shodan-skill
Use the installed shodan-skill CLI for documented Shodan REST, Streaming, Trends, and Exploits operations, including host intelligence, search and facets, DNS, scans, alerts, notifiers, bulk datasets, organizations, API-plan and credit-balance checks, and real-time feeds. Trigger for Shodan looku...
Install this skill
or
80/100
Security score
The shodan-skill skill was audited on Aug 12, 2026 and we found 2 security issues across 2 threat categories, including 1 high-severity. Review the findings below before installing.
Categories Tested
Security Issues
medium line 45
Access to home directory dotfiles
SourceSKILL.md
| 43 | ## OpenClaw installation |
| 44 | |
| 45 | Install the `shodan-skill` Python package first, then place this generated directory at `~/.openclaw/skills/shodan-skill`. Confirm discovery with `shodan-skill --help` before an API request. |
| 46 |
high line 24
Urgency-based manipulation
SourceSKILL.md
| 22 | 5. Route API-plan, usage-limit, quota, remaining-credit, credit-balance, query-credit, and scan-credit requests to `shodan-skill account api-info`. Use `shodan-skill account profile` only for membership and profile metadata. Never treat the profile response's generic `credits` field as the query- or scan-credit balance. |
| 23 | 6. Treat an explicit user request as the instruction to execute that operation, including credits, mutations, downloads, scans, monitoring, streams, and Enterprise operations. Do not ask for a second confirmation or authorization acknowledgement. |
| 24 | 7. Use the default `direct` safety mode. The CLI emits deterministic previews for applicable operations and continues immediately. Use `--dry-run` only when the user asks to preview without execution. Use `strict` mode only when the user explicitly requests it. |
| 25 | 8. Validate every target and dynamic path segment locally, and do not add operations or expand targets beyond what the user requested. Treat Streaming and Enterprise entitlements as account requirements. |
| 26 | 9. Parse stdout as the stable JSON envelope, JSON Lines for default streams, or SSE `data:` events when `--stream-format sse` is selected. Treat stderr as diagnostics and preserve nonzero exit codes. Never expose redacted values, signed URLs, authorization headers, cookies, or API keys. |
Scanned on Aug 12, 2026
View Security Dashboard