Global Rank · of 601 Skills
slowmist-agent-security AI Agent Skill
View Source: slowmist/slowmist-agent-security
MediumInstallation
npx skills add slowmist/slowmist-agent-security --skill slowmist-agent-security 130
Installs
SlowMist Agent Security Skill π‘οΈ
A comprehensive security review framework for AI agents operating in adversarial environments.
Core principle: Every external input is untrusted until verified.
Overview
This skill provides a structured security review framework applicable to OpenClaw, Hermes Agent, and other LLM-based agent systems, covering:
- Skill/MCP Installation β Detect malicious patterns before installation
- GitHub Repository Review β Audit codebases for security issues
- URL/Document Analysis β Scan for prompt injection and social engineering
- On-Chain Address Review β AML risk assessment and transaction analysis
- Product/Service Evaluation β Architecture and permission analysis
- Social Share Review β Validate tools recommended in chats
Installation
The installation example below uses OpenClaw for demonstration. In practice, you can simply hand the repository URL to your agent and let it handle the installation β it's that easy.
Option 1: Direct Download
Download the latest release and extract to your OpenClaw workspace:
cd ~/.openclaw/workspace/skills
git clone https://github.com/slowmist/slowmist-agent-security.gitOption 2: ClawHub (when available)
clawhub install slowmist-agent-securityQuick Start
Once installed, the agent will automatically reference this framework when encountering:
- Skill/MCP installation requests
- Unknown GitHub repositories
- External URLs or documents
- Blockchain addresses
- Product/service recommendations
Framework Structure
slowmist-agent-security/
βββ SKILL.md # Main framework documentation
βββ README.md # This file
βββ _meta.json # ClawHub metadata
βββ reviews/
β βββ skill-mcp.md # Skill/MCP review guide
β βββ repository.md # GitHub repo review guide
β βββ url-document.md # URL/document review guide
β βββ onchain.md # On-chain address review guide
β βββ product-service.md # Product/service review guide
β βββ message-share.md # Social share review guide
βββ patterns/
β βββ red-flags.md # Code-level dangerous patterns (11 categories)
β βββ social-engineering.md # Social engineering patterns (8 categories)
β βββ supply-chain.md # Supply chain attack patterns (7 categories)
βββ templates/
βββ report-skill.md # Skill assessment report template
βββ report-repo.md # Repository assessment report template
βββ report-url.md # URL/document assessment report template
βββ report-onchain.md # On-chain assessment report template
βββ report-product.md # Product/service assessment report templateRisk Rating System
| Level | Meaning | Agent Action |
|---|---|---|
| π’ LOW | Information-only, no execution, no data collection, trusted source | Inform user, proceed if requested |
| π‘ MEDIUM | Limited capability, clear scope, known source, some risk | Full report with risk items, recommend caution |
| π΄ HIGH | Involves credentials, funds, system modification, unknown source | Detailed report, must have human approval |
| β REJECT | Matches red-flag patterns, confirmed malicious, unacceptable design | Refuse to proceed, explain why |
Trust Hierarchy
| Tier | Source Type | Scrutiny Level |
|---|---|---|
| 1 | Official project/exchange org | Moderate |
| 2 | Known security teams/researchers | Moderate |
| 3 | ClawHub high-download + multi-version | Moderate-High |
| 4 | GitHub high-star + actively maintained | High β verify code |
| 5 | Unknown source, new account | Maximum scrutiny |
Optional Integration
- MistTrack Skills β For on-chain AML risk assessment (external tool)
Usage Examples
Example 1: Skill Review
When a user asks to install a skill:
- Reference
reviews/skill-mcp.md - Scan files using
patterns/red-flags.md - Output report using
templates/report-skill.md
Example 2: On-Chain Address Review
When a user provides a blockchain address:
- Validate address format
- Query AML risk data (via available tools)
- Output report using
templates/report-onchain.md
Contributing
This framework is maintained by SlowMist. Contributions welcome:
- New attack patterns
- Improved detection rules
- Additional review templates
Credits
- Inspired by skill-vetter by spclaudehome
- Attack patterns informed by the OpenClaw Security Practice Guide
- Prompt injection patterns based on real-world PoC research
License
MIT License β Free to use, modify, and distribute.
Security is not a feature β it's a prerequisite. π‘οΈ
SlowMist Β· https://slowmist.com
Installs
Security Audit
Power your AI Agents with
the best open-source models.
Drop-in OpenAI-compatible API. No data leaves Europe.
Explore Inference APIGLM
GLM 5
$1.00 / $3.20
per M tokens
Kimi
Kimi K2.5
$0.60 / $2.80
per M tokens
MiniMax
MiniMax M2.5
$0.30 / $1.20
per M tokens
Qwen
Qwen3.5 122B
$0.40 / $3.00
per M tokens
How to use this skill
Install slowmist-agent-security by running npx skills add slowmist/slowmist-agent-security --skill slowmist-agent-security in your project directory. Run the install command above in your project directory. The skill file will be downloaded from GitHub and placed in your project.
No configuration needed. Your AI agent (Claude Code, Cursor, Windsurf, etc.) automatically detects installed skills and uses them as context when generating code.
The skill enhances your agent's understanding of slowmist-agent-security, helping it follow established patterns, avoid common mistakes, and produce production-ready output.
What you get
Skills are plain-text instruction files β not executable code. They encode expert knowledge about frameworks, languages, or tools that your AI agent reads to improve its output. This means zero runtime overhead, no dependency conflicts, and full transparency: you can read and review every instruction before installing.
Compatibility
This skill works with any AI coding agent that supports the skills.sh format, including Claude Code (Anthropic), Cursor, Windsurf, Cline, Aider, and other tools that read project-level context files. Skills are framework-agnostic at the transport level β the content inside determines which language or framework it applies to.
Chat with 100+ AI Models in one App.
Use Claude, ChatGPT, Gemini alongside with EU-Hosted Models like Deepseek, GLM-5, Kimi K2.5 and many more.