{"id":"659b1b2e-d33c-4943-a419-8f57a4d0c6ba","entityType":"agent","slug":"clawhub-markeljan-agentsec","name":"Agentsec","canonicalUrl":"https://www.xpersona.co/agent/clawhub-markeljan-agentsec","canonicalPath":"/agent/clawhub-markeljan-agentsec","generatedAt":"2026-10-10T15:51:18.869Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T13:51:13.273Z","emptyReason":null},"description":"Audit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before runnin... Skill: Agentsec Owner: markeljan Summary: Audit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before runnin... Tags: latest:0.4.0 Version history: v0.4.0 | 2026-07-01T18:09:31.606Z | auto Version 0.4.0 of agentsec - Updated \"OWASP Agentic Skills Top 10\" risk category descriptions (notably, AST05 is now \"Untrusted External Inst","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.4K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s175gp6xftj25qjw80131jwsk98408d7:agentsec","sourceUrl":"https://clawhub.ai/markeljan/agentsec","homepage":"https://clawhub.ai/markeljan/skills/agentsec","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/markeljan/agentsec","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/markeljan/skills/agentsec","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Audit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before runnin..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:51:13.273Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:51:13.273Z","emptyReason":null},"stars":null,"forks":null,"downloads":1403,"packageName":null,"latestVersion":"0.4.0","tractionLabel":"1.4K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:51:13.273Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T13:51:13.273Z","lastCrawledAt":"2026-10-10T13:51:13.273Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T13:51:13.273Z","lastVerifiedAt":null,"highlights":[{"version":"0.4.0","createdAt":"2026-07-01T18:09:31.606Z","changelog":"Version 0.4.0 of agentsec - Updated \"OWASP Agentic Skills Top 10\" risk category descriptions (notably, AST05 is now \"Untrusted External Instructions\"). - Removed the file skill-card.md. - Incremented version to 0.4.0. - No other core command or flag changes noted in documentation.","fileCount":3,"zipByteSize":5655},{"version":"0.3.3","createdAt":"2026-05-28T16:25:00.223Z","changelog":"- Added explicit support and documentation for the Hermes agent platform, including auto-discovery paths and usage examples. - Updated auto-discovery section to clarify all platforms must use the agentskills.io SKILL.md format. - Enhanced flag documentation and usage examples to include Hermes and other platforms. - Removed redundant skill-card.md file for improved clarity and maintenance.","fileCount":3,"zipByteSize":5626},{"version":"0.3.2","createdAt":"2026-05-21T15:58:05.343Z","changelog":"- Added license, author, and permissions metadata to SKILL.md. - Introduced a top-level permissions section (filesystem:read). - Declared author as semiotic-ai. - Specified license as MIT. - Minor metadata structure updates for agentsec and openclaw fields.","fileCount":3,"zipByteSize":5432},{"version":"0.3.1","createdAt":"2026-05-21T14:52:16.754Z","changelog":"## agentsec 0.3.1 - Updated version to 0.3.1 in SKILL.md. - No functional, workflow, or documentation changes outside of the version bump.","fileCount":2,"zipByteSize":4315},{"version":"0.3.0","createdAt":"2026-05-07T15:56:03.899Z","changelog":"agentsec 0.3.0 - Bumped version from 0.2.7 to 0.3.0 in SKILL.md - No other documentation or feature changes in this release","fileCount":2,"zipByteSize":4314},{"version":"0.2.7","createdAt":"2026-05-06T23:09:01.832Z","changelog":"agentsec 0.2.7 changelog: - Version bumped from 0.2.6 to 0.2.7 in SKILL.md. - No functional or documentation changes other than the version update.","fileCount":2,"zipByteSize":4315},{"version":"0.2.6","createdAt":"2026-05-06T18:56:17.112Z","changelog":"- Added support for `--profile` flag (`default`, `web3`, `strict`) to control rule profiles. - Web3-touching skills are now auto-detected and audited against additional AST-10 Web3 Annex rules. - Updated OpenClaw integration metadata. - Documentation now describes AST-10 Web3 Annex coverage and auto-tagging of Web3 skills. - Incremented version to 0.2.6.","fileCount":2,"zipByteSize":4316},{"version":"0.1.5","createdAt":"2026-04-28T18:14:00.553Z","changelog":"Sharpen description and add openclaw install metadata","fileCount":2,"zipByteSize":3360}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s175gp6xftj25qjw80131jwsk98408d7:agentsec","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T15:51:18.866Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-markeljan-agentsec/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T13:51:13.273Z","emptyReason":null},"readme":"Skill: Agentsec\n\nOwner: markeljan\n\nSummary: Audit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before runnin...\n\nTags: latest:0.4.0\n\nVersion history:\n\nv0.4.0 | 2026-07-01T18:09:31.606Z | auto\n\nVersion 0.4.0 of agentsec\n\n- Updated \"OWASP Agentic Skills Top 10\" risk category descriptions (notably, AST05 is now \"Untrusted External Instructions\").\n- Removed the file skill-card.md.\n- Incremented version to 0.4.0.\n- No other core command or flag changes noted in documentation.\n\nv0.3.3 | 2026-05-28T16:25:00.223Z | auto\n\n- Added explicit support and documentation for the Hermes agent platform, including auto-discovery paths and usage examples.\n- Updated auto-discovery section to clarify all platforms must use the agentskills.io SKILL.md format.\n- Enhanced flag documentation and usage examples to include Hermes and other platforms.\n- Removed redundant skill-card.md file for improved clarity and maintenance.\n\nv0.3.2 | 2026-05-21T15:58:05.343Z | auto\n\n- Added license, author, and permissions metadata to SKILL.md.\n- Introduced a top-level permissions section (filesystem:read).\n- Declared author as semiotic-ai.\n- Specified license as MIT.\n- Minor metadata structure updates for agentsec and openclaw fields.\n\nv0.3.1 | 2026-05-21T14:52:16.754Z | auto\n\n## agentsec 0.3.1\n\n- Updated version to 0.3.1 in SKILL.md.\n- No functional, workflow, or documentation changes outside of the version bump.\n\nv0.3.0 | 2026-05-07T15:56:03.899Z | auto\n\nagentsec 0.3.0\n\n- Bumped version from 0.2.7 to 0.3.0 in SKILL.md\n- No other documentation or feature changes in this release\n\nv0.2.7 | 2026-05-06T23:09:01.832Z | auto\n\nagentsec 0.2.7 changelog:\n\n- Version bumped from 0.2.6 to 0.2.7 in SKILL.md.\n- No functional or documentation changes other than the version update.\n\nv0.2.6 | 2026-05-06T18:56:17.112Z | auto\n\n- Added support for `--profile` flag (`default`, `web3`, `strict`) to control rule profiles.\n- Web3-touching skills are now auto-detected and audited against additional AST-10 Web3 Annex rules.\n- Updated OpenClaw integration metadata.\n- Documentation now describes AST-10 Web3 Annex coverage and auto-tagging of Web3 skills.\n- Incremented version to 0.2.6.\n\nv0.1.5 | 2026-04-28T18:14:00.553Z | user\n\nSharpen description and add openclaw install metadata\n\nv0.1.4 | 2026-04-28T15:11:14.212Z | user\n\nInitial release: OWASP AST10 security audit CLI for AI agent skills\n\nArchive index:\n\nArchive v0.4.0: 3 files, 5655 bytes\n\nFiles: skill-card.md (2092b), SKILL.md (11168b), _meta.json (127b)\n\nFile v0.4.0:SKILL.md\n\n---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.4.0\nlicense: MIT\nhomepage: https://agentsec.sh\nauthor: semiotic-ai\npermissions:\n  - filesystem:read\nmetadata:\n  agentsec:\n    profile: meta\n  openclaw:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\nagentsec is agent-platform agnostic — every platform listed below ships skills in the [agentskills.io](https://agentskills.io/specification) `SKILL.md` format and is auto-discovered.\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Hermes**             | `~/.hermes/skills`, `~/.hermes/skills/*` (bundled categories), `./.hermes/skills`                                         |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n```bash\n# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list\n```\n\n## Installation\n\n`npx agentsec` needs no install. For repeated use, install globally:\n\n```bash\n# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec\n```\n\nThen drop the `npx` prefix:\n\n```bash\nagentsec\nagentsec scan --path ./my-skills\n```\n\n## Flags\n\nAll flags work with any command.\n\n| Flag         | Short | Values                          | Default    | Purpose                                                  |\n| ------------ | ----- | ------------------------------- | ---------- | -------------------------------------------------------- |\n| `--format`   | `-f`  | `text`, `json`, `sarif`, `html` | `text`     | Output format                                            |\n| `--output`   | `-o`  | path                            | stdout     | Write report to file                                     |\n| `--policy`   | `-p`  | preset name or path             | `default`  | Apply a policy preset                                    |\n| `--platform` |       | `openclaw`, `claude`, `codex`, `hermes` | auto | Narrow to one agent platform                             |\n| `--path`     |       | path                            | auto       | Custom skill directory to scan                           |\n| `--profile`  |       | `default`, `web3`, `strict`     | `default`  | Rule profile. `default` auto-detects Web3 skills; `web3` forces the annex on every skill |\n| `--verbose`  | `-v`  |                                 | off        | Show detailed findings                                   |\n| `--no-color` |       |                                 | off        | Disable colored output                                   |\n| `--help`     | `-h`  |                                 |            | Show help                                                |\n| `--version`  | `-V`  |                                 |            | Print version                                            |\n\n## Common Recipes\n\n### Show detailed findings and remediation\n\n```bash\nnpx agentsec --verbose\n```\n\n### Scan a specific directory\n\n```bash\nnpx agentsec scan --path ./my-skills\n```\n\n### Target a specific agent platform\n\n```bash\nnpx agentsec --platform claude\nnpx agentsec --platform codex\nnpx agentsec --platform hermes\nnpx agentsec --platform openclaw\n```\n\n### Audit with a strict policy and save JSON\n\n```bash\nnpx agentsec --policy strict --format json --output audit.json\n```\n\n### Generate an HTML report for stakeholders\n\n```bash\nnpx agentsec --format html --output report.html\n```\n\n### Generate a SARIF report for IDE / code-scanning integration\n\n```bash\nnpx agentsec --format sarif --output report.sarif\n```\n\n### List available policy presets\n\n```bash\nnpx agentsec policy list\n```\n\n### Inspect the rules in a preset\n\n```bash\nnpx agentsec policy show strict\n```\n\n### Validate a custom policy config file\n\n```bash\nnpx agentsec policy validate ./my-policy.json\n```\n\n### Replay a previous audit as an HTML report\n\n```bash\nnpx agentsec report audit.json --format html --output report.html\n```\n\n## Policy Presets\n\n| Name                 | Use Case                                                             |\n| -------------------- | -------------------------------------------------------------------- |\n| `default`            | Balanced policy. Blocks critical findings.                           |\n| `strict`             | Enterprise-grade. Blocks high and critical findings, enforces tests. |\n| `permissive`         | Lenient. Only blocks critical CVEs. Good for development.            |\n| `owasp-agent-top-10` | Built directly from the OWASP Agentic Skills Top 10.                 |\n\n## Configuration File\n\n`agentsec` auto-loads `.agentsecrc`, `.agentsecrc.json`, or `agentsec.config.json` from the current directory (or any parent):\n\n```json\n{\n  \"format\": \"text\",\n  \"output\": null,\n  \"policy\": \"strict\",\n  \"verbose\": false\n}\n```\n\nCLI flags always override config file values. Omit `\"platform\"` and `\"path\"` to keep the default auto-discovery behavior — agentsec will scan every known platform's default locations.\n\n## OWASP Agentic Skills Top 10\n\nEvery audit checks all ten risk categories:\n\n| ID    | Risk                            |\n| ----- | ------------------------------- |\n| AST01 | Malicious Skills                |\n| AST02 | Supply Chain Compromise         |\n| AST03 | Over-Privileged Skills          |\n| AST04 | Insecure Metadata               |\n| AST05 | Untrusted External Instructions |\n| AST06 | Weak Isolation                  |\n| AST07 | Update Drift                    |\n| AST08 | Poor Scanning                   |\n| AST09 | No Governance                   |\n| AST10 | Cross-Platform Reuse            |\n\n## AST-10 Web3 Annex (auto-detected)\n\nWeb3-touching skills are detected automatically and audited against twelve additional rules — no flag required. A skill is detected as Web3 when its manifest declares a `web3:` block, when its source imports a Web3 client library (`viem`, `ethers`, `web3`, `wagmi`, `@solana/web3.js`, `@coinbase/onchainkit`, `@privy-io`, `@biconomy`, `@zerodev`), when it references a Web3 RPC method (`eth_*`, `wallet_*`, `personal_sign`, `signTypedData`), or when it ships a `.sol` file. Detected skills are tagged `[Web3]` in the output:\n\n```text\n✔ scoped-trader v1.4.0  [Web3]  C (62)\n✔ helpful-summarizer v1.2.0     A (95)\n```\n\n`--profile web3` is still available — it forces the annex onto every skill regardless of detection (useful for cross-team CI consistency):\n\n```bash\nnpx agentsec audit --profile web3 --path ./my-skills\n```\n\n| ID      | Risk                                            |\n| ------- | ----------------------------------------------- |\n| AST-W01 | Unbounded Signing Authority                     |\n| AST-W02 | Implicit Permit / Permit2 Signature Capture     |\n| AST-W03 | Delegation Hijack via EIP-7702                  |\n| AST-W04 | Blind / Opaque Signing Surface                  |\n| AST-W05 | RPC Endpoint Substitution & Mempool Leakage     |\n| AST-W06 | Unverified Contract Call Targets                |\n| AST-W07 | Cross-Chain / Bridge Action Replay              |\n| AST-W08 | MCP Chain-Tool Drift / Capability Smuggling     |\n| AST-W09 | Session-Key / Permission-Caveat Erosion         |\n| AST-W10 | Slippage / Oracle Manipulation by Agent Loop    |\n| AST-W11 | Key Material in Agent Memory / Logs             |\n| AST-W12 | No On-Chain Action Audit / Kill-Switch          |\n\nSkills can declare a `web3` block in their manifest (chains, signers, policy caps, session-key scopes, MCP server pinning, audit sink, kill-switch) so the annex can verify scoping without flagging well-bounded skills. See `docs/plans/ast10-web3-annex-rules.md` for full per-rule detection signals.\n\n## Understanding the Output\n\nDefault output is compact: each skill shows its grade and score, followed by a one-line finding summary and a PASS/WARN/FAIL status.\n\n```\n✔ Found 6 skills\n\n✔ fetch-data     v1.0.0  D (42)\n✔ deploy-helper  v2.3.0  C (68)\n✔ code-review    v1.1.0  A (95)\n\n6 skills scanned  •  avg score 78  •  4 certified\nFindings: 2 critical, 1 high, 2 medium\n\n⚠ WARN  3 high/critical finding(s) detected\n```\n\nUse `--verbose` for score breakdowns, rule IDs, file/line locations, and remediation for each finding.\n\n## Exit Codes\n\n- `0` — audit passed the active policy\n- `1` — policy violation or fatal error\n\nUse the exit code directly to gate CI pipelines — no special flag required:\n\n```bash\nnpx agentsec --policy strict || exit 1\n```\n\n## Tips\n\n- Start with `npx agentsec` — no install, no flags. Iterate from there.\n- Add `--verbose` whenever you need to act on specific findings.\n- Pipe `--format json` into `jq` or a custom script for programmatic handling.\n- `strict` is the most common preset for production repositories.\n- Browse the agent skills ecosystem at [skills.sh](https://skills.sh).\n\nFile v0.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.4.0\",\n  \"publishedAt\": 1782929371606\n}\n\nFile v0.4.0:skill-card.md\n\n## Description:\n\nAudit AI agent skills for security vulnerabilities when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before running them, gating CI/CD on skill safety, or generating audit reports for stakeholders.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[markeljan](https://clawhub.ai/user/markeljan)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use Agentsec to audit installed agent skills, check OWASP Agentic Skills Top 10 coverage, gate CI/CD workflows, and generate security reports for stakeholders.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill recommends executing an npm-distributed CLI, including global installation options, to scan local skill directories.\n\nMitigation: Review before installing in sensitive environments and prefer a pinned version, lockfile-managed local install, or internally vetted package mirror.\n\nRisk: Default scans inspect multiple known skill directories and may cover more local content than intended.\n\nMitigation: Use targeted scans with --path or --platform when only selected skill directories should be inspected.\n\n## Reference(s):\n\n- [Agentsec homepage](https://agentsec.sh)\n- [Agent Skills specification](https://agentskills.io/specification)\n- [Skills.sh](https://skills.sh)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands; generated audit reports may be text, JSON, SARIF, or HTML.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can guide scans across default skill directories or targeted paths and platforms.]\n\n## Skill Version(s):\n\n0.4.0 (source: server release metadata and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.3.3: 3 files, 5626 bytes\n\nFiles: skill-card.md (2102b), SKILL.md (11072b), _meta.json (127b)\n\nFile v0.3.3:SKILL.md\n\n---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.3.3\nlicense: MIT\nhomepage: https://agentsec.sh\nauthor: semiotic-ai\npermissions:\n  - filesystem:read\nmetadata:\n  agentsec:\n    profile: meta\n  openclaw:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\nagentsec is agent-platform agnostic — every platform listed below ships skills in the [agentskills.io](https://agentskills.io/specification) `SKILL.md` format and is auto-discovered.\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Hermes**             | `~/.hermes/skills`, `~/.hermes/skills/*` (bundled categories), `./.hermes/skills`                                         |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n```bash\n# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list\n```\n\n## Installation\n\n`npx agentsec` needs no install. For repeated use, install globally:\n\n```bash\n# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec\n```\n\nThen drop the `npx` prefix:\n\n```bash\nagentsec\nagentsec scan --path ./my-skills\n```\n\n## Flags\n\nAll flags work with any command.\n\n| Flag         | Short | Values                          | Default    | Purpose                                                  |\n| ------------ | ----- | ------------------------------- | ---------- | -------------------------------------------------------- |\n| `--format`   | `-f`  | `text`, `json`, `sarif`, `html` | `text`     | Output format                                            |\n| `--output`   | `-o`  | path                            | stdout     | Write report to file                                     |\n| `--policy`   | `-p`  | preset name or path             | `default`  | Apply a policy preset                                    |\n| `--platform` |       | `openclaw`, `claude`, `codex`, `hermes` | auto | Narrow to one agent platform                             |\n| `--path`     |       | path                            | auto       | Custom skill directory to scan                           |\n| `--profile`  |       | `default`, `web3`, `strict`     | `default`  | Rule profile. `default` auto-detects Web3 skills; `web3` forces the annex on every skill |\n| `--verbose`  | `-v`  |                                 | off        | Show detailed findings                                   |\n| `--no-color` |       |                                 | off        | Disable colored output                                   |\n| `--help`     | `-h`  |                                 |            | Show help                                                |\n| `--version`  | `-V`  |                                 |            | Print version                                            |\n\n## Common Recipes\n\n### Show detailed findings and remediation\n\n```bash\nnpx agentsec --verbose\n```\n\n### Scan a specific directory\n\n```bash\nnpx agentsec scan --path ./my-skills\n```\n\n### Target a specific agent platform\n\n```bash\nnpx agentsec --platform claude\nnpx agentsec --platform codex\nnpx agentsec --platform hermes\nnpx agentsec --platform openclaw\n```\n\n### Audit with a strict policy and save JSON\n\n```bash\nnpx agentsec --policy strict --format json --output audit.json\n```\n\n### Generate an HTML report for stakeholders\n\n```bash\nnpx agentsec --format html --output report.html\n```\n\n### Generate a SARIF report for IDE / code-scanning integration\n\n```bash\nnpx agentsec --format sarif --output report.sarif\n```\n\n### List available policy presets\n\n```bash\nnpx agentsec policy list\n```\n\n### Inspect the rules in a preset\n\n```bash\nnpx agentsec policy show strict\n```\n\n### Validate a custom policy config file\n\n```bash\nnpx agentsec policy validate ./my-policy.json\n```\n\n### Replay a previous audit as an HTML report\n\n```bash\nnpx agentsec report audit.json --format html --output report.html\n```\n\n## Policy Presets\n\n| Name                 | Use Case                                                             |\n| -------------------- | -------------------------------------------------------------------- |\n| `default`            | Balanced policy. Blocks critical findings.                           |\n| `strict`             | Enterprise-grade. Blocks high and critical findings, enforces tests. |\n| `permissive`         | Lenient. Only blocks critical CVEs. Good for development.            |\n| `owasp-agent-top-10` | Built directly from the OWASP Agentic Skills Top 10.                 |\n\n## Configuration File\n\n`agentsec` auto-loads `.agentsecrc`, `.agentsecrc.json`, or `agentsec.config.json` from the current directory (or any parent):\n\n```json\n{\n  \"format\": \"text\",\n  \"output\": null,\n  \"policy\": \"strict\",\n  \"verbose\": false\n}\n```\n\nCLI flags always override config file values. Omit `\"platform\"` and `\"path\"` to keep the default auto-discovery behavior — agentsec will scan every known platform's default locations.\n\n## OWASP Agentic Skills Top 10\n\nEvery audit checks all ten risk categories:\n\n| ID    | Risk                    |\n| ----- | ----------------------- |\n| AST01 | Malicious Skills        |\n| AST02 | Supply Chain Compromise |\n| AST03 | Over-Privileged Skills  |\n| AST04 | Insecure Metadata       |\n| AST05 | Unsafe Deserialization  |\n| AST06 | Weak Isolation          |\n| AST07 | Update Drift            |\n| AST08 | Poor Scanning           |\n| AST09 | No Governance           |\n| AST10 | Cross-Platform Reuse    |\n\n## AST-10 Web3 Annex (auto-detected)\n\nWeb3-touching skills are detected automatically and audited against twelve additional rules — no flag required. A skill is detected as Web3 when its manifest declares a `web3:` block, when its source imports a Web3 client library (`viem`, `ethers`, `web3`, `wagmi`, `@solana/web3.js`, `@coinbase/onchainkit`, `@privy-io`, `@biconomy`, `@zerodev`), when it references a Web3 RPC method (`eth_*`, `wallet_*`, `personal_sign`, `signTypedData`), or when it ships a `.sol` file. Detected skills are tagged `[Web3]` in the output:\n\n```text\n✔ scoped-trader v1.4.0  [Web3]  C (62)\n✔ helpful-summarizer v1.2.0     A (95)\n```\n\n`--profile web3` is still available — it forces the annex onto every skill regardless of detection (useful for cross-team CI consistency):\n\n```bash\nnpx agentsec audit --profile web3 --path ./my-skills\n```\n\n| ID      | Risk                                            |\n| ------- | ----------------------------------------------- |\n| AST-W01 | Unbounded Signing Authority                     |\n| AST-W02 | Implicit Permit / Permit2 Signature Capture     |\n| AST-W03 | Delegation Hijack via EIP-7702                  |\n| AST-W04 | Blind / Opaque Signing Surface                  |\n| AST-W05 | RPC Endpoint Substitution & Mempool Leakage     |\n| AST-W06 | Unverified Contract Call Targets                |\n| AST-W07 | Cross-Chain / Bridge Action Replay              |\n| AST-W08 | MCP Chain-Tool Drift / Capability Smuggling     |\n| AST-W09 | Session-Key / Permission-Caveat Erosion         |\n| AST-W10 | Slippage / Oracle Manipulation by Agent Loop    |\n| AST-W11 | Key Material in Agent Memory / Logs             |\n| AST-W12 | No On-Chain Action Audit / Kill-Switch          |\n\nSkills can declare a `web3` block in their manifest (chains, signers, policy caps, session-key scopes, MCP server pinning, audit sink, kill-switch) so the annex can verify scoping without flagging well-bounded skills. See `docs/plans/ast10-web3-annex-rules.md` for full per-rule detection signals.\n\n## Understanding the Output\n\nDefault output is compact: each skill shows its grade and score, followed by a one-line finding summary and a PASS/WARN/FAIL status.\n\n```\n✔ Found 6 skills\n\n✔ fetch-data     v1.0.0  D (42)\n✔ deploy-helper  v2.3.0  C (68)\n✔ code-review    v1.1.0  A (95)\n\n6 skills scanned  •  avg score 78  •  4 certified\nFindings: 2 critical, 1 high, 2 medium\n\n⚠ WARN  3 high/critical finding(s) detected\n```\n\nUse `--verbose` for score breakdowns, rule IDs, file/line locations, and remediation for each finding.\n\n## Exit Codes\n\n- `0` — audit passed the active policy\n- `1` — policy violation or fatal error\n\nUse the exit code directly to gate CI pipelines — no special flag required:\n\n```bash\nnpx agentsec --policy strict || exit 1\n```\n\n## Tips\n\n- Start with `npx agentsec` — no install, no flags. Iterate from there.\n- Add `--verbose` whenever you need to act on specific findings.\n- Pipe `--format json` into `jq` or a custom script for programmatic handling.\n- `strict` is the most common preset for production repositories.\n- Browse the agent skills ecosystem at [skills.sh](https://skills.sh).\n\nFile v0.3.3:_meta.json\n\n{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.3.3\",\n  \"publishedAt\": 1779985500223\n}\n\nFile v0.3.3:skill-card.md\n\n## Description: <br>\nAudit AI agent skills for security vulnerabilities, including scans against the OWASP Agentic Skills Top 10, pre-run safety checks, CI/CD gating, and stakeholder audit reports. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[markeljan](https://clawhub.ai/user/markeljan) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, security reviewers, and platform teams use this skill to audit installed agent skills, check OWASP Agentic Skills Top 10 coverage, and generate text, JSON, SARIF, or HTML audit reports. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The default command scans known agent skill directories in home and nearby project paths, which may be broader than intended. <br>\nMitigation: Use a scoped command such as `npx agentsec scan --path ./skills` when auditing a specific directory. <br>\nRisk: Generated reports may reveal names or metadata of installed skills. <br>\nMitigation: Review reports before sharing them outside the intended audience. <br>\n\n\n## Reference(s): <br>\n- [Agentsec homepage](https://agentsec.sh) <br>\n- [Agent Skills specification](https://agentskills.io/specification) <br>\n- [ClawHub skill page](https://clawhub.ai/markeljan/agentsec) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and references to text, JSON, SARIF, and HTML report formats.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May advise scoped scans, policy presets, output paths, and report generation commands.] <br>\n\n## Skill Version(s): <br>\n0.3.3 (source: server release metadata and SKILL.md frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.3.2: 3 files, 5432 bytes\n\nFiles: skill-card.md (1854b), SKILL.md (10669b), _meta.json (127b)\n\nFile v0.3.2:SKILL.md\n\n---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.3.2\nlicense: MIT\nhomepage: https://agentsec.sh\nauthor: semiotic-ai\npermissions:\n  - filesystem:read\nmetadata:\n  agentsec:\n    profile: meta\n  openclaw:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n```bash\n# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list\n```\n\n## Installation\n\n`npx agentsec` needs no install. For repeated use, install globally:\n\n```bash\n# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec\n```\n\nThen drop the `npx` prefix:\n\n```bash\nagentsec\nagentsec scan --path ./my-skills\n```\n\n## Flags\n\nAll flags work with any command.\n\n| Flag         | Short | Values                          | Default    | Purpose                                                  |\n| ------------ | ----- | ------------------------------- | ---------- | -------------------------------------------------------- |\n| `--format`   | `-f`  | `text`, `json`, `sarif`, `html` | `text`     | Output format                                            |\n| `--output`   | `-o`  | path                            | stdout     | Write report to file                                     |\n| `--policy`   | `-p`  | preset name or path             | `default`  | Apply a policy preset                                    |\n| `--platform` |       | `openclaw`, `claude`, `codex`   | auto       | Narrow to one agent platform                             |\n| `--path`     |       | path                            | auto       | Custom skill directory to scan                           |\n| `--profile`  |       | `default`, `web3`, `strict`     | `default`  | Rule profile. `default` auto-detects Web3 skills; `web3` forces the annex on every skill |\n| `--verbose`  | `-v`  |                                 | off        | Show detailed findings                                   |\n| `--no-color` |       |                                 | off        | Disable colored output                                   |\n| `--help`     | `-h`  |                                 |            | Show help                                                |\n| `--version`  | `-V`  |                                 |            | Print version                                            |\n\n## Common Recipes\n\n### Show detailed findings and remediation\n\n```bash\nnpx agentsec --verbose\n```\n\n### Scan a specific directory\n\n```bash\nnpx agentsec scan --path ./my-skills\n```\n\n### Target a specific agent platform\n\n```bash\nnpx agentsec --platform claude\nnpx agentsec --platform codex\n```\n\n### Audit with a strict policy and save JSON\n\n```bash\nnpx agentsec --policy strict --format json --output audit.json\n```\n\n### Generate an HTML report for stakeholders\n\n```bash\nnpx agentsec --format html --output report.html\n```\n\n### Generate a SARIF report for IDE / code-scanning integration\n\n```bash\nnpx agentsec --format sarif --output report.sarif\n```\n\n### List available policy presets\n\n```bash\nnpx agentsec policy list\n```\n\n### Inspect the rules in a preset\n\n```bash\nnpx agentsec policy show strict\n```\n\n### Validate a custom policy config file\n\n```bash\nnpx agentsec policy validate ./my-policy.json\n```\n\n### Replay a previous audit as an HTML report\n\n```bash\nnpx agentsec report audit.json --format html --output report.html\n```\n\n## Policy Presets\n\n| Name                 | Use Case                                                             |\n| -------------------- | -------------------------------------------------------------------- |\n| `default`            | Balanced policy. Blocks critical findings.                           |\n| `strict`             | Enterprise-grade. Blocks high and critical findings, enforces tests. |\n| `permissive`         | Lenient. Only blocks critical CVEs. Good for development.            |\n| `owasp-agent-top-10` | Built directly from the OWASP Agentic Skills Top 10.                 |\n\n## Configuration File\n\n`agentsec` auto-loads `.agentsecrc`, `.agentsecrc.json`, or `agentsec.config.json` from the current directory (or any parent):\n\n```json\n{\n  \"format\": \"text\",\n  \"output\": null,\n  \"policy\": \"strict\",\n  \"verbose\": false\n}\n```\n\nCLI flags always override config file values. Omit `\"platform\"` and `\"path\"` to keep the default auto-discovery behavior — agentsec will scan every known platform's default locations.