From sundial-org-awesome-openclaw-skills-4
Scans AgentSkill packages for credential theft, code injection, prompt manipulation, data exfiltration, and evasion techniques before installing from ClawHub or untrusted sources.
npx claudepluginhub joshuarweaver/cascade-ai-ml-agents-misc-2 --plugin sundial-org-awesome-openclaw-skills-4This skill uses the workspace's default tool permissions.
When asked to check, audit, or scan a skill for security, use SkillGuard.
README.mdRED-TEAM-NOTES.mdpackage.jsonrules/dangerous-patterns.jsonsrc/ast-analyzer.jssrc/clawhub.jssrc/cli.jssrc/index.jssrc/prompt-analyzer.jssrc/reporter.jssrc/scanner.jstest-fixtures/clean-skill/weather.jstest-fixtures/evasive-01-string-concat/index.jstest-fixtures/evasive-02-encoded/index.jstest-fixtures/evasive-04-timebomb/scheduler.jstest-fixtures/evasive-05-alias-chain/tools.jstest-fixtures/evasive-07-sandbox-detect/check.jstest-fixtures/evasive-08-reverse-shell/debug.shtest-fixtures/evasive-09-python-pickle/cache.pytest-fixtures/evasive-11-polyglot-json/config-template.jsonGuides Next.js Cache Components and Partial Prerendering (PPR) with cacheComponents enabled. Implements 'use cache', cacheLife(), cacheTag(), revalidateTag(), static/dynamic optimization, and cache debugging.
Guides building MCP servers enabling LLMs to interact with external services via tools. Covers best practices, TypeScript/Node (MCP SDK), Python (FastMCP).
Generates original PNG/PDF visual art via design philosophy manifestos for posters, graphics, and static designs on user request.
When asked to check, audit, or scan a skill for security, use SkillGuard.
node /home/claw/.openclaw/workspace/skillguard/src/cli.js scan <path>
node /home/claw/.openclaw/workspace/skillguard/src/cli.js scan <path> --compact
node /home/claw/.openclaw/workspace/skillguard/src/cli.js check "<text>"
node /home/claw/.openclaw/workspace/skillguard/src/cli.js batch <directory>
node /home/claw/.openclaw/workspace/skillguard/src/cli.js scan-hub <slug>
--compact: chat-friendly summary--json: machine-readable full report--quiet: score and verdict only