Skip to main content

shodan-skill

Use the installed shodan-skill CLI for documented Shodan REST, Streaming, Trends, and Exploits operations, including host intelligence, search and facets, DNS, scans, alerts, notifiers, bulk datasets, organizations, API-plan and credit-balance checks, and real-time feeds. Trigger for Shodan looku...

Install this skill

or
80/100

Security score

The shodan-skill skill was audited on Aug 12, 2026 and we found 2 security issues across 2 threat categories, including 1 high-severity. Review the findings below before installing.

Categories Tested

Security Issues

medium line 45

Access to home directory dotfiles

SourceSKILL.md
43## OpenClaw installation
44
45Install the `shodan-skill` Python package first, then place this generated directory at `~/.openclaw/skills/shodan-skill`. Confirm discovery with `shodan-skill --help` before an API request.
46
high line 24

Urgency-based manipulation

SourceSKILL.md
225. Route API-plan, usage-limit, quota, remaining-credit, credit-balance, query-credit, and scan-credit requests to `shodan-skill account api-info`. Use `shodan-skill account profile` only for membership and profile metadata. Never treat the profile response's generic `credits` field as the query- or scan-credit balance.
236. Treat an explicit user request as the instruction to execute that operation, including credits, mutations, downloads, scans, monitoring, streams, and Enterprise operations. Do not ask for a second confirmation or authorization acknowledgement.
247. Use the default `direct` safety mode. The CLI emits deterministic previews for applicable operations and continues immediately. Use `--dry-run` only when the user asks to preview without execution. Use `strict` mode only when the user explicitly requests it.
258. Validate every target and dynamic path segment locally, and do not add operations or expand targets beyond what the user requested. Treat Streaming and Enterprise entitlements as account requirements.
269. Parse stdout as the stable JSON envelope, JSON Lines for default streams, or SSE `data:` events when `--stream-format sse` is selected. Treat stderr as diagnostics and preserve nonzero exit codes. Never expose redacted values, signed URLs, authorization headers, cookies, or API keys.
Scanned on Aug 12, 2026
View Security Dashboard
Installation guide →
GitHub Stars 4
Rate this skill
Categorydevelopment
UpdatedSeptember 29, 2026
liuweitao/shodan-skill