4worlds4w-svg/clauwdit/SKILL.md
Security auditor for AI agent skills. Scans SKILL.md files for prompt injection, data exfiltration, obfuscation, and dangerous capability combinations.
npx skillsauth add openclaw/skills clauwditInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Static security analyzer for OpenClaw SKILL.md files. Detects prompt injection, credential exfiltration, obfuscated payloads, and dangerous capability combinations before you install.
Paste or pipe any SKILL.md content and get back a trust score (0-100) with detailed findings.
Detects:
Zone-aware analysis — understands markdown structure. Code blocks are weighted as executable instructions. Security documentation describing threats is not flagged as a threat itself.
Audit a skill before installing:
curl -s https://clauwdit.4worlds.dev/audit/author/skill-name
Or POST raw skill content:
curl -s -X POST https://clauwdit.4worlds.dev/audit \
-H "Content-Type: application/json" \
-d '{"skill":"author/skill-name"}'
| Score | Tier | Meaning | |-------|------|---------| | 80-100 | Trusted | No significant issues found | | 60-79 | Moderate | Minor concerns, review recommended | | 40-59 | Suspicious | Significant issues, use with caution | | 0-39 | Dangerous | Critical threats detected, do not install |
{
"trust": { "score": 85, "tier": "trusted" },
"findings": [
{
"severity": "medium",
"description": "Network request capability detected",
"zone": "code",
"line": 12
}
],
"capabilities": ["network_out", "file_read"],
"compoundThreats": [],
"permissionIntegrity": { "undeclared": [], "unused": [] }
}
Built by 4Worlds. Zone-aware static analysis with 60+ detection patterns, Unicode homoglyph normalization, and compound threat detection.
tools
Use when the user wants to connect to, test, or use the McDonalds service at mcp.mcd.cn, including checking authentication, probing MCP endpoints, listing tools, or calling McDonalds MCP tools through a reusable local CLI.
development
Web scraping platform — Twitter/X data, Vinted marketplace, and general web scraping API
development
SlowMist AI Agent Security Review — comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version)
data-ai
去除中文文本中的 AI 写作痕迹,使其读起来自然。基于维基百科 AI 写作特征指南,检测 24 种 AI 模式。触发词:humanizer-cn、去除 AI 痕迹、去除 AI 写作痕迹、中文文本人性化。