\n\n## OWASP Agentic Skills Top 10\n\nEvery audit checks all ten risk categories:\n\n| ID    | Risk                    |\n| ----- | ----------------------- |\n| AST01 | Malicious Skills        |\n| AST02 | Supply Chain Compromise |\n| AST03 | Over-Privileged Skills  |\n| AST04 | Insecure Metadata       |\n| AST05 | Unsafe Deserialization  |\n| AST06 | Weak Isolation          |\n| AST07 | Update Drift            |\n| AST08 | Poor Scanning           |\n| AST09 | No Governance           |\n| AST10 | Cross-Platform Reuse    |\n\n## AST-10 Web3 Annex (auto-detected)\n\nWeb3-touching skills are detected automatically and audited against twelve additional rules — no flag required. A skill is detected as Web3 when its manifest declares a `web3:` block, when its source imports a Web3 client library (`viem`, `ethers`, `web3`, `wagmi`, `@solana/web3.js`, `@coinbase/onchainkit`, `@privy-io`, `@biconomy`, `@zerodev`), when it references a Web3 RPC method (`eth_*`, `wallet_*`, `personal_sign`, `signTypedData`), or when it ships a `.sol` file. Detected skills are tagged `[Web3]` in the output:\n\n```text\n✔ scoped-trader v1.4.0  [Web3]  C (62)\n✔ helpful-summarizer v1.2.0     A (95)\n```\n\n`--profile web3` is still available — it forces the annex onto every skill regardless of detection (useful for cross-team CI consistency):\n\n```bash\nnpx agentsec audit --profile web3 --path ./my-skills\n```\n\n| ID      | Risk                                            |\n| ------- | ----------------------------------------------- |\n| AST-W01 | Unbounded Signing Authority                     |\n| AST-W02 | Implicit Permit / Permit2 Signature Capture     |\n| AST-W03 | Delegation Hijack via EIP-7702                  |\n| AST-W04 | Blind / Opaque Signing Surface                  |\n| AST-W05 | RPC Endpoint Substitution & Mempool Leakage     |\n| AST-W06 | Unverified Contract Call Targets                |\n| AST-W07 | Cross-Chain / Bridge Action Replay              |\n| AST-W08 | MCP Chain-Tool Drift / Capability Smuggling     |\n| AST-W09 | Session-Key / Permission-Caveat Erosion         |\n| AST-W10 | Slippage / Oracle Manipulation by Agent Loop    |\n| AST-W11 | Key Material in Agent Memory / Logs             |\n| AST-W12 | No On-Chain Action Audit / Kill-Switch          |\n\nSkills can declare a `web3` block in their manifest (chains, signers, policy caps, session-key scopes, MCP server pinning, audit sink, kill-switch) so the annex can verify scoping without flagging well-bounded skills. See `docs/plans/ast10-web3-annex-rules.md` for full per-rule detection signals.\n\n## Understanding the Output\n\nDefault output is compact: each skill shows its grade and score, followed by a one-line finding summary and a PASS/WARN/FAIL status.\n\n```\n✔ Found 6 skills\n\n✔ fetch-data     v1.0.0  D (42)\n✔ deploy-helper  v2.3.0  C (68)\n✔ code-review    v1.1.0  A (95)\n\n6 skills scanned  •  avg score 78  •  4 certified\nFindings: 2 critical, 1 high, 2 medium\n\n⚠ WARN  3 high/critical finding(s) detected\n```\n\nUse `--verbose` for score breakdowns, rule IDs, file/line locations, and remediation for each finding.\n\n## Exit Codes\n\n- `0` — audit passed the active policy\n- `1` — policy violation or fatal error\n\nUse the exit code directly to gate CI pipelines — no special flag required:\n\n```bash\nnpx agentsec --policy strict || exit 1\n```\n\n## Tips\n\n- Start with `npx agentsec` — no install, no flags. Iterate from there.\n- Add `--verbose` whenever you need to act on specific findings.\n- Pipe `--format json` into `jq` or a custom script for programmatic handling.\n- `strict` is the most common preset for production repositories.\n- Browse the agent skills ecosystem at [skills.sh](https://skills.sh).\n\nFile v0.3.2:_meta.json\n\n{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.3.2\",\n  \"publishedAt\": 1779379085343\n}\n\nFile v0.3.2:skill-card.md\n\n## Description: <br>\nAudit AI agent skills for security vulnerabilities against the OWASP Agentic Skills Top 10, including local scans, CI/CD gating, and stakeholder reports. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[markeljan](https://clawhub.ai/user/markeljan) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, security engineers, and platform maintainers use Agentsec to audit installed agent skills, check OWASP Agentic Skills Top 10 coverage, and produce reports or CI/CD gates before running skills. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Default scans can inspect broad local skill directories that may reveal private prompts, client work, or sensitive project structure. <br>\nMitigation: Use a narrowed path such as `npx agentsec scan --path ./my-skills` or a platform filter when scanning sensitive environments. <br>\n\n\n## Reference(s): <br>\n- [Agentsec Homepage](https://agentsec.sh) <br>\n- [ClawHub Agentsec Skill Page](https://clawhub.ai/markeljan/agentsec) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, json, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with shell commands and optional text, JSON, SARIF, or HTML audit reports] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Reports may be written to stdout or to files selected with CLI output flags.] <br>\n\n## Skill Version(s): <br>\n0.3.2 (source: frontmatter and server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.3.1: 2 files, 4315 bytes\n\nFiles: SKILL.md (10573b), _meta.json (127b)\n\nFile v0.3.1:SKILL.md\n\n---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.3.1\nhomepage: https://agentsec.sh\nmetadata:\n  openclaw:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n```bash\n# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list\n```\n\n## Installation\n\n`npx agentsec` needs no install. For repeated use, install globally:\n\n```bash\n# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec\n```\n\nThen drop the `npx` prefix:\n\n```bash\nagentsec\nagentsec scan --path ./my-skills\n```\n\n## Flags\n\nAll flags work with any command.\n\n| Flag         | Short | Values                          | Default    | Purpose                                                  |\n| ------------ | ----- | ------------------------------- | ---------- | -------------------------------------------------------- |\n| `--format`   | `-f`  | `text`, `json`, `sarif`, `html` | `text`     | Output format                                            |\n| `--output`   | `-o`  | path                            | stdout     | Write report to file                                     |\n| `--policy`   | `-p`  | preset name or path             | `default`  | Apply a policy preset                                    |\n| `--platform` |       | `openclaw`, `claude`, `codex`   | auto       | Narrow to one agent platform                             |\n| `--path`     |       | path                            | auto       | Custom skill directory to scan                           |\n| `--profile`  |       | `default`, `web3`, `strict`     | `default`  | Rule profile. `default` auto-detects Web3 skills; `web3` forces the annex on every skill |\n| `--verbose`  | `-v`  |                                 | off        | Show detailed findings                                   |\n| `--no-color` |       |                                 | off        | Disable colored output                                   |\n| `--help`     | `-h`  |                                 |            | Show help                                                |\n| `--version`  | `-V`  |                                 |            | Print version                                            |\n\n## Common Recipes\n\n### Show detailed findings and remediation\n\n```bash\nnpx agentsec --verbose\n```\n\n### Scan a specific directory\n\n```bash\nnpx agentsec scan --path ./my-skills\n```\n\n### Target a specific agent platform\n\n```bash\nnpx agentsec --platform claude\nnpx agentsec --platform codex\n```\n\n### Audit with a strict policy and save JSON\n\n```bash\nnpx agentsec --policy strict --format json --output audit.json\n```\n\n### Generate an HTML report for stakeholders\n\n```bash\nnpx agentsec --format html --output report.html\n```\n\n### Generate a SARIF report for IDE / code-scanning integration\n\n```bash\nnpx agentsec --format sarif --output report.sarif\n```\n\n### List available policy presets\n\n```bash\nnpx agentsec policy list\n```\n\n### Inspect the rules in a preset\n\n```bash\nnpx agentsec policy show strict\n```\n\n### Validate a custom policy config file\n\n```bash\nnpx agentsec policy validate ./my-policy.json\n```\n\n### Replay a previous audit as an HTML report\n\n```bash\nnpx agentsec report audit.json --format html --output report.html\n```\n\n## Policy Presets\n\n| Name                 | Use Case                                                             |\n| -------------------- | -------------------------------------------------------------------- |\n| `default`            | Balanced policy. Blocks critical findings.                           |\n| `strict`             | Enterprise-grade. Blocks high and critical findings, enforces tests. |\n| `permissive`         | Lenient. Only blocks critical CVEs. Good for development.            |\n| `owasp-agent-top-10` | Built directly from the OWASP Agentic Skills Top 10.                 |\n\n## Configuration File\n\n`agentsec` auto-loads `.agentsecrc`, `.agentsecrc.json`, or `agentsec.config.json` from the current directory (or any parent):\n\n```json\n{\n  \"format\": \"text\",\n  \"output\": null,\n  \"policy\": \"strict\",\n  \"verbose\": false\n}\n```\n\nCLI flags always override config file values. Omit `\"platform\"` and `\"path\"` to keep the default auto-discovery behavior — agentsec will scan every known platform's default locations.\n\n## OWASP Agentic Skills Top 10\n\nEvery audit checks all ten risk categories:\n\n| ID    | Risk                    |\n| ----- | ----------------------- |\n| AST01 | Malicious Skills        |\n| AST02 | Supply Chain Compromise |\n| AST03 | Over-Privileged Skills  |\n| AST04 | Insecure Metadata       |\n| AST05 | Unsafe Deserialization  |\n| AST06 | Weak Isolation          |\n| AST07 | Update Drift            |\n| AST08 | Poor Scanning           |\n| AST09 | No Governance           |\n| AST10 | Cross-Platform Reuse    |\n\n## AST-10 Web3 Annex (auto-detected)\n\nWeb3-touching skills are detected automatically and audited against twelve additional rules — no flag required. A skill is detected as Web3 when its manifest declares a `web3:` block, when its source imports a Web3 client library (`viem`, `ethers`, `web3`, `wagmi`, `@solana/web3.js`, `@coinbase/onchainkit`, `@privy-io`, `@biconomy`, `@zerodev`), when it references a Web3 RPC method (`eth_*`, `wallet_*`, `personal_sign`, `signTypedData`), or when it ships a `.sol` file. Detected skills are tagged `[Web3]` in the output:\n\n```text\n✔ scoped-trader v1.4.0  [Web3]  C (62)\n✔ helpful-summarizer v1.2.0     A (95)\n```\n\n`--profile web3` is still available — it forces the annex onto every skill regardless of detection (useful for cross-team CI consistency):\n\n```bash\nnpx agentsec audit --profile web3 --path ./my-skills\n```\n\n| ID      | Risk                                            |\n| ------- | ----------------------------------------------- |\n| AST-W01 | Unbounded Signing Authority                     |\n| AST-W02 | Implicit Permit / Permit2 Signature Capture     |\n| AST-W03 | Delegation Hijack via EIP-7702                  |\n| AST-W04 | Blind / Opaque Signing Surface                  |\n| AST-W05 | RPC Endpoint Substitution & Mempool Leakage     |\n| AST-W06 | Unverified Contract Call Targets                |\n| AST-W07 | Cross-Chain / Bridge Action Replay              |\n| AST-W08 | MCP Chain-Tool Drift / Capability Smuggling     |\n| AST-W09 | Session-Key / Permission-Caveat Erosion         |\n| AST-W10 | Slippage / Oracle Manipulation by Agent Loop    |\n| AST-W11 | Key Material in Agent Memory / Logs             |\n| AST-W12 | No On-Chain Action Audit / Kill-Switch          |\n\nSkills can declare a `web3` block in their manifest (chains, signers, policy caps, session-key scopes, MCP server pinning, audit sink, kill-switch) so the annex can verify scoping without flagging well-bounded skills. See `docs/plans/ast10-web3-annex-rules.md` for full per-rule detection signals.