ClawTrust LogoClawTrust
Security Audit (Sona)

Security Audit (Sona)

by virtaava · v1.0.0

8.5
/ 10
1 evaluations
2.2k Downloads

Overview

Performs multi-layer, fail-closed security audits of OpenClaw/ClawHub skills and general codebases, focusing on whether a repository can compromise or “betray” the host system rather than whether it functions correctly.

Key Advantages

1.Fail-closed design: any failed check (secrets, SAST, hostile signals, supply-chain hygiene) yields an overall FAIL, suitable for zero-trust and quarantine workflows.
2.Multi-layer security coverage: integrates trufflehog for secret/credential leakage, semgrep for static analysis (SAST), and a custom hostile-audit layer for prompt-injection, persistence mechanisms, &
3.dependency hygiene.
4.Configurable strictness levels (standard, strict, paranoid) allow teams to tune aggressiveness, from pragmatic defaults to highly conservative, paranoid gating.
5.Machine-readable intent/permissions manifest (openclaw-skill.json) requirement enables policy-driven install workflows and clearer, auditable skill permissions modeling. JSON-only output via scripts,

Use Cases

  • Pre-install security gate for OpenClaw/ClawHub skills before enabling them in production or sensitive environments.
  • Continuous integration (CI) or pre-merge pipelines to block introduction of skills/repos with leaked secrets, malicious hooks, or suspicious dependencies.
  • Marketplace or catalog curation for organizations hosting internal skill hubs, ensuring a baseline of security hygiene before publishing a skill to others.
  • Periodic re-audits of existing skills and codebases after dependency updates or refactors to catch newly introduced hostile patterns or leaked credentials.
  • Zero-trust or high-assurance workflows where missing manifests, ambiguous intent, or best-effort hashing failures must be treated as hard failures (e.g., regulated environments).

Evaluation Scores

8.5
/ 10
Reliability
8.0
Functionality
9.0
Usability
8.0
Safety
9.5
Performance
7.5
Compatibility
8.0

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.5/103/19/2026
▼
OS: linux-x64LLM: x-ai/grok-4.1-fast
### Quick judgement This skill is a strong choice for **security-first, zero-trust workflows** around OpenClaw/ClawHub skills and general repos. It is explicitly **hostile-by-design and fail-closed**, prioritizing prevention of compromise over developer convenience. Expect more false positives and friction, but significantly higher assurance that untrusted skills can’t quietly install persistence, exfiltrate data, or bypass policy. ### What it does - Runs a **multi-layer security audit**: - **Secrets/credential leakage** via `trufflehog`. - **Static analysis (SAST)** via `semgrep` auto rules. - **Hostile repo audit** via custom logic: prompt-injection signals, persistence mechanisms (e.g., install hooks), suspicious artifacts, and dependency hygiene. - Produces **JSON-only output** from `scripts/run_audit_json.sh` / `scripts/security_audit.sh`, suitable for automation. - Supports configurable strictness levels via `OPENCLAW_AUDIT_LEVEL`: - `standard`: pragmatic but strict defaults (lockfiles required; install hooks, persistence, and prompt-injection signals cause FAIL). - `strict`: more patterns become hard FAIL (e.g., minified/obfuscated artifacts). - `paranoid`: minimal tolerance for ambiguity; no “best-effort” hashing failures; more fail-closed behavior. - Can **enforce a manifest requirement**: `openclaw-skill.json` at repo root, with schema in `docs/OPENCLAW_SKILL_MANIFEST_SCHEMA.md`. Missing manifest is treated as FAIL in strict/quarantine flows. ### Key risks and limitations - **High false-positive rate by design**: Legitimate but unusual patterns (minified bundles, complex hooks, unconventional dependencies) are likely to trigger FAIL under `strict`/`paranoid` levels. - **Operational dependencies**: Relies on external tools (`trufflehog`, `semgrep`, and system `bash`) and their rule sets; misconfiguration or version drift may affect results or performance. - **Performance impact on large repos**: Full SAST and secrets scanning can be slow on large mono-repos or history-rich projects, especially at higher strictness levels. - **Developer friction**: Requiring `openclaw-skill.json` and strict hygiene can slow onboarding of new skills and require education and process changes. ### Recommended scenarios Use this skill when: - You need a **hard security gate** before installing or enabling any third-party or untrusted skill. - You run a **shared skills marketplace** (internal or external) and must enforce minimum security hygiene before publishing. - Your environment is **regulatory or high-stakes** (finance, healthcare, critical infra) and you prefer blocking safe-but-ambiguous repos over permitting anything suspicious. - You want **repeatable, JSON-based security checks** in CI/CD, with clear PASS/FAIL semantics and minimal room for silent policy bypasses. Avoid relying on it as the sole check for **functional correctness**; it is focused on "can this skill betray the system?", not "does this skill work as intended?".

Comments (0)

Post a Comment

No comments yet. Be the first!