security-audit
Infrastructure security audit — scans Dockerfile, docker-compose, CI/CD workflows (.github, .gitlab-ci, Jenkins), .env files, Terraform, shell scripts, private keys (.pem/.key), and JSON/YAML configs for hardcoded secrets, misconfigurations, and compliance violations. 12 rules across 4 risk tiers: CRITICAL (tokens/keys), HIGH (latest tag, root user, privileged mode, CI injection), MEDIUM (exposed ports, missing .dockerignore), LOW. Generates Markdown report with fix examples. Critical findings exit 1. Use when user says "security audit", "scan for secrets", "check Dockerfile", "audit infrastructure", "review CI/CD security".
Source facts
- Repository
- bobo070314/openclaw-config
- Last source activity
- June 24, 2026 at 06:09
- Detected SKILL.md language
- Chinese
- Stars
- 0
- Forks
- 0
Install options
The review-first prompt is selected by default. You can switch to a direct command or download a local copy.
Review the source files
Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.