← Back to Skills Marketplace
jgarrison929

Security Auditor

by jgarrison929 · GitHub ↗ · v1.0.0
cross-platform ✓ Security Clean
27676
Downloads
47
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install security-auditor
Description
Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review.
Usage Guidance
Install this if you want an agent to help review code and security practices. Because the activation terms are broad, users should expect it may engage during general security-related conversations and should still review any proposed file reads, commands, or code changes before allowing them.
Capability Analysis
Type: OpenClaw Skill Name: security-auditor Version: 1.0.0 The skill bundle is designed to equip an AI agent with the knowledge and processes to perform security audits. The `SKILL.md` file provides extensive guidance on secure coding practices, OWASP Top 10 vulnerabilities, security headers, input validation, authentication best practices, and dependency security. All code examples clearly differentiate between insecure and secure patterns, serving an educational purpose. There is no evidence of malicious intent, data exfiltration, unauthorized execution, persistence, or prompt injection aimed at subverting the agent's intended function; instead, it explicitly promotes secure development and auditing practices.
Capability Assessment
Purpose & Capability
The stated purpose is security auditing, and the described content covers secure coding, OWASP-style checks, headers, validation, authentication, and dependency review in a coherent educational/audit role.
Instruction Scope
The trigger terms are broad and may activate for general security or authentication discussions, but that is related to the skill's stated security-auditor purpose and is not paired with hidden authority or unsafe actions.
Install Mechanism
No install hooks, package scripts, dependency installation, or automatic runtime commands were identified in the supplied evidence.
Credentials
Any access to code or project details would be expected for a user-directed security review; there is no artifact-backed evidence of unrelated local indexing, credential harvesting, or network use.
Persistence & Privilege
No persistence, background workers, privilege escalation, credential/session-store use, destructive behavior, or data exfiltration was identified.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install security-auditor
  3. After installation, invoke the skill by name or use /security-auditor
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Initial release – comprehensive security audit and secure coding skill. - Provides actionable code review for security vulnerabilities and OWASP Top 10 risks. - Includes checklists and code patterns for authentication, CORS/CSP headers, input validation, XSS, SQL injection, secrets handling, and more. - Offers recommended secure code snippets and sample security headers. - Details best practices for dependency scanning, output formatting, and secure architecture review. - Supports structured output for clear, actionable security audit results.
Metadata
Slug security-auditor
Version 1.0.0
License
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is Security Auditor?

Use when reviewing code for security vulnerabilities, implementing authentication flows, auditing OWASP Top 10, configuring CORS/CSP headers, handling secrets, input validation, SQL injection prevention, XSS protection, or any security-related code review. It is an AI Agent Skill for Claude Code / OpenClaw, with 27676 downloads so far.

How do I install Security Auditor?

Run "/install security-auditor" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is Security Auditor free?

Yes, Security Auditor is completely free (open-source). You can download, install and use it at no cost.

Which platforms does Security Auditor support?

Security Auditor is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Security Auditor?

It is built and maintained by jgarrison929 (@jgarrison929); the current version is v1.0.0.

💬 Comments