clawsec-suite
Manages ClawSec suite with monitoring, cryptographic verification, and guided setup for enhanced security skills.
Install this skill
Security score
The clawsec-suite skill was audited on Mar 2, 2026 and we found 18 security issues across 3 threat categories, including 2 high-severity. Review the findings below before installing.
Categories Tested
Security Issues
Template literal with variable interpolation in command context
| 37 | ```bash |
Template literal with variable interpolation in command context
| 64 | ```bash |
Template literal with variable interpolation in command context
| 144 | ```bash |
Template literal with variable interpolation in command context
| 151 | ```bash |
Template literal with variable interpolation in command context
| 169 | ```bash |
Template literal with variable interpolation in command context
| 193 | - Remote feed signature URL: `${CLAWSEC_FEED_URL}.sig` (override with `CLAWSEC_FEED_SIG_URL`) |
Template literal with variable interpolation in command context
| 196 | - Local feed signature: `${CLAWSEC_LOCAL_FEED}.sig` (override with `CLAWSEC_LOCAL_FEED_SIG`) |
Template literal with variable interpolation in command context
| 206 | ```bash |
Template literal with variable interpolation in command context
| 375 | ```bash |
Access to hidden dotfiles in home directory
| 195 | - Local seed fallback: `~/.openclaw/skills/clawsec-suite/advisories/feed.json` |
Access to hidden dotfiles in home directory
| 197 | - Local checksums manifest: `~/.openclaw/skills/clawsec-suite/advisories/checksums.json` |
Access to hidden dotfiles in home directory
| 198 | - Pinned feed signing key: `~/.openclaw/skills/clawsec-suite/advisories/feed-signing-public.pem` (override with `CLAWSEC_FEED_PUBLIC_KEY`) |
Access to hidden dotfiles in home directory
| 199 | - State file: `~/.openclaw/clawsec-suite-feed-state.json` |
Access to hidden dotfiles in home directory
| 298 | 3. `~/.openclaw/security-audit.json` |
External URL reference
| 5 | homepage: https://clawsec.prompt.security |
External URL reference
| 35 | Discover the current catalog from the authoritative index (`https://clawsec.prompt.security/skills/index.json`) at runtime: |
External URL reference
| 192 | - Remote feed URL: `https://clawsec.prompt.security/advisories/feed.json` |
External URL reference
| 207 | FEED_URL="${CLAWSEC_FEED_URL:-https://clawsec.prompt.security/advisories/feed.json}" |
Install this skill with one command
/learn @prompt-security/clawsec-suite