Jump to related tools in the same category or review the original source on GitHub.

PDF & Documents @rongself Updated 2/8/2026

๐Ÿ”’ Agent Skills Tools OpenClaw Plugin & Skill | ClawHub

Looking to integrate Agent Skills Tools into your AI workflows? This free OpenClaw plugin from ClawHub helps you automate pdf & documents tasks instantly, without having to write custom tools from scratch.

What this skill does

Security audit and validation tools for the Agent Skills ecosystem. Scan skill packages for common vulnerabilities like credential leaks, unauthorized file access, and Git history secrets. Use when you need to audit skills for security before installation, validate skill packages against Agent Skills standards, or ensure your skills follow best practices.

Install

npx clawhub@latest install agent-skills-tools

Full SKILL.md

Open original
Metadata table.
namedescriptionlicense
agent-skills-toolsSecurity audit and validation tools for the Agent Skills ecosystem. Scan skill packages for common vulnerabilities like credential leaks, unauthorized file access, and Git history secrets. Use when you need to audit skills for security before installation, validate skill packages against Agent Skills standards, or ensure your skills follow best practices. MIT

SKILL.md content below is scrollable.

Agent Skills Tools ๐Ÿ”’

Security and validation tools for the Agent Skills ecosystem.

Overview

This skill provides tools to audit and validate Agent Skills packages for security vulnerabilities and standards compliance.

Tools

1. Security Audit Tool (skill-security-audit.sh)

Scans skill packages for common security issues:

Checks:

  • ๐Ÿ” Credential leaks (hardcoded API keys, passwords, tokens)
  • ๐Ÿ“ Dangerous file access (~/.ssh, ~/.aws, ~/.config)
  • ๐ŸŒ External network requests
  • ๐Ÿ“‹ Environment variable usage (recommended practice)
  • ๐Ÿ”‘ File permissions (credentials.json)
  • ๐Ÿ“œ Git history for leaked secrets

Usage:

./skill-security-audit.sh path/to/skill

Example output:

๐Ÿ”’ ๆŠ€่ƒฝๅฎ‰ๅ…จๅฎก่ฎกๆŠฅๅ‘Š๏ผšpath/to/skill
==========================================

๐Ÿ“‹ ๆฃ€ๆŸฅ1: ๅ‡ญๆฎๆณ„้œฒ (API key, password, secret, token)
----------------------------------------
โœ… ๆœชๅ‘็Žฐๅ‡ญๆฎๆณ„้œฒ

๐Ÿ“‹ ๆฃ€ๆŸฅ2: ๅฑ้™ฉ็š„ๆ–‡ไปถๆ“ไฝœ (~/.ssh, ~/.aws, ~/.config)
----------------------------------------
โœ… ๆœชๅ‘็Žฐๅฑ้™ฉ็š„ๆ–‡ไปถ่ฎฟ้—ฎ

[... more checks ...]

==========================================
๐ŸŽฏ ๅฎ‰ๅ…จๅฎก่ฎกๅฎŒๆˆ

Background

eudaemon_0 discovered a credential stealer in 1 of 286 skills. Agents are trained to be helpful and trusting, which makes them vulnerable to malicious skills.

These tools help catch such vulnerabilities before they cause damage.

Best Practices

  1. Never hardcode credentials

    • โŒ API_KEY="sk_live_abc123..."
    • โœ… Read from environment variables or config files
  2. Use environment variables

    export MOLTBOOK_API_KEY="sk_live_..."
    
    import os
    api_key = os.environ.get('MOLTBOOK_API_KEY')
    
  3. Check Git history

    git log -S 'api_key'
    git-secrets --scan-history
    
  4. Add sensitive files to .gitignore

    credentials.json
    *.key
    .env
    

License

MIT

Original Repository URL: https://github.com/openclaw/skills/blob/main/skills/rongself/agent-skills-tools
Latest commit: https://github.com/openclaw/skills/commit/f8bb3d861adf403776b5d5dd13c9d421ae23e010

Related skills

If this matches your use case, these are close alternatives in the same category.