\n\n## Understanding the Output\n\nDefault output is compact: each skill shows its grade and score, followed by a one-line finding summary and a PASS/WARN/FAIL status.\n\n```\n✔ Found 6 skills\n\n✔ fetch-data     v1.0.0  D (42)\n✔ deploy-helper  v2.3.0  C (68)\n✔ code-review    v1.1.0  A (95)\n\n6 skills scanned  •  avg score 78  •  4 certified\nFindings: 2 critical, 1 high, 2 medium\n\n⚠ WARN  3 high/critical finding(s) detected\n```\n\nUse `--verbose` for score breakdowns, rule IDs, file/line locations, and remediation for each finding.\n\n## Exit Codes\n\n- `0` — audit passed the active policy\n- `1` — policy violation or fatal error\n\nUse the exit code directly to gate CI pipelines — no special flag required:\n\n```bash\nnpx agentsec --policy strict || exit 1\n```\n\n## Tips\n\n- Start with `npx agentsec` — no install, no flags. Iterate from there.\n- Add `--verbose` whenever you need to act on specific findings.\n- Pipe `--format json` into `jq` or a custom script for programmatic handling.\n- `strict` is the most common preset for production repositories.\n- Browse the agent skills ecosystem at [skills.sh](https://skills.sh).\n\nFile v0.3.1:_meta.json\n\n{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.3.1\",\n  \"publishedAt\": 1779375136754\n}\n\nArchive v0.3.0: 2 files, 4314 bytes\n\nFiles: SKILL.md (10573b), _meta.json (127b)\n\nFile v0.3.0:SKILL.md\n\n---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.3.0\nhomepage: https://agentsec.sh\nmetadata:\n  openclaw:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n```bash\n# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list\n```\n\n## Installation\n\n`npx agentsec` needs no install. For repeated use, install globally:\n\n```bash\n# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec\n```\n\nThen drop the `npx` prefix:\n\n```bash\nagentsec\nagentsec scan --path ./my-skills\n```\n\n## Flags\n\nAll flags work with any command.\n\n| Flag         | Short | Values                          | Default    | Purpose                                                  |\n| ------------ | ----- | ------------------------------- | ---------- | -------------------------------------------------------- |\n| `--format`   | `-f`  | `text`, `json`, `sarif`, `html` | `text`     | Output format                                            |\n| `--output`   | `-o`  | path                            | stdout     | Write report to file                                     |\n| `--policy`   | `-p`  | preset name or path             | `default`  | Apply a policy preset                                    |\n| `--platform` |       | `openclaw`, `claude`, `codex`   | auto       | Narrow to one agent platform                             |\n| `--path`     |       | path                            | auto       | Custom skill directory to scan                           |\n| `--profile`  |       | `default`, `web3`, `strict`     | `default`  | Rule profile. `default` auto-detects Web3 skills; `web3` forces the annex on every skill |\n| `--verbose`  | `-v`  |                                 | off        | Show detailed findings                                   |\n| `--no-color` |       |                                 | off        | Disable colored output                                   |\n| `--help`     | `-h`  |                                 |            | Show help                                                |\n| `--version`  | `-V`  |                                 |            | Print version                                            |\n\n## Common Recipes\n\n### Show detailed findings and remediation\n\n```bash\nnpx agentsec --verbose\n```\n\n### Scan a specific directory\n\n```bash\nnpx agentsec scan --path ./my-skills\n```\n\n### Target a specific agent platform\n\n```bash\nnpx agentsec --platform claude\nnpx agentsec --platform codex\n```\n\n### Audit with a strict policy and save JSON\n\n```bash\nnpx agentsec --policy strict --format json --output audit.json\n```\n\n### Generate an HTML report for stakeholders\n\n```bash\nnpx agentsec --format html --output report.html\n```\n\n### Generate a SARIF report for IDE / code-scanning integration\n\n```bash\nnpx agentsec --format sarif --output report.sarif\n```\n\n### List available policy presets\n\n```bash\nnpx agentsec policy list\n```\n\n### Inspect the rules in a preset\n\n```bash\nnpx agentsec policy show strict\n```\n\n### Validate a custom policy config file\n\n```bash\nnpx agentsec policy validate ./my-policy.json\n```\n\n### Replay a previous audit as an HTML report\n\n```bash\nnpx agentsec report audit.json --format html --output report.html\n```\n\n## Policy Presets\n\n| Name                 | Use Case                                                             |\n| -------------------- | -------------------------------------------------------------------- |\n| `default`            | Balanced policy. Blocks critical findings.                           |\n| `strict`             | Enterprise-grade. Blocks high and critical findings, enforces tests. |\n| `permissive`         | Lenient. Only blocks critical CVEs. Good for development.            |\n| `owasp-agent-top-10` | Built directly from the OWASP Agentic Skills Top 10.                 |\n\n## Configuration File\n\n`agentsec` auto-loads `.agentsecrc`, `.agentsecrc.json`, or `agentsec.config.json` from the current directory (or any parent):\n\n```json\n{\n  \"format\": \"text\",\n  \"output\": null,\n  \"policy\": \"strict\",\n  \"verbose\": false\n}\n```\n\nCLI flags always override config file values. Omit `\"platform\"` and `\"path\"` to keep the default auto-discovery behavior — agentsec will scan every known platform's default locations.\n\n## OWASP Agentic Skills Top 10\n\nEvery audit checks all ten risk categories:\n\n| ID    | Risk                    |\n| ----- | ----------------------- |\n| AST01 | Malicious Skills        |\n| AST02 | Supply Chain Compromise |\n| AST03 | Over-Privileged Skills  |\n| AST04 | Insecure Metadata       |\n| AST05 | Unsafe Deserialization  |\n| AST06 | Weak Isolation          |\n| AST07 | Update Drift            |\n| AST08 | Poor Scanning           |\n| AST09 | No Governance           |\n| AST10 | Cross-Platform Reuse    |\n\n## AST-10 Web3 Annex (auto-detected)\n\nWeb3-touching skills are detected automatically and audited against twelve additional rules — no flag required. A skill is detected as Web3 when its manifest declares a `web3:` block, when its source imports a Web3 client library (`viem`, `ethers`, `web3`, `wagmi`, `@solana/web3.js`, `@coinbase/onchainkit`, `@privy-io`, `@biconomy`, `@zerodev`), when it references a Web3 RPC method (`eth_*`, `wallet_*`, `personal_sign`, `signTypedData`), or when it ships a `.sol` file. Detected skills are tagged `[Web3]` in the output:\n\n```text\n✔ scoped-trader v1.4.0  [Web3]  C (62)\n✔ helpful-summarizer v1.2.0     A (95)\n```\n\n`--profile web3` is still available — it forces the annex onto every skill regardless of detection (useful for cross-team CI consistency):\n\n```bash\nnpx agentsec audit --profile web3 --path ./my-skills\n```\n\n| ID      | Risk                                            |\n| ------- | ----------------------------------------------- |\n| AST-W01 | Unbounded Signing Authority                     |\n| AST-W02 | Implicit Permit / Permit2 Signature Capture     |\n| AST-W03 | Delegation Hijack via EIP-7702                  |\n| AST-W04 | Blind / Opaque Signing Surface                  |\n| AST-W05 | RPC Endpoint Substitution & Mempool Leakage     |\n| AST-W06 | Unverified Contract Call Targets                |\n| AST-W07 | Cross-Chain / Bridge Action Replay              |\n| AST-W08 | MCP Chain-Tool Drift / Capability Smuggling     |\n| AST-W09 | Session-Key / Permission-Caveat Erosion         |\n| AST-W10 | Slippage / Oracle Manipulation by Agent Loop    |\n| AST-W11 | Key Material in Agent Memory / Logs             |\n| AST-W12 | No On-Chain Action Audit / Kill-Switch          |\n\nSkills can declare a `web3` block in their manifest (chains, signers, policy caps, session-key scopes, MCP server pinning, audit sink, kill-switch) so the annex can verify scoping without flagging well-bounded skills. See `docs/plans/ast10-web3-annex-rules.md` for full per-rule detection signals.\n\n## Understanding the Output\n\nDefault output is compact: each skill shows its grade and score, followed by a one-line finding summary and a PASS/WARN/FAIL status.\n\n```\n✔ Found 6 skills\n\n✔ fetch-data     v1.0.0  D (42)\n✔ deploy-helper  v2.3.0  C (68)\n✔ code-review    v1.1.0  A (95)\n\n6 skills scanned  •  avg score 78  •  4 certified\nFindings: 2 critical, 1 high, 2 medium\n\n⚠ WARN  3 high/critical finding(s) detected\n```\n\nUse `--verbose` for score breakdowns, rule IDs, file/line locations, and remediation for each finding.\n\n## Exit Codes\n\n- `0` — audit passed the active policy\n- `1` — policy violation or fatal error\n\nUse the exit code directly to gate CI pipelines — no special flag required:\n\n```bash\nnpx agentsec --policy strict || exit 1\n```\n\n## Tips\n\n- Start with `npx agentsec` — no install, no flags. Iterate from there.\n- Add `--verbose` whenever you need to act on specific findings.\n- Pipe `--format json` into `jq` or a custom script for programmatic handling.\n- `strict` is the most common preset for production repositories.\n- Browse the agent skills ecosystem at [skills.sh](https://skills.sh).\n\nFile v0.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.3.0\",\n  \"publishedAt\": 1778169363899\n}\n\nArchive v0.2.7: 2 files, 4315 bytes\n\nFiles: SKILL.md (10573b), _meta.json (127b)\n\nFile v0.2.7:SKILL.md\n\n---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.2.7\nhomepage: https://agentsec.sh\nmetadata:\n  openclaw:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n```bash\n# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list\n```\n\n## Installation\n\n`npx agentsec` needs no install. For repeated use, install globally:\n\n```bash\n# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec\n```\n\nThen drop the `npx` prefix:\n\n```bash\nagentsec\nagentsec scan --path ./my-skills\n```\n\n## Flags\n\nAll flags work with any command.