smithery.ai

clawdbot-security-advisor

Conversational security advisor for Clawdbot. Runs audits, explains findings, suggests fixes. Use when user asks about security, wants an audit, or mentions securing their Clawdbot.

First seen Apr 19, 2026

Installation

$ npx skills add https://smithery.ai

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from smithery.ai · top by installs.

npx skills add https://smithery.ai

Browse all from smithery.ai

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 2,643 B
  • docs SUMMARY.md 214 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 1 installs

SKILL.md

Security Advisor

A conversational security advisor for your Clawdbot installation.

Usage

Start a conversation about your security posture. I can:

  • Run security audits and explain findings in plain language
  • Help you understand threats in your specific context
  • Suggest compromises between security and convenience
  • Guide you through fixes step-by-step

Just say things like:

  • "Check my security"
  • "Run a security audit"
  • "Help me secure my Clawdbot"
  • "What's my security posture?"

Tools Available

  • runsecurityaudit: Execute clawdbot security audit --deep
  • read_config: Read current configuration (secrets redacted)
  • check_permissions: Verify file and directory permissions
  • apply_fix: Apply configuration changes (creates backup first)

What I Check

I evaluate 10 security areas:

  1. Gateway Binding - Network exposure
  2. DM Policy - Who can message the bot
  3. Sandbox - Command containment
  4. Credential Security - Secret protection
  5. Prompt Injection - External content handling
  6. Dangerous Commands - Destructive operation controls
  7. Network Isolation - Bot network access
  8. Tool Access - Permission scope
  9. Audit Logging - Action recording
  10. Pairing Codes - Authentication strength

My Approach

I don't just tell you what's wrong - I help you understand:

  • Why something is a risk in your specific context
  • What the realistic threats are
  • How to balance security with your actual needs

If you resist a recommendation, I'll offer compromises rather than insisting on the "most secure" option that you won't actually use.


After Execution

Self-assess this run on the standard scale: 1=failed, 2=poor, 3=acceptable, 4=good, 5=excellent.

Append one JSON line to FEEDBACK.jsonl in this skill directory — the copy you are running from, not the skillmonger repo:

{"ts":"<UTC ISO 8601>","skill":"clawdbot-security-healthcheck","version":"<skill.version from CONFIG.yaml>","prompt":"<the user's original request>","outcome":<1-5>,"note":"<one line, especially when the outcome is not 4>","source":"llm","session":"<this session's id>","schema_version":1}

Drop session if you do not know this session's id. That line is the whole record: nothing in CONFIG.yaml is edited by a run.

Use "source":"user" when the score came from the user rather than from your own assessment.