← Back to Skills Marketplace
enderphan94

Web Security Client-Side Scanner 1773654191

by Ender Loc Phan · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
342
Downloads
2
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install web-front-scanner
Description
Perform a thorough client-side / browser-facing security assessment of a target web application. Use this skill whenever the user asks to pentest, audit, or...
Usage Guidance
This skill appears coherent for front-end pentesting, but before installing or running it: 1) obtain explicit, written authorization from the asset owner and confirm the exact scope (which subdomains, paths, or accounts are allowed); 2) decide whether active tools (subdomain enumeration, httpx, nuclei templates) are permitted — these can be more intrusive than pure client-side inspection; 3) avoid sharing high-privilege credentials — if authenticated testing is needed, prefer scoped or test accounts and short-lived credentials; 4) confirm the runtime environment will contain the listed tools (or provide an approved TOOLS_DIR) because the skill assumes external CLI tools will be executed; and 5) plan for safe handling of any secrets or sensitive data discovered in client assets (do not exfiltrate them to external services). If you want, I can produce a shorter checklist of the exact commands and tools the skill will run so you can approve them one-by-one.
Capability Analysis
Type: OpenClaw Skill Name: web-front-scanner-1773654191 Version: 1.0.0 The skill bundle (SKILL.md) provides a comprehensive framework for conducting client-side security assessments, including reconnaissance, static analysis, and vulnerability validation. It instructs the agent to utilize several high-risk network and security tools such as `nuclei`, `subfinder`, `katana`, and `gau`. While the instructions emphasize non-destructive testing and require user authorization, the inclusion of these broad network and execution capabilities—even when plausibly needed for the stated purpose of a security audit—meets the specific criteria for a suspicious classification. No evidence of intentional malicious behavior, such as data exfiltration or backdoors, was identified.
Capability Assessment
Purpose & Capability
The skill is explicitly a client-side/front-end security assessment and its checklist, methodology, and recommended tools align with that purpose (JS bundle analysis, source maps, CSP, storage, service workers, etc.). It does not claim unrelated capabilities (e.g., full cloud administration) and declares no environment or credential requirements up front.
Instruction Scope
Instructions are prescriptive and mostly limited to passive/low-risk client-side analysis. However, the guidance references active reconnaissance tools (subfinder, httpx, nuclei, waybackurls, etc.) that can broaden scope and perform more intrusive checks; the SKILL.md does state 'confirm scope' and 'non-destructive only', but an operator should explicitly approve any subdomain discovery or active scanning before use.
Install Mechanism
Instruction-only skill with no install spec and no code files — minimal risk from install mechanisms. The skill assumes external tools exist in the environment (TOOLS_DIR or PATH) but does not attempt to fetch or run installers itself.
Credentials
The skill declares no required environment variables or credentials. It does ask the operator to confirm TARGET and optional LOGIN credentials if authenticated testing is in scope, which is reasonable and proportional for a pentest. There is no unexplained request for unrelated secrets.
Persistence & Privilege
always is false and the skill does not request persistent or elevated agent privileges. It does not modify other skills or system-wide settings in the instructions provided.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install web-front-scanner
  3. After installation, invoke the skill by name or use /web-front-scanner
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Initial release
Metadata
Slug web-front-scanner
Version 1.0.0
License MIT-0
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is Web Security Client-Side Scanner 1773654191?

Perform a thorough client-side / browser-facing security assessment of a target web application. Use this skill whenever the user asks to pentest, audit, or... It is an AI Agent Skill for Claude Code / OpenClaw, with 342 downloads so far.

How do I install Web Security Client-Side Scanner 1773654191?

Run "/install web-front-scanner" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is Web Security Client-Side Scanner 1773654191 free?

Yes, Web Security Client-Side Scanner 1773654191 is completely free, licensed under MIT-0. You can download, install and use it at no cost.

Which platforms does Web Security Client-Side Scanner 1773654191 support?

Web Security Client-Side Scanner 1773654191 is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Web Security Client-Side Scanner 1773654191?

It is built and maintained by Ender Loc Phan (@enderphan94); the current version is v1.0.0.

💬 Comments