\n\n| Flag         | Short | Values                          | Default    | Purpose                                                  |\n| ------------ | ----- | ------------------------------- | ---------- | -------------------------------------------------------- |\n| `--format`   | `-f`  | `text`, `json`, `sarif`, `html` | `text`     | Output format                                            |\n| `--output`   | `-o`  | path                            | stdout     | Write report to file                                     |\n| `--policy`   | `-p`  | preset name or path             | `default`  | Apply a policy preset                                    |\n| `--platform` |       | `openclaw`, `claude`, `codex`   | auto       | Narrow to one agent platform                             |\n| `--path`     |       | path                            | auto       | Custom skill directory to scan                           |\n| `--profile`  |       | `default`, `web3`, `strict`     | `default`  | Rule profile. `default` auto-detects Web3 skills; `web3` forces the annex on every skill |\n| `--verbose`  | `-v`  |                                 | off        | Show detailed findings                                   |\n| `--no-color` |       |                                 | off        | Disable colored output                                   |\n| `--help`     | `-h`  |                                 |            | Show help                                                |\n| `--version`  | `-V`  |                                 |            | Print version                                            |\n\n## Common Recipes\n\n### Show detailed findings and remediation\n\n```bash\nnpx agentsec --verbose\n```\n\n### Scan a specific directory\n\n```bash\nnpx agentsec scan --path ./my-skills\n```\n\n### Target a specific agent platform\n\n```bash\nnpx agentsec --platform claude\nnpx agentsec --platform codex\n```\n\n### Audit with a strict policy and save JSON\n\n```bash\nnpx agentsec --policy strict --format json --output audit.json\n```\n\n### Generate an HTML report for stakeholders\n\n```bash\nnpx agentsec --format html --output report.html\n```\n\n### Generate a SARIF report for IDE / code-scanning integration\n\n```bash\nnpx agentsec --format sarif --output report.sarif\n```\n\n### List available policy presets\n\n```bash\nnpx agentsec policy list\n```\n\n### Inspect the rules in a preset\n\n```bash\nnpx agentsec policy show strict\n```\n\n### Validate a custom policy config file\n\n```bash\nnpx agentsec policy validate ./my-policy.json\n```\n\n### Replay a previous audit as an HTML report\n\n```bash\nnpx agentsec report audit.json --format html --output report.html\n```\n\n## Policy Presets\n\n| Name                 | Use Case                                                             |\n| -------------------- | -------------------------------------------------------------------- |\n| `default`            | Balanced policy. Blocks critical findings.                           |\n| `strict`             | Enterprise-grade. Blocks high and critical findings, enforces tests. |\n| `permissive`         | Lenient. Only blocks critical CVEs. Good for development.            |\n| `owasp-agent-top-10` | Built directly from the OWASP Agentic Skills Top 10.                 |\n\n## Configuration File\n\n`agentsec` auto-loads `.agentsecrc`, `.agentsecrc.json`, or `agentsec.config.json` from the current directory (or any parent):\n\n```json\n{\n  \"format\": \"text\",\n  \"output\": null,\n  \"policy\": \"strict\",\n  \"verbose\": false\n}\n```\n\nCLI flags always override config file values. Omit `\"platform\"` and `\"path\"` to keep the default auto-discovery behavior — agentsec will scan every known platform's default locations.\n\n## OWASP Agentic Skills Top 10\n\nEvery audit checks all ten risk categories:\n\n| ID    | Risk                    |\n| ----- | ----------------------- |\n| AST01 | Malicious Skills        |\n| AST02 | Supply Chain Compromise |\n| AST03 | Over-Privileged Skills  |\n| AST04 | Insecure Metadata       |\n| AST05 | Unsafe Deserialization  |\n| AST06 | Weak Isolation          |\n| AST07 | Update Drift            |\n| AST08 | Poor Scanning           |\n| AST09 | No Governance           |\n| AST10 | Cross-Platform Reuse    |\n\n## AST-10 Web3 Annex (auto-detected)\n\nWeb3-touching skills are detected automatically and audited against twelve additional rules — no flag required. A skill is detected as Web3 when its manifest declares a `web3:` block, when its source imports a Web3 client library (`viem`, `ethers`, `web3`, `wagmi`, `@solana/web3.js`, `@coinbase/onchainkit`, `@privy-io`, `@biconomy`, `@zerodev`), when it references a Web3 RPC method (`eth_*`, `wallet_*`, `personal_sign`, `signTypedData`), or when it ships a `.sol` file. Detected skills are tagged `[Web3]` in the output:\n\n```text\n✔ scoped-trader v1.4.0  [Web3]  C (62)\n✔ helpful-summarizer v1.2.0     A (95)\n```\n\n`--profile web3` is still available — it forces the annex onto every skill regardless of detection (useful for cross-team CI consistency):\n\n```bash\nnpx agentsec audit --profile web3 --path ./my-skills\n```\n\n| ID      | Risk                                            |\n| ------- | ----------------------------------------------- |\n| AST-W01 | Unbounded Signing Authority                     |\n| AST-W02 | Implicit Permit / Permit2 Signature Capture     |\n| AST-W03 | Delegation Hijack via EIP-7702                  |\n| AST-W04 | Blind / Opaque Signing Surface                  |\n| AST-W05 | RPC Endpoint Substitution & Mempool Leakage     |\n| AST-W06 | Unverified Contract Call Targets                |\n| AST-W07 | Cross-Chain / Bridge Action Replay              |\n| AST-W08 | MCP Chain-Tool Drift / Capability Smuggling     |\n| AST-W09 | Session-Key / Permission-Caveat Erosion         |\n| AST-W10 | Slippage / Oracle Manipulation by Agent Loop    |\n| AST-W11 | Key Material in Agent Memory / Logs             |\n| AST-W12 | No On-Chain Action Audit / Kill-Switch          |\n\nSkills can declare a `web3` block in their manifest (chains, signers, policy caps, session-key scopes, MCP server pinning, audit sink, kill-switch) so the annex can verify scoping without flagging well-bounded skills. See `docs/plans/ast10-web3-annex-rules.md` for full per-rule detection signals.\n\n## Understanding the Output\n\nDefault output is compact: each skill shows its grade and score, followed by a one-line finding summary and a PASS/WARN/FAIL status.\n\n```\n✔ Found 6 skills\n\n✔ fetch-data     v1.0.0  D (42)\n✔ deploy-helper  v2.3.0  C (68)\n✔ code-review    v1.1.0  A (95)\n\n6 skills scanned  •  avg score 78  •  4 certified\nFindings: 2 critical, 1 high, 2 medium\n\n⚠ WARN  3 high/critical finding(s) detected\n```\n\nUse `--verbose` for score breakdowns, rule IDs, file/line locations, and remediation for each finding.\n\n## Exit Codes\n\n- `0` — audit passed the active policy\n- `1` — policy violation or fatal error\n\nUse the exit code directly to gate CI pipelines — no special flag required:\n\n```bash\nnpx agentsec --policy strict || exit 1\n```\n\n## Tips\n\n- Start with `npx agentsec` — no install, no flags. Iterate from there.\n- Add `--verbose` whenever you need to act on specific findings.\n- Pipe `--format json` into `jq` or a custom script for programmatic handling.\n- `strict` is the most common preset for production repositories.\n- Browse the agent skills ecosystem at [skills.sh](https://skills.sh).\n\nFile v0.2.7:_meta.json\n\n{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.2.7\",\n  \"publishedAt\": 1778108941832\n}\n\nArchive v0.2.6: 2 files, 4316 bytes\n\nFiles: SKILL.md (10573b), _meta.json (127b)\n\nFile v0.2.6:SKILL.md\n\n---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.2.6\nhomepage: https://agentsec.sh\nmetadata:\n  openclaw:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n```bash\n# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list\n```\n\n## Installation\n\n`npx agentsec` needs no install. For repeated use, install globally:\n\n```bash\n# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec\n```\n\nThen drop the `npx` prefix:\n\n```bash\nagentsec\nagentsec scan --path ./my-skills\n```\n\n## Flags\n\nAll flags work with any command.\n\n| Flag         | Short | Values                          | Default    | Purpose                                                  |\n| ------------ | ----- | ------------------------------- | ---------- | -------------------------------------------------------- |\n| `--format`   | `-f`  | `text`, `json`, `sarif`, `html` | `text`     | Output format                                            |\n| `--output`   | `-o`  | path                            | stdout     | Write report to file                                     |\n| `--policy`   | `-p`  | preset name or path             | `default`  | Apply a policy preset                                    |\n| `--platform` |       | `openclaw`, `claude`, `codex`   | auto       | Narrow to one agent platform                             |\n| `--path`     |       | path                            | auto       | Custom skill directory to scan                           |\n| `--profile`  |       | `default`, `web3`, `strict`     | `default`  | Rule profile. `default` auto-detects Web3 skills; `web3` forces the annex on every skill |\n| `--verbose`  | `-v`  |                                 | off        | Show detailed findings                                   |\n| `--no-color` |       |                                 | off        | Disable colored output                                   |\n| `--help`     | `-h`  |                                 |            | Show help                                                |\n| `--version`  | `-V`  |                                 |            | Print version                                            |\n\n## Common Recipes\n\n### Show detailed findings and remediation\n\n```bash\nnpx agentsec --verbose\n```\n\n### Scan a specific directory\n\n```bash\nnpx agentsec scan --path ./my-skills\n```\n\n### Target a specific agent platform\n\n```bash\nnpx agentsec --platform claude\nnpx agentsec --platform codex\n```\n\n### Audit with a strict policy and save JSON\n\n```bash\nnpx agentsec --policy strict --format json --output audit.json\n```\n\n### Generate an HTML report for stakeholders\n\n```bash\nnpx agentsec --format html --output report.html\n```\n\n### Generate a SARIF report for IDE / code-scanning integration\n\n```bash\nnpx agentsec --format sarif --output report.sarif\n```\n\n### List available policy presets\n\n```bash\nnpx agentsec policy list\n```\n\n### Inspect the rules in a preset\n\n```bash\nnpx agentsec policy show strict\n```\n\n### Validate a custom policy config file\n\n```bash\nnpx agentsec policy validate ./my-policy.json\n```\n\n### Replay a previous audit as an HTML report\n\n```bash\nnpx agentsec report audit.json --format html --output report.html\n```\n\n## Policy Presets\n\n| Name                 | Use Case                                                             |\n| -------------------- | -------------------------------------------------------------------- |\n| `default`            | Balanced policy. Blocks critical findings.                           |\n| `strict`             | Enterprise-grade. Blocks high and critical findings, enforces tests. |\n| `permissive`         | Lenient. Only blocks critical CVEs. Good for development.            |\n| `owasp-agent-top-10` | Built directly from the OWASP Agentic Skills Top 10.                 |\n\n## Configuration File\n\n`agentsec` auto-loads `.agentsecrc`, `.agentsecrc.json`, or `agentsec.config.json` from the current directory (or any parent):\n\n```json\n{\n  \"format\": \"text\",\n  \"output\": null,\n  \"policy\": \"strict\",\n  \"verbose\": false\n}\n```\n\nCLI flags always override config file values. Omit `\"platform\"` and `\"path\"` to keep the default auto-discovery behavior — agentsec will scan every known platform's default locations.\n\n## OWASP Agentic Skills Top 10\n\nEvery audit checks all ten risk categories:\n\n| ID    | Risk                    |\n| ----- | ----------------------- |\n| AST01 | Malicious Skills        |\n| AST02 | Supply Chain Compromise |\n| AST03 | Over-Privileged Skills  |\n| AST04 | Insecure Metadata       |\n| AST05 | Unsafe Deserialization  |\n| AST06 | Weak Isolation          |\n| AST07 | Update Drift            |\n| AST08 | Poor Scanning           |\n| AST09 | No Governance           |\n| AST10 | Cross-Platform Reuse    |\n\n## AST-10 Web3 Annex (auto-detected)\n\nWeb3-touching skills are detected automatically and audited against twelve additional rules — no flag required. A skill is detected as Web3 when its manifest declares a `web3:` block, when its source imports a Web3 client library (`viem`, `ethers`, `web3`, `wagmi`, `@solana/web3.js`, `@coinbase/onchainkit`, `@privy-io`, `@biconomy`, `@zerodev`), when it references a Web3 RPC method (`eth_*`, `wallet_*`, `personal_sign`, `signTypedData`), or when it ships a `.sol` file. Detected skills are tagged `[Web3]` in the output:\n\n```text\n✔ scoped-trader v1.4.0  [Web3]  C (62)\n✔ helpful-summarizer v1.2.0     A (95)\n```\n\n`--profile web3` is still available — it forces the annex onto every skill regardless of detection (useful for cross-team CI consistency):\n\n```bash\nnpx agentsec audit --profile web3 --path ./my-skills\n```\n\n| ID      | Risk                                            |\n| ------- | ----------------------------------------------- |\n| AST-W01 | Unbounded Signing Authority                     |\n| AST-W02 | Implicit Permit / Permit2 Signature Capture     |\n| AST-W03 | Delegation Hijack via EIP-7702                  |\n| AST-W04 | Blind / Opaque Signing Surface                  |\n| AST-W05 | RPC Endpoint Substitution & Mempool Leakage     |\n| AST-W06 | Unverified Contract Call Targets                |\n| AST-W07 | Cross-Chain / Bridge Action Replay              |\n| AST-W08 | MCP Chain-Tool Drift / Capability Smuggling     |\n| AST-W09 | Session-Key / Permission-Caveat Erosion         |\n| AST-W10 | Slippage / Oracle Manipulation by Agent Loop    |\n| AST-W11 | Key Material in Agent Memory / Logs             |\n| AST-W12 | No On-Chain Action Audit / Kill-Switch          |\n\nSkills can declare a `web3` block in their manifest (chains, signers, policy caps, session-key scopes, MCP server pinning, audit sink, kill-switch) so the annex can verify scoping without flagging well-bounded skills. See `docs/plans/ast10-web3-annex-rules.md` for full per-rule detection signals.\n\n## Understanding the Output\n\nDefault output is compact: each skill shows its grade and score, followed by a one-line finding summary and a PASS/WARN/FAIL status.\n\n```\n✔ Found 6 skills\n\n✔ fetch-data     v1.0.0  D (42)\n✔ deploy-helper  v2.3.0  C (68)\n✔ code-review    v1.1.0  A (95)\n\n6 skills scanned  •  avg score 78  •  4 certified\nFindings: 2 critical, 1 high, 2 medium\n\n⚠ WARN  3 high/critical finding(s) detected\n```\n\nUse `--verbose` for score breakdowns, rule IDs, file/line locations, and remediation for each finding.\n\n## Exit Codes\n\n- `0` — audit passed the active policy\n- `1` — policy violation or fatal error\n\nUse the exit code directly to gate CI pipelines — no special flag required:\n\n```bash\nnpx agentsec --policy strict || exit 1\n```\n\n## Tips\n\n- Start with `npx agentsec` — no install, no flags. Iterate from there.\n- Add `--verbose` whenever you need to act on specific findings.\n- Pipe `--format json` into `jq` or a custom script for programmatic handling.\n- `strict` is the most common preset for production repositories.\n- Browse the agent skills ecosystem at [skills.sh](https://skills.sh).\n\nFile v0.2.6:_meta.json\n\n{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.2.6\",\n  \"publishedAt\": 1778093777112\n}\n\nArchive v0.1.5: 2 files, 3360 bytes\n\nFiles: SKILL.md (8087b), _meta.json (127b)\n\nFile v0.1.5:SKILL.md\n\n---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.1.5\nhomepage: https://agentsec.sh\nmetadata:\n  clawdbot:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n```bash\n# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list\n```\n\n## Installation\n\n`npx agentsec` needs no install. For repeated use, install globally:\n\n```bash\n# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec\n```\n\nThen drop the `npx` prefix:\n\n```bash\nagentsec\nagentsec scan --path ./my-skills\n```\n\n## Flags\n\nAll flags work with any command.\n\n| Flag         | Short | Values                          | Default    | Purpose                        |\n| ------------ | ----- | ------------------------------- | ---------- | ------------------------------ |\n| `--format`   | `-f`  | `text`, `json`, `sarif`, `html` | `text`     | Output format                  |\n| `--output`   | `-o`  | path                            | stdout     | Write report to file           |\n| `--policy`   | `-p`  | preset name or path             | `default`  | Apply a policy preset          |\n| `--platform` |       | `openclaw`, `claude`, `codex`   | auto       | Narrow to one agent platform   |\n| `--path`     |       | path                            | auto       | Custom skill directory to scan |\n| `--verbose`  | `-v`  |                                 | off        | Show detailed findings         |\n| `--no-color` |       |                                 | off        | Disable colored output         |\n| `--help`     | `-h`  |                                 |            | Show help                      |\n| `--version`  | `-V`  |                                 |            | Print version                  |\n\n## Common Recipes\n\n### Show detailed findings and remediation\n\n```bash\nnpx agentsec --verbose\n```\n\n### Scan a specific directory\n\n```bash\nnpx agentsec scan --path ./my-skills\n```\n\n### Target a specific agent platform\n\n```bash\nnpx agentsec --platform claude\nnpx agentsec --platform codex\n```\n\n### Audit with a strict policy and save JSON\n\n```bash\nnpx agentsec --policy strict --format json --output audit.json\n```\n\n### Generate an HTML report for stakeholders\n\n```bash\nnpx agentsec --format html --output report.html\n```\n\n### Generate a SARIF report for IDE / code-scanning integration\n\n```bash\nnpx agentsec --format sarif --output report.sarif\n```\n\n### List available policy presets\n\n```bash\nnpx agentsec policy list\n```\n\n### Inspect the rules in a preset\n\n```bash\nnpx agentsec policy show strict\n```\n\n### Validate a custom policy config file\n\n```bash\nnpx agentsec policy validate ./my-policy.json\n```\n\n### Replay a previous audit as an HTML report\n\n```bash\nnpx agentsec report audit.json --format html --output report.html\n```\n\n## Policy Presets\n\n| Name                 | Use Case                                                             |\n| -------------------- | -------------------------------------------------------------------- |\n| `default`            | Balanced policy. Blocks critical findings.                           |\n| `strict`             | Enterprise-grade. Blocks high and critical findings, enforces tests. |\n| `permissive`         | Lenient. Only blocks critical CVEs. Good for development.            |\n| `owasp-agent-top-10` | Built directly from the OWASP Agentic Skills Top 10.                 |\n\n## Configuration File\n\n`agentsec` auto-loads `.agentsecrc`, `.agentsecrc.json`, or `agentsec.config.json` from the current directory (or any parent):\n\n```json\n{\n  \"format\": \"text\",\n  \"output\": null,\n  \"policy\": \"strict\",\n  \"verbose\": false\n}\n```\n\nCLI flags always override config file values. Omit `\"platform\"` and `\"path\"` to keep the default auto-discovery behavior — agentsec will scan every known platform's default locations.\n\n## OWASP Agentic Skills Top 10\n\nEvery audit checks all ten risk categories:\n\n| ID    | Risk                    |\n| ----- | ----------------------- |\n| AST01 | Malicious Skills        |\n| AST02 | Supply Chain Compromise |\n| AST03 | Over-Privileged Skills  |\n| AST04 | Insecure Metadata       |\n| AST05 | Unsafe Deserialization  |\n| AST06 | Weak Isolation          |\n| AST07 | Update Drift            |\n| AST08 | Poor Scanning           |\n| AST09 | No Governance           |\n| AST10 | Cross-Platform Reuse    |\n\n## Understanding the Output\n\nDefault output is compact: each skill shows its grade and score, followed by a one-line finding summary and a PASS/WARN/FAIL status.\n\n```\n✔ Found 6 skills\n\n✔ fetch-data     v1.0.0  D (42)\n✔ deploy-helper  v2.3.0  C (68)\n✔ code-review    v1.1.0  A (95)\n\n6 skills scanned  •  avg score 78  •  4 certified\nFindings: 2 critical, 1 high, 2 medium\n\n⚠ WARN  3 high/critical finding(s) detected\n```\n\nUse `--verbose` for score breakdowns, rule IDs, file/line locations, and remediation for each finding.\n\n## Exit Codes\n\n- `0` — audit passed the active policy\n- `1` — policy violation or fatal error\n\nUse the exit code directly to gate CI pipelines — no special flag required:\n\n```bash\nnpx agentsec --policy strict || exit 1\n```\n\n## Tips\n\n- Start with `npx agentsec` — no install, no flags. Iterate from there.\n- Add `--verbose` whenever you need to act on specific findings.\n- Pipe `--format json` into `jq` or a custom script for programmatic handling.\n- `strict` is the most common preset for production repositories.\n- Browse the agent skills ecosystem at [skills.sh](https://skills.sh).\n\nFile v0.1.5:_meta.json\n\n{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.1.5\",\n  \"publishedAt\": 1777400040553\n}\n\nArchive v0.1.4: 2 files, 3360 bytes\n\nFiles: SKILL.md (8087b), _meta.json (127b)\n\nFile v0.1.4:SKILL.md\n\n---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.1.4\nhomepage: https://agentsec.sh\nmetadata:\n  clawdbot:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n```bash\n# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list\n```\n\n## Installation\n\n`npx agentsec` needs no install. For repeated use, install globally:\n\n```bash\n# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec\n```\n\nThen drop the `npx` prefix:\n\n```bash\nagentsec\nagentsec scan --path ./my-skills\n```\n\n## Flags\n\nAll flags work with any command.