~/.openclaw/clawsec-scanner-state.json`).\n- `CLAWSEC_INSTALL_ROOT`: Override installed skills root directory.\n\n### CVE Database Integration\n\n- `CLAWSEC_NVD_API_KEY`: NVD API key for rate-limit-free access (without this, 6-second delays apply).\n- `GITHUB_TOKEN`: GitHub OAuth token for GitHub Advisory Database queries (optional enhancement).\n\n### Selective Scanning\n\n- `CLAWSEC_SKIP_DEPENDENCY_SCAN`: Set to `1` to disable dependency scanning (npm audit, pip-audit).\n- `CLAWSEC_SKIP_SAST`: Set to `1` to disable static analysis (Semgrep, Bandit).\n- `CLAWSEC_SKIP_DAST`: Set to `1` to disable dynamic analysis (hook security tests).\n- `CLAWSEC_SKIP_CVE_LOOKUP`: Set to `1` to disable CVE database enrichment.\n\n### Advanced Options\n\n- `CLAWSEC_SCANNER_TIMEOUT`: Maximum scan duration in seconds before timeout (default `300` / 5 minutes).\n- `CLAWSEC_SCANNER_FORMAT`: Output format for findings (`json` or `text`, default `text`).\n- `CLAWSEC_SCANNER_MIN_SEVERITY`: Minimum severity to report (`critical`, `high`, `medium`, `low`, `info`, default `medium`).\n- `CLAWSEC_SCANNER_OUTPUT_FILE`: Optional path to write full scan report JSON (default: conversation only).\n\n## Required Binaries\n\nThe hook requires the following binaries to be available on `PATH`:\n\n- `node` (20+) - JavaScript runtime\n- `npm` - For npm audit execution\n- `python3` (3.10+) - Python runtime\n- `pip-audit` - Python dependency scanner\n- `semgrep` - JavaScript/TypeScript static analysis\n- `bandit` - Python static analysis\n- `jq` - JSON parsing and merging\n- `curl` - API requests (fallback)\n\nMissing binaries will be logged as warnings; available tools will still run.\n\nFile v0.0.3:skill-card.md\n\n## Description: <br>\nAutomated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific DAST hook execution testing for OpenClaw hooks. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[davida-ps](https://clawhub.ai/user/davida-ps) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill to scan agent skill directories and dependencies for known vulnerabilities, static-analysis findings, and OpenClaw hook behavior risks. It can run on demand or through an OpenClaw hook for periodic monitoring. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: DAST and hook scanning can execute scanned hook code with broad local environment access. <br>\nMitigation: Run scans in an isolated environment with secrets removed, and avoid DAST scans for untrusted skills unless that isolation is in place. <br>\nRisk: Continuous monitoring hook setup persists and can trigger automatic scans. <br>\nMitigation: Review the hook configuration, scan target, and scan interval before enabling it, and disable the hook when ongoing monitoring is not intended. <br>\nRisk: Optional GitHub and NVD credentials may be used to enrich vulnerability data. <br>\nMitigation: Use scoped credentials through environment variables and do not include tokens in reports or shared logs. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/davida-ps/clawsec-scanner) <br>\n- [ClawSec homepage](https://clawsec.prompt.security) <br>\n- [ClawSec scanner documentation](https://clawsec.prompt.security/scanner) <br>\n- [OSV API documentation](https://osv.dev/docs/) <br>\n- [NVD API documentation](https://nvd.nist.gov/developers/vulnerabilities) <br>\n- [Semgrep Registry](https://semgrep.dev/explore) <br>\n- [Bandit documentation](https://bandit.readthedocs.io/) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, json, shell commands, configuration, guidance] <br>\n**Output Format:** [JSON and human-readable text reports, plus Markdown guidance with shell commands.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May require local scanner binaries and optional NVD or GitHub credentials; hook mode can post scan findings into conversation messages.] <br>\n\n## Skill Version(s): <br>\n0.0.3 (source: server release metadata and SKILL.md frontmatter; changelog released 2026-05-13) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.0.3:skill.json\n\n{\n  \"name\": \"clawsec-scanner\",\n  \"version\": \"0.0.3\",\n  \"description\": \"Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific DAST hook execution testing for OpenClaw hooks.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"keywords\": [\n    \"security\",\n    \"vulnerability\",\n    \"scanner\",\n    \"dependency\",\n    \"cve\",\n    \"sast\",\n    \"dast\",\n    \"audit\",\n    \"agents\",\n    \"ai\",\n    \"openclaw\",\n    \"semgrep\",\n    \"bandit\",\n    \"osv\",\n    \"nvd\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Scanner skill documentation and usage guide\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and feature changelog\"\n      },\n      {\n        \"path\": \"scripts/runner.sh\",\n        \"required\": true,\n        \"description\": \"Main orchestration script for running all scanner engines\"\n      },\n      {\n        \"path\": \"scripts/scan_dependencies.mjs\",\n        \"required\": true,\n        \"description\": \"Dependency scanner using npm audit and pip-audit with JSON parsing\"\n      },\n      {\n        \"path\": \"scripts/query_cve_databases.mjs\",\n        \"required\": true,\n        \"description\": \"Multi-database CVE lookup (OSV primary, NVD/GitHub fallback)\"\n      },\n      {\n        \"path\": \"scripts/sast_analyzer.mjs\",\n        \"required\": true,\n        \"description\": \"Static analysis engine running Semgrep and Bandit as subprocesses\"\n      },\n      {\n        \"path\": \"scripts/dast_runner.mjs\",\n        \"required\": true,\n        \"description\": \"Dynamic analysis harness executing OpenClaw hook handlers with malicious-input and timeout checks\"\n      },\n      {\n        \"path\": \"scripts/dast_hook_executor.mjs\",\n        \"required\": true,\n        \"description\": \"Isolated hook execution helper used by DAST for real OpenClaw harness testing\"\n      },\n      {\n        \"path\": \"scripts/setup_scanner_hook.mjs\",\n        \"required\": false,\n        \"description\": \"Hook installer for continuous monitoring integration\"\n      },\n      {\n        \"path\": \"lib/report.mjs\",\n        \"required\": true,\n        \"description\": \"Unified vulnerability report generator (JSON and human-readable formats)\"\n      },\n      {\n        \"path\": \"lib/utils.mjs\",\n        \"required\": true,\n        \"description\": \"Shared utility functions for subprocess execution and JSON parsing\"\n      },\n      {\n        \"path\": \"lib/types.ts\",\n        \"required\": true,\n        \"description\": \"TypeScript type definitions for Vulnerability and ScanReport schemas\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/HOOK.md\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook metadata for continuous scanning integration\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/handler.ts\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook handler for periodic vulnerability scanning\"\n      }\n    ]\n  },\n  \"openclaw\": {\n    \"emoji\": \"🔍\",\n    \"category\": \"security\",\n    \"requires\": {\n      \"bins\": [\n        \"node\",\n        \"npm\",\n        \"python3\",\n        \"pip-audit\",\n        \"semgrep\",\n        \"bandit\",\n        \"jq\",\n        \"curl\"\n      ]\n    },\n    \"triggers\": [\n      \"vulnerability scan\",\n      \"security scan\",\n      \"dependency scan\",\n      \"cve scan\",\n      \"sast scan\",\n      \"run scanner\",\n      \"scan vulnerabilities\",\n      \"check vulnerabilities\",\n      \"audit dependencies\",\n      \"security check\"\n    ]\n  }\n}\n\nArchive v0.0.2: 22 files, 56476 bytes\n\nFiles: CHANGELOG.md (1394b), hooks/clawsec-scanner-hook/handler.ts (9541b), hooks/clawsec-scanner-hook/HOOK.md (3676b), lib/report.mjs (8204b), lib/types.ts (923b), lib/utils.mjs (3568b), scripts/dast_hook_executor.mjs (6598b), scripts/dast_runner.mjs (20551b), scripts/query_cve_databases.mjs (8892b), scripts/runner.sh (9574b), scripts/sast_analyzer.mjs (8621b), scripts/scan_dependencies.mjs (10147b), scripts/setup_scanner_hook.mjs (3770b), skill.json (4382b), SKILL.md (16423b), test/cve_integration.test.mjs (18916b), test/dast_harness.test.mjs (7159b), test/dependency_scanner.test.mjs (18770b), test/lib/test_harness.mjs (2426b), test/reviewer_regressions.test.mjs (7614b), test/sast_engine.test.mjs (17894b), _meta.json (134b)\n\nFile v0.0.2:SKILL.md\n\n---\nname: clawsec-scanner\nversion: 0.0.2\ndescription: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific DAST hook execution testing for OpenClaw hooks.\nhomepage: https://clawsec.prompt.security\nclawdis:\n  emoji: \"🔍\"\n  requires:\n    bins: [node, npm, python3, pip-audit, semgrep, bandit, jq, curl]\n---\n\n# ClawSec Scanner\n\nComprehensive security scanner for agent platforms that automates vulnerability detection across multiple dimensions:\n\n- **Dependency Scanning**: Analyzes npm and Python dependencies using `npm audit` and `pip-audit` with structured JSON output parsing\n- **CVE Database Integration**: Queries OSV (primary), NVD 2.0, and GitHub Advisory Database for vulnerability enrichment\n- **SAST Analysis**: Static code analysis using Semgrep (JavaScript/TypeScript) and Bandit (Python) to detect hardcoded secrets, command injection, path traversal, and unsafe deserialization\n- **DAST Framework**: Agent-specific dynamic analysis with real OpenClaw hook execution harness (malicious input, timeout, output bounds, event mutation safety)\n- **Unified Reporting**: Consolidated vulnerability reports with severity classification and remediation guidance\n- **Continuous Monitoring**: OpenClaw hook integration for automated periodic scanning\n\n## Features\n\n### Multi-Engine Scanning\n\nThe scanner orchestrates four complementary scan types to provide comprehensive vulnerability coverage:\n\n1. **Dependency Scanning**\n   - Executes `npm audit --json` and `pip-audit -f json` as subprocesses\n   - Parses structured output to extract CVE IDs, severity, affected versions\n   - Handles edge cases: missing package-lock.json, zero vulnerabilities, malformed JSON\n\n2. **CVE Database Queries**\n   - **OSV API** (primary): Free, no authentication, broad ecosystem support (npm, PyPI, Go, Maven)\n   - **NVD 2.0** (optional): Requires API key to avoid 6-second rate limiting\n   - **GitHub Advisory Database** (optional): GraphQL API with OAuth token\n   - Normalizes all API responses to unified `Vulnerability` schema\n\n3. **Static Analysis (SAST)**\n   - **Semgrep** for JavaScript/TypeScript: Detects security issues using `--config auto` or `--config p/security-audit`\n   - **Bandit** for Python: Leverages existing `pyproject.toml` configuration\n   - Identifies: hardcoded secrets (API keys, tokens), command injection (`eval`, `exec`), path traversal, unsafe deserialization\n\n4. **Dynamic Analysis (DAST)**\n   - Real hook execution harness for OpenClaw hook handlers discovered from `HOOK.md` metadata\n   - Verifies: malicious input resilience, timeout behavior, output amplification bounds, and core event mutation safety\n   - Note: Traditional web DAST tools (ZAP, Burp) do not apply to agent platforms - this provides agent-specific testing\n\n### Unified Reporting\n\nAll scan types emit a consistent `ScanReport` JSON schema:\n\n```typescript\n{\n  scan_id: string;         // UUID\n  timestamp: string;       // ISO 8601\n  target: string;          // Scanned path\n  vulnerabilities: Vulnerability[];\n  summary: {\n    critical: number;\n    high: number;\n    medium: number;\n    low: number;\n    info: number;\n  }\n}\n```\n\nEach `Vulnerability` object includes:\n- `id`: CVE-2023-12345 or GHSA-xxxx-yyyy-zzzz\n- `source`: npm-audit | pip-audit | osv | nvd | github | sast | dast\n- `severity`: critical | high | medium | low | info\n- `package`: Package name (or 'N/A' for SAST/DAST)\n- `version`: Affected version\n- `fixed_version`: First version with fix (if available)\n- `title`: Short description\n- `description`: Full advisory text\n- `references`: URLs for more info\n- `discovered_at`: ISO 8601 timestamp\n\n### OpenClaw Integration\n\nAutomated continuous monitoring via hook:\n\n- Runs scanner on configurable interval (default: 86400s / 24 hours)\n- Triggers on `agent:bootstrap` and `command:new` events\n- Posts findings to `event.messages` array with severity summary\n- Rate-limited by `CLAWSEC_SCANNER_INTERVAL` environment variable\n\n## Installation\n\n### Prerequisites\n\nVerify required binaries are available:\n\n```bash\n# Core runtimes\nnode --version  # v20+\nnpm --version\npython3 --version  # 3.10+\n\n# Scanning tools\npip-audit --version  # Install: uv pip install pip-audit\nsemgrep --version    # Install: pip install semgrep OR brew install semgrep\nbandit --version     # Install: uv pip install bandit\n\n# Utilities\njq --version\ncurl --version\n```\n\n### Option A: Via clawhub (recommended)\n\n```bash\nnpx clawhub@latest install clawsec-scanner\n```\n\n### Option B: Manual installation with verification\n\n```bash\nset -euo pipefail\n\nVERSION=\"${SKILL_VERSION:?Set SKILL_VERSION (e.g. 0.1.0)}\"\nINSTALL_ROOT=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}\"\nDEST=\"$INSTALL_ROOT/clawsec-scanner\"\nBASE=\"https://github.com/prompt-security/clawsec/releases/download/clawsec-scanner-v${VERSION}\"\n\nTEMP_DIR=\"$(mktemp -d)\"\ntrap 'rm -rf \"$TEMP_DIR\"' EXIT\n\n# Pinned release-signing public key\n# Fingerprint (SHA-256 of SPKI DER): 711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8\ncat > \"$TEMP_DIR/release-signing-public.pem\" <<'PEM'\n-----BEGIN PUBLIC KEY-----\nMCowBQYDK2VwAyEAS7nijfMcUoOBCj4yOXJX+GYGv2pFl2Yaha1P4v5Cm6A=\n-----END PUBLIC KEY-----\nPEM\n\nZIP_NAME=\"clawsec-scanner-v${VERSION}.zip\"\n\n# Download release archive + signed checksums\ncurl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TEMP_DIR/$ZIP_NAME\"\ncurl -fsSL \"$BASE/checksums.json\" -o \"$TEMP_DIR/checksums.json\"\ncurl -fsSL \"$BASE/checksums.sig\" -o \"$TEMP_DIR/checksums.sig\"\n\n# Verify checksums manifest signature\nopenssl base64 -d -A -in \"$TEMP_DIR/checksums.sig\" -out \"$TEMP_DIR/checksums.sig.bin\"\nif ! openssl pkeyutl -verify \\\n  -pubin \\\n  -inkey \"$TEMP_DIR/release-signing-public.pem\" \\\n  -sigfile \"$TEMP_DIR/checksums.sig.bin\" \\\n  -rawin \\\n  -in \"$TEMP_DIR/checksums.json\" >/dev/null 2>&1; then\n  echo \"ERROR: checksums.json signature verification failed\" >&2\n  exit 1\nfi\n\nEXPECTED_SHA=\"$(jq -r '.archive.sha256 // empty' \"$TEMP_DIR/checksums.json\")\"\nif [ -z \"$EXPECTED_SHA\" ]; then\n  echo \"ERROR: checksums.json missing archive.sha256\" >&2\n  exit 1\nfi\n\nACTUAL_SHA=\"$(shasum -a 256 \"$TEMP_DIR/$ZIP_NAME\" | awk '{print $1}')\"\nif [ \"$EXPECTED_SHA\" != \"$ACTUAL_SHA\" ]; then\n  echo \"ERROR: Archive checksum mismatch\" >&2\n  exit 1\nfi\n\necho \"Checksums verified. Installing...\"\n\nmkdir -p \"$INSTALL_ROOT\"\nrm -rf \"$DEST\"\nunzip -q \"$TEMP_DIR/$ZIP_NAME\" -d \"$INSTALL_ROOT\"\n\nchmod 600 \"$DEST/skill.json\"\nfind \"$DEST\" -type f ! -name \"skill.json\" -exec chmod 644 {} \\;\n\necho \"Installed clawsec-scanner v${VERSION} to: $DEST\"\necho \"Next step: Run a scan or set up continuous monitoring\"\n```\n\n## Usage\n\n### On-Demand CLI Scanning\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\n\n# Scan all skills with JSON output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./skills/ --output report.json --format json\n\n# Scan specific directory with human-readable output\n\"$SCANNER_DIR/scripts/runner.sh\" --target ./my-skill/ --format text\n\n# Check available flags\n\"$SCANNER_DIR/scripts/runner.sh\" --help\n```\n\n**CLI Flags:**\n- `--target <path>`: Directory to scan (required)\n- `--output <file>`: Write results to file (optional, defaults to stdout)\n- `--format <json|text>`: Output format (default: json)\n- `--check`: Verify all required binaries are installed\n\n### OpenClaw Hook Setup (Continuous Monitoring)\n\nEnable automated periodic scanning:\n\n```bash\nSCANNER_DIR=\"${INSTALL_ROOT:-$HOME/.openclaw/skills}/clawsec-scanner\"\nnode \"$SCANNER_DIR/scripts/setup_scanner_hook.mjs\"\n```\n\nThis creates a hook that:\n- Scans on `agent:bootstrap` and `command:new` events\n- Respects `CLAWSEC_SCANNER_INTERVAL` rate limiting (default: 86400 seconds / 24 hours)\n- Posts findings to conversation with severity summary\n- Recommends remediation for high/critical vulnerabilities\n\nRestart the OpenClaw gateway after enabling the hook, then run `/new` to trigger an immediate scan.