Skill Vetter
一个面向 Security 场景的 Agent 技能。原始说明:Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
name: security-monitor
description: Real-time security monitoring for Clawdbot. Detects intrusions, unusual API calls, credential usage patterns, and alerts on breaches.
Run continuous security monitoring to detect breaches, intrusions, and unusual activity on your Clawdbot deployment.
No external dependencies required. Runs as a background process.
node skills/security-monitor/scripts/monitor.cjs --interval 60
node skills/security-monitor/scripts/monitor.cjs --daemon --interval 60
node skills/security-monitor/scripts/monitor.cjs --threats=credentials,ports,api-calls
| Threat | Detection | Response |
|--------|-----------|----------|
| Brute force attacks | Failed login detection | Alert + IP tracking |
| Port scanning | Rapid connection attempts | Alert |
| Process anomalies | Unexpected processes | Alert |
| File changes | Unauthorized modifications | Alert |
| Container health | Docker issues | Alert |
/root/clawd/clawdbot-security/logs/alerts.logUse systemd or PM2 to keep monitoring active:
# With PM2
pm2 start monitor.cjs --name "clawdbot-security" -- --daemon --interval 60
Run audit first, then monitor continuously:
# One-time audit
node skills/security-audit/scripts/audit.cjs --full
# Continuous monitoring
node skills/security-monitor/scripts/monitor.cjs --daemon
security-audit - One-time security scan (install separately)