
prompt-security/clawsec
2 skills1.3k installs2.1k starsGitHub
Install
npx skills add https://github.com/prompt-security/clawsecSkills in this repo
1Clawsec SuiteClawSec Suite is a Prompt Security skill for solo builders running OpenClaw who treat third-party agent skills as supply-chain risk, not free plugins. It combines an advisory-feed monitor, signature verification, and approval-gated reactions when the feed flags malicious skills that match what you already installed, while acting as the entrypoint to wire up sibling ClawSec protections. Network fetches hit signed feed artifacts and catalog metadata unless you pin local paths; setup scripts may write hooks and cron jobs on your machine. That operational footprint is why it belongs on the Ship security shelf first and stays relevant in Operate monitoring as feeds update. You are still the authority: recommended blocks and removals stay approval-gated rather than silently deleting environments. For indie builders juggling Claude Code–style skill marketplaces, this skill encodes a heartbeat ritual and trust model so security checks become repeatable agent procedure instead of a forgotten README note.686installs2Openclaw Audit Watchdogopenclaw-audit-watchdog is a Prompt Security / Clawsec skill package for solo builders who publish or consume OpenClaw skills through ClawHub. It packages scripts and procedures to stand up recurring audits, render human-readable reports, and apply suppression rules so noisy findings do not drown real issues. Recent versions emphasize verifiable distribution: installers can validate signed release artifacts, archive hashes, and consistency of SKILL.md and skill.json against published checksums before execution. Cron-oriented setup keeps watchdog behavior running in the background rather than as a one-off chat prompt. The skill fits indie operators who treat agent skills as installable software with supply-chain risk, not ephemeral prompts. It complements manual review by encoding repeatable audit execution and documented verification steps, while local test harness paths stay excluded from ClawHub upload payloads per the published ignore rules.633installs