\n\n### Environment Variables\n\n```bash\n# Optional - NVD API key to avoid rate limiting (6-second delays without key)\nexport CLAWSEC_NVD_API_KEY=\"your-nvd-api-key\"\n\n# Optional - GitHub OAuth token for Advisory Database queries\nexport GITHUB_TOKEN=\"ghp_your_token_here\"\n\n# Optional - Scanner hook interval in seconds (default: 86400 / 24 hours)\nexport CLAWSEC_SCANNER_INTERVAL=\"86400\"\n\n# Optional - Allow unsigned advisory feed during development (from clawsec-suite)\nexport CLAWSEC_ALLOW_UNSIGNED_FEED=\"1\"\n```\n\n## Architecture\n\n### Modular Design\n\nEach scan type is an independent module that can run standalone or as part of unified scan:\n\n```\nscripts/runner.sh              # Orchestration layer\n├── scan_dependencies.mjs      # npm audit + pip-audit\n├── query_cve_databases.mjs    # OSV/NVD/GitHub API queries\n├── sast_analyzer.mjs          # Semgrep + Bandit static analysis\n├── dast_runner.mjs            # Dynamic security testing orchestration\n└── dast_hook_executor.mjs     # Isolated real hook execution harness\n\nlib/\n├── report.mjs                 # Result aggregation and formatting\n├── utils.mjs                  # Subprocess exec, JSON parsing, error handling\n└── types.ts                   # TypeScript schema definitions\n\nhooks/clawsec-scanner-hook/\n├── HOOK.md                    # OpenClaw hook metadata\n└── handler.ts                 # Periodic scan trigger\n```\n\n### Fail-Open Philosophy\n\nThe scanner prioritizes availability over strict failure propagation:\n\n- Network failures → emit partial results, log warnings\n- Missing tools → skip that scan type, continue with others\n- Malformed JSON → parse what's valid, log errors\n- API rate limits → implement exponential backoff, fallback to other sources\n- Zero vulnerabilities → emit success report with empty array\n\n**Critical failures** that exit immediately:\n- Target path does not exist\n- No scanning tools available (all bins missing)\n- Concurrent scan detected (lockfile present)\n\n### Subprocess Execution Pattern\n\nAll external tools run as subprocesses with structured JSON output:\n\n```javascript\nimport { spawn } from 'node:child_process';\n\n// Example: npm audit execution\nconst proc = spawn('npm', ['audit', '--json'], {\n  cwd: targetPath,\n  stdio: ['ignore', 'pipe', 'pipe']\n});\n\n// Handle non-zero exit codes gracefully\n// npm audit exits 1 when vulnerabilities found (not an error!)\nproc.on('close', code => {\n  if (code !== 0 && stderr.includes('ERR!')) {\n    // Actual error\n    reject(new Error(stderr));\n  } else {\n    // Vulnerabilities found or success\n    resolve(JSON.parse(stdout));\n  }\n});\n```\n\n## Troubleshooting\n\n### Common Issues\n\n**\"Missing package-lock.json\" warning**\n- `npm audit` requires lockfile to run\n- Run `npm install` in target directory to generate\n- Scanner continues with other scan types if npm audit fails\n\n**\"NVD API rate limit exceeded\"**\n- Set `CLAWSEC_NVD_API_KEY` environment variable\n- Without API key: 6-second delays enforced between requests\n- OSV API used as primary source (no rate limits)\n\n**\"pip-audit not found\"**\n- Install: `uv pip install pip-audit` or `pip install pip-audit`\n- Verify: `which pip-audit`\n- Add to PATH if installed in non-standard location\n\n**\"Semgrep binary missing\"**\n- Install: `pip install semgrep` OR `brew install semgrep`\n- Requires Python 3.8+ runtime\n- Alternative: use Docker image `returntocorp/semgrep`\n\n**\"TypeScript hook not executable in DAST harness\"**\n- The DAST harness executes real hook handlers and transpiles `handler.ts` files when a TypeScript compiler is available\n- Install TypeScript in the scanner environment: `npm install -D typescript` (or provide `handler.js`/`handler.mjs`)\n- Without a compiler, scanner reports an `info`-level coverage finding instead of a high-severity vulnerability\n\n**\"Concurrent scan detected\"**\n- Lockfile exists: `/tmp/clawsec-scanner.lock`\n- Wait for running scan to complete or manually remove lockfile\n- Prevents overlapping scans that could produce inconsistent results\n\n### Verification\n\nCheck scanner is working correctly:\n\n```bash\n# Verify required binaries\n./scripts/runner.sh --check\n\n# Run unit tests\nnode test/dependency_scanner.test.mjs\nnode test/cve_integration.test.mjs\nnode test/sast_engine.test.mjs\nnode test/dast_harness.test.mjs\n\n# Validate skill structure\npython ../../utils/validate_skill.py .\n\n# Scan test fixtures (should detect known vulnerabilities)\n./scripts/runner.sh --target test/fixtures/ --format text\n```\n\n## Development\n\n### Running Tests\n\n```bash\n# All tests (vanilla Node.js, no framework)\nfor test in test/*.test.mjs; do\n  node \"$test\" || exit 1\ndone\n\n# Individual test suites\nnode test/dependency_scanner.test.mjs  # Dependency scanning\nnode test/cve_integration.test.mjs     # CVE database APIs\nnode test/sast_engine.test.mjs         # Static analysis\nnode test/dast_harness.test.mjs        # DAST harness execution\n```\n\n### Linting\n\n```bash\n# JavaScript/TypeScript\nnpx eslint . --ext .ts,.tsx,.js,.jsx,.mjs --max-warnings 0\n\n# Python (Bandit already configured in pyproject.toml)\nruff check .\nbandit -r . -ll\n\n# Shell scripts\nshellcheck scripts/*.sh\n```\n\n### Adding Custom Semgrep Rules\n\nCreate custom rules in `.semgrep/rules/`:\n\n```yaml\nrules:\n  - id: custom-security-rule\n    pattern: dangerous_function($ARG)\n    message: Avoid dangerous_function - use safe_alternative instead\n    severity: WARNING\n    languages: [javascript, typescript]\n```\n\nUpdate `scripts/sast_analyzer.mjs` to include custom rules:\n\n```javascript\nconst proc = spawn('semgrep', [\n  'scan',\n  '--config', 'auto',\n  '--config', '.semgrep/rules/',  // Add custom rules\n  '--json',\n  targetPath\n]);\n```\n\n## Integration with ClawSec Suite\n\nThe scanner works standalone or as part of the ClawSec ecosystem:\n\n- **clawsec-suite**: Meta-skill that can install and manage clawsec-scanner\n- **clawsec-feed**: Advisory feed for malicious skill detection (complementary)\n- **openclaw-audit-watchdog**: Cron-based audit automation (similar pattern)\n\nInstall the full ClawSec suite:\n\n```bash\nnpx clawhub@latest install clawsec-suite\n# Then use clawsec-suite to discover and install clawsec-scanner\n```\n\n## Security Considerations\n\n### Scanner Security\n\n- No hardcoded secrets in scanner