Content Scanner
Detects hidden instructions and prompt injection in content before processing. Catches instruction overrides, authority claims, obfuscation techniques, and instructions hiding in data. Use when your agent receives content from external sources like API responses, documents, emails, or user uploads. Invoke with /content-scanner or when asked to scan, check, or analyze content for hidden instructio…
Url Preflight
Security checker for URLs before fetching. Detects phishing domains, typosquatting, path traversal, suspicious query parameters, and redirect attacks. Use before your agent fetches URLs from untrusted sources or user input. Invoke with /url-preflight or when the user asks to check, validate, or verify a URL before fetching.
Social Engineering Detector
Detects manipulation tactics in messages and content. Identifies urgency exploitation, authority claims, flattery patterns, fear tactics, and trust manipulation. Use when your agent receives requests from users, emails, or external messages that could contain social engineering. Invoke with /social-engineering-detector or when asked to check for manipulation.
Skill Auditor
Security scanner for third-party skills. Detects prompt injection, code execution risks, data exfiltration, credential harvesting, and obfuscation patterns before installation. Use when vetting skills from registries, ClawHub, or untrusted sources. Invoke with /skill-auditor or when the user asks to review, audit, or vet a skill before installing.
Dependency Checker
Checks package and dependency names for supply chain attack patterns. Detects typosquatting, dependency confusion, and known malicious packages before installation. Use when your agent installs packages or reviews requirements files. Invoke with /dependency-checker or when asked to check dependencies for security issues.