\n\n| Flag         | Short | Values                          | Default    | Purpose                        |\n| ------------ | ----- | ------------------------------- | ---------- | ------------------------------ |\n| `--format`   | `-f`  | `text`, `json`, `sarif`, `html` | `text`     | Output format                  |\n| `--output`   | `-o`  | path                            | stdout     | Write report to file           |\n| `--policy`   | `-p`  | preset name or path             | `default`  | Apply a policy preset          |\n| `--platform` |       | `openclaw`, `claude`, `codex`   | auto       | Narrow to one agent platform   |\n| `--path`     |       | path                            | auto       | Custom skill directory to scan |\n| `--verbose`  | `-v`  |                                 | off        | Show detailed findings         |\n| `--no-color` |       |                                 | off        | Disable colored output         |\n| `--help`     | `-h`  |                                 |            | Show help                      |\n| `--version`  | `-V`  |                                 |            | Print version                  |\n\n## Common Recipes\n\n### Show detailed findings and remediation\n\n```bash\nnpx agentsec --verbose\n```\n\n### Scan a specific directory\n\n```bash\nnpx agentsec scan --path ./my-skills\n```\n\n### Target a specific agent platform\n\n```bash\nnpx agentsec --platform claude\nnpx agentsec --platform codex\n```\n\n### Audit with a strict policy and save JSON\n\n```bash\nnpx agentsec --policy strict --format json --output audit.json\n```\n\n### Generate an HTML report for stakeholders\n\n```bash\nnpx agentsec --format html --output report.html\n```\n\n### Generate a SARIF report for IDE / code-scanning integration\n\n```bash\nnpx agentsec --format sarif --output report.sarif\n```\n\n### List available policy presets\n\n```bash\nnpx agentsec policy list\n```\n\n### Inspect the rules in a preset\n\n```bash\nnpx agentsec policy show strict\n```\n\n### Validate a custom policy config file\n\n```bash\nnpx agentsec policy validate ./my-policy.json\n```\n\n### Replay a previous audit as an HTML report\n\n```bash\nnpx agentsec report audit.json --format html --output report.html\n```\n\n## Policy Presets\n\n| Name                 | Use Case                                                             |\n| -------------------- | -------------------------------------------------------------------- |\n| `default`            | Balanced policy. Blocks critical findings.                           |\n| `strict`             | Enterprise-grade. Blocks high and critical findings, enforces tests. |\n| `permissive`         | Lenient. Only blocks critical CVEs. Good for development.            |\n| `owasp-agent-top-10` | Built directly from the OWASP Agentic Skills Top 10.                 |\n\n## Configuration File\n\n`agentsec` auto-loads `.agentsecrc`, `.agentsecrc.json`, or `agentsec.config.json` from the current directory (or any parent):\n\n```json\n{\n  \"format\": \"text\",\n  \"output\": null,\n  \"policy\": \"strict\",\n  \"verbose\": false\n}\n```\n\nCLI flags always override config file values. Omit `\"platform\"` and `\"path\"` to keep the default auto-discovery behavior — agentsec will scan every known platform's default locations.\n\n## OWASP Agentic Skills Top 10\n\nEvery audit checks all ten risk categories:\n\n| ID    | Risk                    |\n| ----- | ----------------------- |\n| AST01 | Malicious Skills        |\n| AST02 | Supply Chain Compromise |\n| AST03 | Over-Privileged Skills  |\n| AST04 | Insecure Metadata       |\n| AST05 | Unsafe Deserialization  |\n| AST06 | Weak Isolation          |\n| AST07 | Update Drift            |\n| AST08 | Poor Scanning           |\n| AST09 | No Governance           |\n| AST10 | Cross-Platform Reuse    |\n\n## Understanding the Output\n\nDefault output is compact: each skill shows its grade and score, followed by a one-line finding summary and a PASS/WARN/FAIL status.\n\n```\n✔ Found 6 skills\n\n✔ fetch-data     v1.0.0  D (42)\n✔ deploy-helper  v2.3.0  C (68)\n✔ code-review    v1.1.0  A (95)\n\n6 skills scanned  •  avg score 78  •  4 certified\nFindings: 2 critical, 1 high, 2 medium\n\n⚠ WARN  3 high/critical finding(s) detected\n```\n\nUse `--verbose` for score breakdowns, rule IDs, file/line locations, and remediation for each finding.\n\n## Exit Codes\n\n- `0` — audit passed the active policy\n- `1` — policy violation or fatal error\n\nUse the exit code directly to gate CI pipelines — no special flag required:\n\n```bash\nnpx agentsec --policy strict || exit 1\n```\n\n## Tips\n\n- Start with `npx agentsec` — no install, no flags. Iterate from there.\n- Add `--verbose` whenever you need to act on specific findings.\n- Pipe `--format json` into `jq` or a custom script for programmatic handling.\n- `strict` is the most common preset for production repositories.\n- Browse the agent skills ecosystem at [skills.sh](https://skills.sh).\n\nFile v0.1.4:_meta.json\n\n{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.1.4\",\n  \"publishedAt\": 1777389074212\n}","readmeExcerpt":"Skill: Agentsec Owner: markeljan Summary: Audit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before runnin... Tags: latest:0.4.0 Version history: v0.4.0 | 2026-07-01T18:09:31.606Z | auto Version 0.4.0 of agentsec - Updated \"OWASP Agentic Skills Top 10\" risk category descriptions (notably, AST05 is now \"Untrusted External Inst","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"npx agentsec"},{"language":"bash","snippet":"# Full audit (scan + policy evaluation). Default command.\nnpx agentsec\n\n# Scan only (no policy evaluation)\nnpx agentsec scan\n\n# Generate a report from a previously saved audit JSON\nnpx agentsec report audit.json\n\n# Manage and inspect policy presets\nnpx agentsec policy list"},{"language":"bash","snippet":"# bun (recommended)\nbun add -g agentsec\n\n# npm\nnpm install -g agentsec\n\n# pnpm\npnpm add -g agentsec\n\n# yarn\nyarn global add agentsec"},{"language":"bash","snippet":"agentsec\nagentsec scan --path ./my-skills"},{"language":"bash","snippet":"npx agentsec --verbose"},{"language":"bash","snippet":"npx agentsec scan --path ./my-skills"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: agentsec\ndescription: >\n  Audit AI agent skills for security vulnerabilities. Use when scanning\n  installed skills against the OWASP Agentic Skills Top 10, checking skills\n  before running them, gating CI/CD on skill safety, or generating audit\n  reports (text, JSON, SARIF, HTML) for stakeholders.\nversion: 0.4.0\nlicense: MIT\nhomepage: https://agentsec.sh\nauthor: semiotic-ai\npermissions:\n  - filesystem:read\nmetadata:\n  agentsec:\n    profile: meta\n  openclaw:\n    emoji: \"🛡️\"\n    homepage: https://agentsec.sh\n    requires:\n      anyBins:\n        - agentsec\n        - npx\n        - bunx\n    install:\n      - kind: node\n        package: agentsec\n        bins:\n          - agentsec\n        label: Install agentsec (npm)\n---\n\n# agentsec\n\n`agentsec` is a security auditing CLI for AI agent skills. It scans every skill installed in a project against the OWASP Agentic Skills Top 10 and reports vulnerabilities, misconfigurations, and governance gaps.\n\n## When to Use\n\nUse `agentsec` when the user asks to:\n\n- Audit, scan, or check agent skills for security issues\n- Verify installed skills are safe before running them\n- Check OWASP compliance of an agent setup\n- Gate a CI/CD pipeline on skill security\n- Generate a security report for stakeholders\n\n## Quick Start\n\nThe fastest path to a result — no install, no flags:\n\n```bash\nnpx agentsec\n```\n\nThis scans every default skills directory on the machine — grouped by platform — plus any `./skills` folder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.\n\n### Auto-discovery locations\n\nagentsec is agent-platform agnostic — every platform listed below ships skills in the [agentskills.io](https://agentskills.io/specification) `SKILL.md` format and is auto-discovered.\n\n| Platform               | Paths scanned                                                                                                             |\n| ---------------------- | ------------------------------------------------------------------------------------------------------------------------- |\n| **Claude Code**        | `~/.claude/skills`, `./.claude/skills`, `~/.claude/plugins/*/skills/*`, `~/.claude/commands`, `./.claude/commands`         |\n| **OpenClaw / ClawHub** | `~/.openclaw/workspace/skills`, `~/.openclaw/workspace-*/skills` (profiles via `OPENCLAW_PROFILE`), `~/.openclaw/skills`  |\n| **Codex / skills.sh**  | `~/.agents/skills`, `./.agents/skills`, `../.agents/skills`, `/etc/codex/skills`                                          |\n| **Hermes**             | `~/.hermes/skills`, `~/.hermes/skills/*` (bundled categories), `./.hermes/skills`                                         |\n| **Other** (generic)    | Any `skills/` directory found within the current project, up to two levels deep                                           |\n\n## Core Commands\n\nEvery workflow starts from one of four commands. Run them with `npx agentsec` — no install needed.\n\n"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7bmrdn938fvmekwg8tggxskh809zbv\",\n  \"slug\": \"agentsec\",\n  \"version\": \"0.4.0\",\n  \"publishedAt\": 1782929371606\n}"},{"path":"skill-card.md","content":"## Description:\n\nAudit AI agent skills for security vulnerabilities when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before running them, gating CI/CD on skill safety, or generating audit reports for stakeholders.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[markeljan](https://clawhub.ai/user/markeljan)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use Agentsec to audit installed agent skills, check OWASP Agentic Skills Top 10 coverage, gate CI/CD workflows, and generate security reports for stakeholders.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill recommends executing an npm-distributed CLI, including global installation options, to scan local skill directories.\n\nMitigation: Review before installing in sensitive environments and prefer a pinned version, lockfile-managed local install, or internally vetted package mirror.\n\nRisk: Default scans inspect multiple known skill directories and may cover more local content than intended.\n\nMitigation: Use targeted scans with --path or --platform when only selected skill directories should be inspected.\n\n## Reference(s):\n\n- [Agentsec homepage](https://agentsec.sh)\n- [Agent Skills specification](https://agentskills.io/specification)\n- [Skills.sh](https://skills.sh)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands; generated audit reports may be text, JSON, SARIF, or HTML.]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can guide scans across default skill directories or targeted paths and platforms.]\n\n## Skill Version(s):\n\n0.4.0 (source: server release metadata and frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Audit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before runnin... Skill: Agentsec Owner: markeljan Summary: Audit AI agent skills for security vulnerabilities. Use when scanning installed skills against the OWASP Agentic Skills Top 10, checking skills before runnin... Tags: latest:0.4.0 Version history: v0.4.0 | 2026-07-01T18:09:31.606Z | auto Version 0.4.0 of agentsec - Updated \"OWASP Agentic Skills Top 10\" risk category descriptions (notably, AST05 is now \"Untrusted External Inst","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1206,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T13:51:13.273Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T13:51:13.273Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T15:51:18.869Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}