code\n- API keys read from environment variables only (never logged or committed)\n- Subprocess arguments use arrays to prevent shell injection\n- All external tool output parsed with try/catch error handling\n\n### Vulnerability Prioritization\n\n**Critical/High severity findings** should be addressed immediately:\n- Known exploits in dependencies (CVSS 9.0+)\n- Hardcoded API keys or credentials in code\n- Command injection vulnerabilities\n- Path traversal without validation\n\n**Medium/Low severity findings** can be addressed in normal sprint cycles:\n- Outdated dependencies without known exploits\n- Missing security headers\n- Weak cryptography usage\n\n**Info findings** are advisory only:\n- Deprecated API usage\n- Code quality issues flagged by linters\n\n## Roadmap\n\n### v0.0.2 (Current)\n- [x] Dependency scanning (npm audit, pip-audit)\n- [x] CVE database integration (OSV, NVD, GitHub Advisory)\n- [x] SAST analysis (Semgrep, Bandit)\n- [x] Real OpenClaw hook execution harness for DAST\n- [x] Unified JSON reporting\n- [x] OpenClaw hook integration\n\n### Future Enhancements\n- [ ] Automatic remediation (dependency upgrades, code fixes)\n- [ ] SARIF output format for GitHub Code Scanning integration\n- [ ] Web dashboard for vulnerability tracking over time\n- [ ] CI/CD GitHub Action for PR blocking on high-severity findings\n- [ ] Container image scanning (Docker, OCI)\n- [ ] Infrastructure-as-Code scanning (Terraform, CloudFormation)\n- [ ] Comprehensive agent workflow DAST (requires deeper platform integration)\n\n## Contributing\n\nFound a security issue? Please report privately to security@prompt.security.\n\nFor feature requests and bug reports, open an issue at:\nhttps://github.com/prompt-security/clawsec/issues\n\n## License\n\nAGPL-3.0-or-later\n\nSee LICENSE file in repository root for full text.\n\n## Resources\n\n- **ClawSec Homepage**: https://clawsec.prompt.security\n- **Documentation**: https://clawsec.prompt.security/scanner\n- **GitHub Repository**: https://github.com/prompt-security/clawsec\n- **OSV API Docs**: https://osv.dev/docs/\n- **NVD API Docs**: https://nvd.nist.gov/developers/vulnerabilities\n- **Semgrep Registry**: https://semgrep.dev/explore\n- **Bandit Documentation**: https://bandit.readthedocs.io/\n\nFile v0.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-scanner\",\n  \"version\": \"0.0.2\",\n  \"publishedAt\": 1773163743416\n}\n\nFile v0.0.2:CHANGELOG.md\n\n# Changelog\n\nAll notable changes to the ClawSec Scanner will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.0.2] - 2026-03-10\n\n### Changed\n\n- Replaced simulated DAST checks with real OpenClaw hook execution harness testing\n- Updated DAST semantics so high-severity findings are emitted for actual hook execution failures/timeouts, not static payload pattern matches\n- Reclassified DAST harness capability limitations (for example missing TypeScript compiler for `.ts` hooks) to `info` coverage findings instead of high severity\n- Added DAST harness mode guard to prevent recursive scanner execution when hook handlers are tested in isolation\n\n### Added\n\n- New DAST helper executor script for isolated per-hook execution and timeout enforcement\n- DAST harness regression tests covering no-false-positive baseline and malicious-input crash detection\n\n## [0.0.1] - 2026-02-27\n\n### Added\n\n- Initial release of ClawSec Scanner skill\n- Automated vulnerability scanning for OpenClaw skill installations\n- Integration with advisory feed for real-time security alerts\n- Support for scanning skill dependencies and detecting known CVEs\n- Configurable scan policies and risk thresholds\n- Detailed vulnerability reporting with remediation guidance\n\nFile v0.0.2:hooks/clawsec-scanner-hook/HOOK.md\n\n---\nname: clawsec-scanner-hook\ndescription: Periodic vulnerability scanning for installed skills and dependencies with configurable scan intervals.\nmetadata: { \"openclaw\": { \"events\": [\"agent:bootstrap\", \"command:new\"] } }\n---\n\n# ClawSec Scanner Hook\n\nThis hook performs comprehensive vulnerability scanning on installed skills and their dependencies on:\n\n- `agent:bootstrap`\n- `command:new`\n\nWhen triggered, it runs all configured scanning engines (dependency scan, SAST, DAST, CVE database lookup) and posts findings as conversation messages. Scans are rate-limited by configurable interval to avoid performance impact.\n\n## Scanning Capabilities\n\nThe hook orchestrates four independent scanning engines:\n\n1. **Dependency Scanning**: Executes `npm audit` and `pip-audit` to detect known vulnerabilities in JavaScript and Python dependencies\n2. **SAST (Static Analysis)**: Runs Semgrep (JS/TS) and Bandit (Python) to detect security issues like hardcoded secrets, command injection, and path traversal\n3. **CVE Database Lookup**: Queries OSV API (primary), NVD 2.0 (optional), and GitHub Advisory Database (optional) for vulnerability enrichment\n4. **DAST (Dynamic Analysis)**: Executes real OpenClaw hook handlers in an isolated harness and tests malicious-input resilience, timeout behavior, output bounds, and event mutation safety\n\n## Safety Contract\n\n- The hook does not modify or delete skills.\n- It only reports findings and provides remediation guidance.\n- Scanning is non-blocking and runs on a configurable interval (default 24 hours).\n- Failed scans (network errors, missing tools) produce warnings but do not block execution.\n- Findings are deduplicated to avoid alert fatigue.\n\n## Optional Environment Variables\n\n### Core Configuration\n\n- `CLAWSEC_SCANNER_INTERVAL`: Minimum interval between hook scans in seconds (default `86400` / 24 hours).\n- `CLAWSEC_SCANNER_TARGET`: Override default scan target path (default: installed skills root).