CLAUDE CODE MARKETPLACES
SkillsMarketplacesMCPDigestLearnAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Web & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web CrawlingAutomation & Workflows
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Plugins Reference

Community

  • About
  • Learn
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by @mertduzgun

Independent project, not affiliated with Anthropic
  1. Skills
  2. /
  3. useai-pro
  4. /
  5. openclaw-skills-security
  6. /
  7. Skill Auditor

Skill Auditor

Editor's Note

Before you install any OpenClaw skill, run it through this six-step security review. It checks for typosquatting (missing characters, homoglyphs, scope confusion), over-privileged permission requests (network plus fileRead equals exfiltration risk), dependency vulnerabilities, prompt injection patterns, and data exfiltration signatures. The protocol is opinionated: it blocks combinations like network and shell together, flags base64-encoded instructions, and looks for references to credential files. You get a structured verdict with red flags and a safe-run plan. Treat it like a code review gate for third-party skills. Useful when someone shares a SKILL.md file or before pulling something from ClawHub, especially if the author is unknown or permissions changed between versions.

Install

npx skills add https://github.com/useai-pro/openclaw-skills-security --skill skill-auditor
Votes
0
Installs558
GitHub Stars58
Categories
Security
First SeenJun 3, 2026
View on GitHub

Comments

Login to comment

Related Security Skills

View all →
security-audit-scanner

tbartel74/Vigil-Code

0
8
Automated security scanning for Vigil Guard v2.0.0. Use for OWASP Top 10 checks, TruffleHog secret detection, npm/pip vulnerability scanning, 3-branch service security, heuristics-service audit, and CI/CD security pipelines.
permission-auditor

useai-pro/openclaw-skills-security

0
377
58
permission auditor
supabase-audit-auth-config

yoanbernabeu/supabase-pentest-skills

0
237
43
supabase audit auth config
supabase-audit-auth-users

yoanbernabeu/supabase-pentest-skills

0
208
43
supabase audit auth users
supabase-audit-auth-signup

yoanbernabeu/supabase-pentest-skills

0
205
43
supabase audit auth signup
supabase-audit-authenticated

yoanbernabeu/supabase-pentest-skills

0
182
43
supabase audit authenticated