security-guide — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited security-guide (Agent Skill) and scored it 82/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 2 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 2 flagged
The text {match} is the classic direct prompt-injection phrasing. Placed in a skill body that the agent reads as trusted instructions, it tries to make the agent abandon its prior rules and follow whatever comes next — a full system-prompt override.
ignore/disregard/forget … previous instructions sentence.Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
When the user invokes this skill, provide a complete security deployment checklist based on the following best practices. Check the current system state using available tools and give actionable recommendations.
ufw allow from 127.0.0.1 to any port 19000 docker run --cap-drop=ALL --cap-add=NET_BIND_SERVICE \
--read-only --tmpfs /tmp \
-u 1000:1000 \
openclaw--memory=2g --cpus=1chmod 600 ~/.env ~/.ssh/* ~/.aws/credentialsRemind the user about ShellWard's quick commands:
/security — Full security status overview/audit [count] [filter] — View audit log/harden — Scan for issues, /harden fix to auto-fix/scan-plugins — Scan plugins for security risks/check-updates — Check versions and vulnerabilities~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.