\n- `CLAWSEC_SCANNER_STATE_FILE`: Override state file path for deduplication (default `~/.openclaw/clawsec-scanner-state.json`).\n- `CLAWSEC_INSTALL_ROOT`: Override installed skills root directory.\n\n### CVE Database Integration\n\n- `CLAWSEC_NVD_API_KEY`: NVD API key for rate-limit-free access (without this, 6-second delays apply).\n- `GITHUB_TOKEN`: GitHub OAuth token for GitHub Advisory Database queries (optional enhancement).\n\n### Selective Scanning\n\n- `CLAWSEC_SKIP_DEPENDENCY_SCAN`: Set to `1` to disable dependency scanning (npm audit, pip-audit).\n- `CLAWSEC_SKIP_SAST`: Set to `1` to disable static analysis (Semgrep, Bandit).\n- `CLAWSEC_SKIP_DAST`: Set to `1` to disable dynamic analysis (hook security tests).\n- `CLAWSEC_SKIP_CVE_LOOKUP`: Set to `1` to disable CVE database enrichment.\n\n### Advanced Options\n\n- `CLAWSEC_SCANNER_TIMEOUT`: Maximum scan duration in seconds before timeout (default `300` / 5 minutes).\n- `CLAWSEC_SCANNER_FORMAT`: Output format for findings (`json` or `text`, default `text`).\n- `CLAWSEC_SCANNER_MIN_SEVERITY`: Minimum severity to report (`critical`, `high`, `medium`, `low`, `info`, default `medium`).\n- `CLAWSEC_SCANNER_OUTPUT_FILE`: Optional path to write full scan report JSON (default: conversation only).\n\n## Required Binaries\n\nThe hook requires the following binaries to be available on `PATH`:\n\n- `node` (20+) - JavaScript runtime\n- `npm` - For npm audit execution\n- `python3` (3.10+) - Python runtime\n- `pip-audit` - Python dependency scanner\n- `semgrep` - JavaScript/TypeScript static analysis\n- `bandit` - Python static analysis\n- `jq` - JSON parsing and merging\n- `curl` - API requests (fallback)\n\nMissing binaries will be logged as warnings; available tools will still run.\n\nFile v0.0.2:skill.json\n\n{\n  \"name\": \"clawsec-scanner\",\n  \"version\": \"0.0.2\",\n  \"description\": \"Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific DAST hook execution testing for OpenClaw hooks.\",\n  \"author\": \"prompt-security\",\n  \"license\": \"AGPL-3.0-or-later\",\n  \"homepage\": \"https://clawsec.prompt.security/\",\n  \"keywords\": [\n    \"security\",\n    \"vulnerability\",\n    \"scanner\",\n    \"dependency\",\n    \"cve\",\n    \"sast\",\n    \"dast\",\n    \"audit\",\n    \"agents\",\n    \"ai\",\n    \"openclaw\",\n    \"semgrep\",\n    \"bandit\",\n    \"osv\",\n    \"nvd\"\n  ],\n  \"sbom\": {\n    \"files\": [\n      {\n        \"path\": \"SKILL.md\",\n        \"required\": true,\n        \"description\": \"Scanner skill documentation and usage guide\"\n      },\n      {\n        \"path\": \"CHANGELOG.md\",\n        \"required\": true,\n        \"description\": \"Version history and feature changelog\"\n      },\n      {\n        \"path\": \"scripts/runner.sh\",\n        \"required\": true,\n        \"description\": \"Main orchestration script for running all scanner engines\"\n      },\n      {\n        \"path\": \"scripts/scan_dependencies.mjs\",\n        \"required\": true,\n        \"description\": \"Dependency scanner using npm audit and pip-audit with JSON parsing\"\n      },\n      {\n        \"path\": \"scripts/query_cve_databases.mjs\",\n        \"required\": true,\n        \"description\": \"Multi-database CVE lookup (OSV primary, NVD/GitHub fallback)\"\n      },\n      {\n        \"path\": \"scripts/sast_analyzer.mjs\",\n        \"required\": true,\n        \"description\": \"Static analysis engine running Semgrep and Bandit as subprocesses\"\n      },\n      {\n        \"path\": \"scripts/dast_runner.mjs\",\n        \"required\": true,\n        \"description\": \"Dynamic analysis harness executing OpenClaw hook handlers with malicious-input and timeout checks\"\n      },\n      {\n        \"path\": \"scripts/dast_hook_executor.mjs\",\n        \"required\": true,\n        \"description\": \"Isolated hook execution helper used by DAST for real OpenClaw harness testing\"\n      },\n      {\n        \"path\": \"scripts/setup_scanner_hook.mjs\",\n        \"required\": false,\n        \"description\": \"Hook installer for continuous monitoring integration\"\n      },\n      {\n        \"path\": \"lib/report.mjs\",\n        \"required\": true,\n        \"description\": \"Unified vulnerability report generator (JSON and human-readable formats)\"\n      },\n      {\n        \"path\": \"lib/utils.mjs\",\n        \"required\": true,\n        \"description\": \"Shared utility functions for subprocess execution and JSON parsing\"\n      },\n      {\n        \"path\": \"lib/types.ts\",\n        \"required\": true,\n        \"description\": \"TypeScript type definitions for Vulnerability and ScanReport schemas\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/HOOK.md\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook metadata for continuous scanning integration\"\n      },\n      {\n        \"path\": \"hooks/clawsec-scanner-hook/handler.ts\",\n        \"required\": false,\n        \"description\": \"OpenClaw hook handler for periodic vulnerability scanning\"\n      },\n      {\n        \"path\": \"test/dependency_scanner.test.mjs\",\n        \"required\": false,\n        \"description\": \"Unit tests for dependency scanning (npm audit, pip-audit)\"\n      },\n      {\n        \"path\": \"test/cve_integration.test.mjs\",\n        \"required\": false,\n        \"description\": \"Integration tests for CVE database API queries\"\n      },\n      {\n        \"path\": \"test/sast_engine.test.mjs\",\n        \"required\": false,\n        \"description\": \"Unit tests for SAST analysis (Semgrep, Bandit)\"\n\n\nArchive v0.0.1: 20 files, 49445 bytes\n\nFiles: CHANGELOG.md (647b), hooks/clawsec-scanner-hook/handler.ts (9358b), hooks/clawsec-scanner-hook/HOOK.md (3614b), lib/report.mjs (8204b), lib/types.ts (923b), lib/utils.mjs (3568b), scripts/dast_runner.mjs (15067b), scripts/query_cve_databases.mjs (8892b), scripts/runner.sh (9574b), scripts/sast_analyzer.mjs (8621b), scripts/scan_dependencies.mjs (10147b), scripts/setup_scanner_hook.mjs (3732b), skill.json (3933b), SKILL.md (15679b), test/cve_integration.test.mjs (18916b), test/dependency_scanner.test.mjs (18770b), test/lib/test_harness.mjs (2426b), test/reviewer_regressions.test.mjs (7614b), test/sast_engine.test.mjs (17894b), _meta.json (134b)","readmeExcerpt":"Skill: clawsec-scanner Owner: davida-ps Summary: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisor... Tags: latest:0.0.7 Version history: v0.0.7 | 2026-06-23T08:26:16.764Z | user Release 0.0.7 via CI v0.0.5 | 2026-06-10T14:59:33.346Z | user Release 0.0.5 via CI v0.0.4 | 2026-06-07T10:07:44.927Z | user Release 0","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"npx skills add prompt-security/clawsec --skill clawsec-scanner -a openclaw -y"},{"language":"typescript","snippet":"{\n  scan_id: string;         // UUID\n  timestamp: string;       // ISO 8601\n  target: string;          // Scanned path\n  vulnerabilities: Vulnerability[];\n  summary: {\n    critical: number;\n    high: number;\n    medium: number;\n    low: number;\n    info: number;\n  }\n}"},{"language":"bash","snippet":"curl --version"},{"language":"bash","snippet":"# Core runtimes\nnode --version  # v20+\nnpm --version\npython3 --version  # 3.10+\n\n# Scanning tools\npip-audit --version  # Install: uv pip install pip-audit\nsemgrep --version    # Install: pip install semgrep OR brew install semgrep\nbandit --version     # Install: uv pip install bandit\n\n# Utilities\njq --version\ncurl --version"},{"language":"bash","snippet":"npx clawhub@latest install clawsec-scanner"},{"language":"bash","snippet":"curl -fsSL \"$BASE/$ZIP_NAME\" -o \"$TEMP_DIR/$ZIP_NAME\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: clawsec-scanner\nversion: 0.0.7\ndescription: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\nhomepage: https://clawsec.prompt.security\nclawdis:\n  emoji: \"🔍\"\n  requires:\n    bins: [node, npm, python3, pip-audit, semgrep, bandit, jq, curl]\n---\n\n# ClawSec Scanner\n\nComprehensive security scanner for agent platforms that automates vulnerability detection across multiple dimensions:\n\n- **Dependency Scanning**: Analyzes npm and Python dependencies using `npm audit` and `pip-audit` with structured JSON output parsing\n- **CVE Database Integration**: Queries OSV (primary), NVD 2.0, and GitHub Advisory Database for vulnerability enrichment\n- **SAST Analysis**: Static code analysis using Semgrep (JavaScript/TypeScript) and Bandit (Python) to detect hardcoded secrets, command injection, path traversal, and unsafe deserialization\n- **DAST Framework**: Agent-specific static analysis of OpenClaw hook metadata and handler source without importing or invoking target code\n- **Unified Reporting**: Consolidated vulnerability reports with severity classification and remediation guidance\n- **Continuous Monitoring**: OpenClaw hook integration for automated periodic scanning\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-scanner -a openclaw -y\n```\n\n## Features\n\n### Multi-Engine Scanning\n\nThe scanner orchestrates four complementary scan types to provide comprehensive vulnerability coverage:\n\n1. **Dependency Scanning**\n   - Executes `npm audit --json` and `pip-audit -f json` as subprocesses\n   - Parses structured output to extract CVE IDs, severity, affected versions\n   - Handles edge cases: missing package-lock.json, zero vulnerabilities, malformed JSON\n\n2. **CVE Database Queries**\n   - **OSV API** (primary): Free, no authentication, broad ecosystem support (npm, PyPI, Go, Maven)\n   - **NVD 2.0** (optional): Requires API key to avoid 6-second rate limiting\n   - **GitHub Advisory Database** (optional): GraphQL API with OAuth token\n   - Normalizes all API responses to unified `Vulnerability` schema\n\n3. **Static Analysis (SAST)**\n   - **Semgrep** for JavaScript/TypeScript: Detects security issues using `--config auto` or `--config p/security-audit`\n   - **Bandit** for Python: Leverages existing `pyproject.toml` configuration\n   - Identifies: hardcoded secrets (API keys, tokens), command injection (`eval`, `exec`), path traversal, unsafe deserialization\n\n4. **Dynamic Analysis (DAST)**\n   - Static hook inspection for OpenClaw hook handlers discovered from `HOOK.md` metadata\n   - Verifies coverage and source-level risk signals without importing, transpiling, or invoking target handlers\n   - Note: Traditional web DAST tools (ZAP, Burp) do not apply to agent platfor"},{"path":"README.md","content":"# Clawsec Scanner\n\nAutomated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisory), SAST analysis (Semgrep, Bandit), and agent-specific static hook inspection for OpenClaw hooks.\n\n## Vercel Skills Installation\n\nInstall with the Vercel Skills CLI for this harness:\n\n```bash\nnpx skills add prompt-security/clawsec --skill clawsec-scanner -a openclaw -y\n```"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76m78f01hqrtpgm895s0jsax80jd8v\",\n  \"slug\": \"clawsec-scanner\",\n  \"version\": \"0.0.7\",\n  \"publishedAt\": 1782203176764\n}"},{"path":"CHANGELOG.md","content":"# Changelog\n\n## [0.0.7] - 2026-06-23\n\n### Changed\n\n- Re-released skill metadata to run through the corrected normal tag publish pipeline without runtime changes.\n\n## [0.0.6] - 2026-06-22\n\n### Changed\n\n- Re-released skill metadata to publish through the updated ClawHub pipeline without runtime changes.