Token导航 LogoToken导航TokenDH.com
研究检索敏感数据clawhub未标认证来源可访问clear审计通过

security-auditor-x安全审计员 x

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

2,596

周安装

104

GitHub Stars

公开资料未说明

下载量

840
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:security-auditor-x(安全审计员 x)
来源仓库:https://github.com/leewest0/security-auditor-x
安装命令:
openclaw skills install security-auditor-x
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install security-auditor-x

简介

针对代码库、API 设计与架构文档执行端到端安全审核,支持自定义策略注入。

  • 适合复杂系统安全评估、设计阶段缺陷预防或多模块联动分析场景。
  • 结合静态分析与模式匹配技术输出可落地的改进清单。
  • 需明确扫描范围与排除目录,避免遗漏重要业务逻辑代码。
  • security-auditor-x 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

name
security-auditor
description
>

Security Auditor

A skill for performing structured security audits across code, infrastructure, APIs, and architecture. Produces prioritised findings with severity ratings and actionable remediation steps.


Scope & Trigger Contexts

Use this skill for any of the following:

  • Code review — source files in any language (Python, JS/TS, Go, PHP, Java, etc.)
  • Infrastructure-as-code — Terraform, CloudFormation, Kubernetes manifests, Docker files
  • API design — OpenAPI/Swagger specs, REST or GraphQL schemas
  • Cloud configs — IAM policies, S3 bucket policies, security group rules, GCP/Azure equivalents
  • Architecture diagrams or descriptions — threat modelling, attack surface analysis
  • Dependency audit — package.json, requirements.txt, pom.xml, go.mod

Audit Process

Step 1 — Clarify Scope (if needed)

If the user hasn't specified, quickly confirm:

  • What is being audited? (code, config, architecture description)
  • What is the deployment context? (web app, internal tool, public API, mobile backend)
  • Any compliance requirements in scope? (SOC 2, ISO 27001, GDPR, PCI-DSS, HIPAA)
  • Desired output format? (inline annotations, structured report, executive summary)

If context is obvious from what's been shared, skip straight to the audit — don't ask unnecessary questions.

Step 2 — Reconnaissance

Before diving into findings, briefly characterise what you're looking at:

  • Tech stack / languages / frameworks identified
  • Entry points (endpoints, event handlers, CLI args, file inputs)
  • Trust boundaries (what's user-controlled vs internal)
  • Data sensitivity (PII, financial, credentials, health data)

Step 3 — Findings

For each issue found, produce a finding block (see format below). Organise findings by severity: Critical → High → Medium → Low → Informational.

Don't pad the report. Only include genuine issues. A clean section is fine if nothing material was found.

Step 4 — Remediation Summary

After all findings, include a prioritised remediation plan — what to fix first and why. If relevant, note any quick wins (easy fixes with high impact).

Step 5 — Positive Observations (optional)

If the code/config shows good security practices, briefly acknowledge them. This adds credibility and context to the report.


Finding Format

### [SEV-###] Finding Title

**Severity**: Critical | High | Medium | Low | Informational
**Category**: [OWASP category or CWE if applicable]
**Location**: file.py:42 (or "Architecture — auth flow")

**Description**
Clear explanation of the vulnerability and why it matters.

**Evidence**
Relevant code snippet or config extract (keep it brief — just enough to illustrate).

**Impact**
What an attacker could achieve if this is exploited.

**Remediation**
Concrete steps to fix it, with a code example where helpful.

**References** (optional)
- OWASP: https://owasp.org/...
- CWE-###

Severity Definitions

SeverityCriteria
CriticalDirect path to full compromise, data breach, RCE, or auth bypass with no mitigations
HighSignificant risk requiring exploitation of one step; privilege escalation, SQLi, SSRF
MediumRequires chaining with other issues or specific conditions; CSRF, insecure defaults
LowDefence-in-depth issues, info leakage, weak configs with limited direct impact
InformationalBest practice gaps, code hygiene, no direct security impact

Common Vulnerability Categories to Check

Web Applications

  • Injection (SQL, NoSQL, command, LDAP, XPath)
  • Broken authentication & session management
  • Insecure direct object references (IDOR)
  • XSS (reflected, stored, DOM-based)
  • CSRF
  • Security misconfigurations (debug mode, verbose errors, default creds)
  • Sensitive data exposure (logging PII, weak encryption, HTTP instead of HTTPS)
  • Using components with known vulnerabilities
  • Insufficient logging & monitoring

APIs

  • Broken object-level authorisation (BOLA/IDOR)
  • Broken function-level authorisation
  • Excessive data exposure
  • Lack of rate limiting / resource exhaustion
  • Mass assignment vulnerabilities
  • Improper input validation
  • JWT issues (alg:none, weak secrets, no expiry)

Infrastructure & Cloud

  • Overly permissive IAM roles / wildcard policies
  • Public S3 buckets or blob storage
  • Unrestricted security group ingress (0.0.0.0/0)
  • Secrets hardcoded in configs or environment variables committed to source control
  • Missing encryption at rest / in transit
  • No MFA on privileged accounts
  • Outdated AMIs / base images
  • Missing audit logging (CloudTrail, GCP Audit Logs)

Authentication & Authorisation

  • Weak password policies
  • Missing brute-force protection
  • Insecure password reset flows
  • Privilege escalation paths
  • Missing authorisation checks on sensitive routes
  • Token leakage in URLs or logs

Output Formats

Full Audit Report

Use for detailed code or config reviews. Includes all sections: scope, recon summary, findings (with evidence), remediation plan, positive observations.

Quick Assessment

Use when the user wants a fast pass or the input is small. Bullet-point findings with severity tags, brief descriptions, and one-line remediations. No full report structure.

Executive Summary

Use when explicitly requested. Plain English, no code snippets, business risk framing. Suitable for sharing with non-technical stakeholders.

Default to Full Audit Report unless the user indicates otherwise or the input is under ~50 lines of code/config.


Tone & Style

  • Be direct and precise — don't soften genuine risks
  • Avoid false positives; if you're uncertain, flag it as "Potential issue — verify"
  • Don't be alarmist about low-severity findings
  • Remediation advice should be practical, not just "validate your inputs"
  • Where relevant, link to authoritative references (OWASP, CWE, NIST, vendor docs)

Compliance Mapping (optional)

If the user mentions a compliance framework, map critical/high findings to relevant controls where appropriate:

FrameworkNotes
SOC 2Map to Trust Service Criteria (CC6, CC7, CC8, CC9)
ISO 27001Map to Annex A controls
OWASP Top 10Always reference where applicable
GDPRFlag PII handling, data retention, breach notification gaps
PCI-DSSFlag cardholder data exposure, network segmentation issues

Only include compliance mapping if explicitly requested or if a specific framework was mentioned in scope.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

71.81%
按下载量换算603

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills