← Back to Skills Marketplace
Secure Code Warrior
by
Membrane Dev
· GitHub ↗
· v1.0.1
· MIT-0
109
Downloads
0
Stars
0
Active Installs
2
Versions
Install in OpenClaw
/install secure-code-warrior
Description
Secure Code Warrior integration. Manage data, records, and automate workflows. Use when the user wants to interact with Secure Code Warrior data.
Usage Guidance
This skill looks like a Membrane-based connector for Secure Code Warrior, but it doesn't declare how authentication is supplied. Before installing or enabling it: 1) Ask the publisher to clarify the authentication flow (does it require a Membrane API key, Secure Code Warrior API key, OAuth redirect, or interactive login?) and why getmembrane.com is the homepage; 2) Confirm what exact endpoints and data types the skill will read or modify (which Secure Code Warrior entities and whether it can write/delete); 3) Prefer supplying credentials with least privilege (scoped API token) and avoid sharing high-privilege org tokens; 4) If you need higher assurance, request the full SKILL.md runtime steps or a code sample showing API calls and verify endpoints are official (api.securecodewarrior.com or an explained Membrane proxy); 5) Because the skill uses network access, consider enabling it in a limited/test environment first and monitor its network activity. If the publisher cannot clearly explain credential handling and data flows, treat the skill with caution.
Capability Analysis
Type: OpenClaw Skill
Name: secure-code-warrior
Version: 1.0.1
The skill provides an integration for Secure Code Warrior via the Membrane CLI, but SKILL.md contains an excessively large list of keywords (e.g., 'Blockchain', 'Robotics', 'Help Desk Architecture') that are entirely unrelated to the stated purpose. This is a form of prompt manipulation or 'skill squatting' designed to hijack the agent's attention for a wide range of unrelated user queries. While the technical instructions for using the 'membrane' CLI appear legitimate, the inclusion of hundreds of irrelevant topics to influence agent behavior is highly suspicious.
Capability Tags
Capability Assessment
Purpose & Capability
The skill name and description say 'Secure Code Warrior integration', but the SKILL.md and homepage/reference point to Membrane (getmembrane.com). That could be legitimate (a proxy/integration provider), but the metadata does not declare the expected credential (Membrane API key or Secure Code Warrior credentials) or explain why a third party is involved.
Instruction Scope
SKILL.md requires network access and a valid Membrane account and enumerates many Secure Code Warrior entities (profiles, courses, assessments, reports, etc.). The file appears to be a broad/generic spec rather than concrete, scoped runtime instructions. There are no explicit commands shown in the provided excerpt, so it's unclear exactly which data the agent will read, modify, or transmit.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, which minimizes on-disk risk (nothing is downloaded or executed at install time).
Credentials
The SKILL.md says a 'valid Membrane account' is required, but the skill metadata lists no required environment variables or primary credential. This mismatch (needing an account but not declaring how credentials are supplied) is a proportionality and transparency issue: the skill will likely need an API token or login, but does not declare it.
Persistence & Privilege
The skill does not request 'always: true' and has no install-time persistence. It can be invoked by the agent (default), which is normal; there is no evidence it modifies other skills or system-wide settings.
How to Use
- Make sure OpenClaw is installed (local or Docker)
- Run the install command in chat:
/install secure-code-warrior - After installation, invoke the skill by name or use
/secure-code-warrior - Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.1
Auto sync from membranedev/application-skills
v1.0.0
Auto sync from membranedev/application-skills
Metadata
Frequently Asked Questions
What is Secure Code Warrior?
Secure Code Warrior integration. Manage data, records, and automate workflows. Use when the user wants to interact with Secure Code Warrior data. It is an AI Agent Skill for Claude Code / OpenClaw, with 109 downloads so far.
How do I install Secure Code Warrior?
Run "/install secure-code-warrior" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.
Is Secure Code Warrior free?
Yes, Secure Code Warrior is completely free, licensed under MIT-0. You can download, install and use it at no cost.
Which platforms does Secure Code Warrior support?
Secure Code Warrior is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).
Who created Secure Code Warrior?
It is built and maintained by Membrane Dev (@membranedev); the current version is v1.0.1.
More Skills