\n\n## [0.0.5] - 2026-06-10\n\n### Changed\n\n- Re-released skill package with updated marketplace grouping and signed release trust artifacts for Vercel-compatible skill installation.\n\n## [0.0.4] - 2026-06-07\n\n### Security\n- Replaced DAST target hook execution with static hook source inspection so scanner runs never import, transpile, or invoke untrusted handler code.\n\n## [0.0.3] - 2026-05-13\n\n### Changed\n- Re-release skill payload metadata after excluding test-only files from release SBOMs and archives.\n\nAll notable changes to the ClawSec Scanner will be documented in this file.\n\nThe format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),\nand this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).\n\n## [0.0.2] - 2026-03-10\n\n### Changed\n\n- Replaced simulated DAST checks with real OpenClaw hook execution harness testing\n- Updated DAST semantics so high-severity findings are emitted for actual hook execution failures/timeouts, not static payload pattern matches\n- Reclassified DAST harness capability limitations (for example missing TypeScript compiler for `.ts` hooks) to `info` coverage findings instead of high severity\n- Added DAST harness mode guard to prevent recursive scanner execution when hook handlers are tested in isolation\n\n### Added\n\n- New DAST helper executor script for isolated per-hook execution and timeout enforcement\n- DAST harness regression tests covering no-false-positive baseline and malicious-input crash detection\n\n## [0.0.1] - 2026-02-27\n\n### Added\n\n- Initial release of ClawSec Scanner skill\n- Automated vulnerability scanning for OpenClaw skill installations\n- Integration with advisory feed for real-time security alerts\n- Support for scanning skill dependencies and detecting known CVEs\n- Configurable scan policies and risk thresholds\n- Detailed vulnerability reporting with remediation guidance"},{"path":"hooks/clawsec-scanner-hook/HOOK.md","content":"---\nname: clawsec-scanner-hook\ndescription: Periodic vulnerability scanning for installed skills and dependencies with configurable scan intervals.\nmetadata: { \"openclaw\": { \"events\": [\"agent:bootstrap\", \"command:new\"] } }\n---\n\n# ClawSec Scanner Hook\n\nThis hook performs comprehensive vulnerability scanning on installed skills and their dependencies on:\n\n- `agent:bootstrap`\n- `command:new`\n\nWhen triggered, it runs all configured scanning engines (dependency scan, SAST, DAST, CVE database lookup) and posts findings as conversation messages. Scans are rate-limited by configurable interval to avoid performance impact.\n\n## Scanning Capabilities\n\nThe hook orchestrates four independent scanning engines:\n\n1. **Dependency Scanning**: Executes `npm audit` and `pip-audit` to detect known vulnerabilities in JavaScript and Python dependencies\n2. **SAST (Static Analysis)**: Runs Semgrep (JS/TS) and Bandit (Python) to detect security issues like hardcoded secrets, command injection, and path traversal\n3. **CVE Database Lookup**: Queries OSV API (primary), NVD 2.0 (optional), and GitHub Advisory Database (optional) for vulnerability enrichment\n4. **DAST (Dynamic Analysis)**: Executes real OpenClaw hook handlers in an isolated harness and tests malicious-input resilience, timeout behavior, output bounds, and event mutation safety\n\n## Safety Contract\n\n- The hook does not modify or delete skills.\n- It only reports findings and provides remediation guidance.\n- Scanning is non-blocking and runs on a configurable interval (default 24 hours).\n- Failed scans (network errors, missing tools) produce warnings but do not block execution.\n- Findings are deduplicated to avoid alert fatigue.\n\n## Optional Environment Variables\n\n### Core Configuration\n\n- `CLAWSEC_SCANNER_INTERVAL`: Minimum interval between hook scans in seconds (default `86400` / 24 hours).\n- `CLAWSEC_SCANNER_TARGET`: Override default scan target path (default: installed skills root).\n- `CLAWSEC_SCANNER_STATE_FILE`: Override state file path for deduplication (default `~/.openclaw/clawsec-scanner-state.json`).\n- `CLAWSEC_INSTALL_ROOT`: Override installed skills root directory.\n\n### CVE Database Integration\n\n- `CLAWSEC_NVD_API_KEY`: NVD API key for rate-limit-free access (without this, 6-second delays apply).\n- `GITHUB_TOKEN`: GitHub OAuth token for GitHub Advisory Database queries (optional enhancement).\n\n### Selective Scanning\n\n- `CLAWSEC_SKIP_DEPENDENCY_SCAN`: Set to `1` to disable dependency scanning (npm audit, pip-audit).\n- `CLAWSEC_SKIP_SAST`: Set to `1` to disable static analysis (Semgrep, Bandit).\n- `CLAWSEC_SKIP_DAST`: Set to `1` to disable dynamic analysis (hook security tests).\n- `CLAWSEC_SKIP_CVE_LOOKUP`: Set to `1` to disable CVE database enrichment.\n\n### Advanced Options\n\n- `CLAWSEC_SCANNER_TIMEOUT`: Maximum scan duration in seconds before timeout (default `300` / 5 minutes).\n- `CLAWSEC_SCANNER_FORMAT`: Output format for findings (`json` or `text`, default `text`).\n- `CLAWSEC_SCANNER_MIN_SEVERITY`: "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisor... Skill: clawsec-scanner Owner: davida-ps Summary: Automated vulnerability scanner for agent platforms. Performs dependency scanning (npm audit, pip-audit), multi-database CVE lookup (OSV, NVD, GitHub Advisor... Tags: latest:0.0.7 Version history: v0.0.7 | 2026-06-23T08:26:16.764Z | user Release 0.0.7 via CI v0.0.5 | 2026-06-10T14:59:33.346Z | user Release 0.0.5 via CI v0.0.4 | 2026-06-07T10:07:44.927Z | user Release 0","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1485,"uniquenessScore":45,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T04:55:30.279Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T04:55:30.279Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T07:35:34.373Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}