{"id":"c5fde5fc-df6f-408a-a8be-22f267dc068b","entityType":"agent","slug":"clawhub-itsnishi-audit-code","name":"Audit Code","canonicalUrl":"https://www.xpersona.co/agent/clawhub-itsnishi-audit-code","canonicalPath":"/agent/clawhub-itsnishi-audit-code","generatedAt":"2026-10-09T07:15:31.803Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities Skill: Audit Code Owner: ItsNishi Summary: Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities Tags: latest:1.0.0, security:1.0.0 Version history: v1.0.0 | 2026-02-07T23:22:00.844Z | user Initial release of audit-code – a security-focused code review skill. - Scans project source code for hardcoded secrets, dangerous calls, and common vulnerabilities (OWASP-style). - Detect","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 4/15/2026.","installCommand":"clawhub skill install kn7c4x4srjpbhtjhec7q71202n80phmw:audit-code","sourceUrl":"https://clawhub.ai/ItsNishi/audit-code","homepage":"https://clawhub.ai/ItsNishi/audit-code","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/ItsNishi/audit-code","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities Skill: Audit Code Owner: ItsNishi Summary: Security-focused code"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"stars":null,"forks":null,"downloads":1537,"packageName":null,"latestVersion":"1.0.0","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-02-28T21:30:01.435Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-28T21:30:01.435Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-01T21:30:01.435Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.0","createdAt":"2026-02-07T23:22:00.844Z","changelog":"Initial release of audit-code – a security-focused code review skill. - Scans project source code for hardcoded secrets, dangerous calls, and common vulnerabilities (OWASP-style). - Detects risky patterns such as eval/exec, insecure SQL, dependency issues, and secrets in files. - Produces a structured, severity-ranked report with file locations and remediation advice. - Designed for pre-commit checks, security audits, and post–AI code generation validation. - Use via CLI with optional path arguments; defaults to scanning the project root.","fileCount":4,"zipByteSize":11718}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install kn7c4x4srjpbhtjhec7q71202n80phmw:audit-code","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T07:15:31.803Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-itsnishi-audit-code/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"Skill: Audit Code\n\nOwner: ItsNishi\n\nSummary: Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities\n\nTags: latest:1.0.0, security:1.0.0\n\nVersion history:\n\nv1.0.0 | 2026-02-07T23:22:00.844Z | user\n\nInitial release of audit-code – a security-focused code review skill.\n\n- Scans project source code for hardcoded secrets, dangerous calls, and common vulnerabilities (OWASP-style).\n- Detects risky patterns such as eval/exec, insecure SQL, dependency issues, and secrets in files.\n- Produces a structured, severity-ranked report with file locations and remediation advice.\n- Designed for pre-commit checks, security audits, and post–AI code generation validation.\n- Use via CLI with optional path arguments; defaults to scanning the project root.\n\nArchive index:\n\nArchive v1.0.0: 4 files, 11718 bytes\n\nFiles: scripts/audit_code.py (8138b), scripts/patterns.py (26840b), SKILL.md (1674b), _meta.json (129b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: audit-code\ndescription: Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities\ndisable-model-invocation: true\nallowed-tools: Read, Glob, Grep, Bash\ncontext: fork\n---\n\n# audit-code -- Project Code Security Review\n\nSecurity-focused code review of project source code. Covers OWASP-style vulnerabilities, hardcoded secrets, dangerous function calls, and patterns relevant to AI-assisted development.\n\n## What to do\n\nRun the auditor against the target path:\n\n```bash\npython3 \"$SKILL_DIR/scripts/audit_code.py\" \"$ARGUMENTS\"\n```\n\nIf `$ARGUMENTS` is empty, default to `$PROJECT_ROOT`.\n\n## What it checks\n\n- **Hardcoded secrets** -- API keys (AWS, GitHub, Stripe, OpenAI, Slack), tokens, private keys, connection strings, passwords\n- **Dangerous function calls** -- eval, exec, subprocess with shell=True, child_process.exec, pickle deserialization, system(), gets(), etc.\n- **SQL injection** -- String concatenation/interpolation in SQL queries\n- **Dependency risks** -- Known hallucinated package names, unverified installations\n- **Sensitive files** -- .env files committed to git, credential files in repo\n- **File permissions** -- Overly permissive chmod patterns\n- **Exfiltration patterns** -- Base64 encode + network send, DNS exfiltration, credential file reads\n\n## Output\n\nStructured report with severity-ranked findings, file locations, and actionable remediation steps.\n\n## When to use\n\n- Before committing or pushing code\n- When reviewing third-party contributions or PRs\n- As part of a periodic security audit of the codebase\n- After AI-assisted code generation to verify no secrets or vulnerabilities were introduced\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7c4x4srjpbhtjhec7q71202n80phmw\",\n  \"slug\": \"audit-code\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1770506520844\n}","readmeExcerpt":"Skill: Audit Code Owner: ItsNishi Summary: Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities Tags: latest:1.0.0, security:1.0.0 Version history: v1.0.0 | 2026-02-07T23:22:00.844Z | user Initial release of audit-code – a security-focused code review skill. - Scans project source code for hardcoded secrets, dangerous calls, and common vulnerabilities (OWASP-style). - Detect","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"python3 \"$SKILL_DIR/scripts/audit_code.py\" \"$ARGUMENTS\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: audit-code\ndescription: Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities\ndisable-model-invocation: true\nallowed-tools: Read, Glob, Grep, Bash\ncontext: fork\n---\n\n# audit-code -- Project Code Security Review\n\nSecurity-focused code review of project source code. Covers OWASP-style vulnerabilities, hardcoded secrets, dangerous function calls, and patterns relevant to AI-assisted development.\n\n## What to do\n\nRun the auditor against the target path:\n\n```bash\npython3 \"$SKILL_DIR/scripts/audit_code.py\" \"$ARGUMENTS\"\n```\n\nIf `$ARGUMENTS` is empty, default to `$PROJECT_ROOT`.\n\n## What it checks\n\n- **Hardcoded secrets** -- API keys (AWS, GitHub, Stripe, OpenAI, Slack), tokens, private keys, connection strings, passwords\n- **Dangerous function calls** -- eval, exec, subprocess with shell=True, child_process.exec, pickle deserialization, system(), gets(), etc.\n- **SQL injection** -- String concatenation/interpolation in SQL queries\n- **Dependency risks** -- Known hallucinated package names, unverified installations\n- **Sensitive files** -- .env files committed to git, credential files in repo\n- **File permissions** -- Overly permissive chmod patterns\n- **Exfiltration patterns** -- Base64 encode + network send, DNS exfiltration, credential file reads\n\n## Output\n\nStructured report with severity-ranked findings, file locations, and actionable remediation steps.\n\n## When to use\n\n- Before committing or pushing code\n- When reviewing third-party contributions or PRs\n- As part of a periodic security audit of the codebase\n- After AI-assisted code generation to verify no secrets or vulnerabilities were introduced"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7c4x4srjpbhtjhec7q71202n80phmw\",\n  \"slug\": \"audit-code\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1770506520844\n}"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities Skill: Audit Code Owner: ItsNishi Summary: Security-focused code review for hardcoded secrets, dangerous calls, and common vulnerabilities Tags: latest:1.0.0, security:1.0.0 Version history: v1.0.0 | 2026-02-07T23:22:00.844Z | user Initial release of audit-code – a security-focused code review skill. - Scans project source code for hardcoded secrets, dangerous calls, and common vulnerabilities (OWASP-style). - Detect","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":661,"uniquenessScore":61,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T07:15:31.803Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}