| name | picoclaw-self-pen-testing |
| version | 0.0.5 |
| description | Picoclaw-only local posture-review skill focused on read-only findings and safe operator remediation guidance. |
| homepage | https://clawsec.prompt.security |
| author | prompt-security |
| license | AGPL-3.0-or-later |
| picoclaw | {"emoji":"🦐","category":"security","requires":{"bins":["node"]},"test_requires":{"bins":["node"]}} |
Picoclaw Posture Review (separate package)
Purpose: keep Picoclaw posture-review checks isolated from the broader guardian package so moderation-sensitive checks can be versioned/published independently.
Vercel Skills Installation
Install with the Vercel Skills CLI for this harness:
npx skills add prompt-security/clawsec --skill picoclaw-self-pen-testing -a openclaw -y
Release Artifact Verification
For standalone installs, verify the signed release manifest before trusting SKILL.md, skill.json, or the archive. The skill.json file is the package metadata/SBOM source, and the release pipeline signs checksums.json with the ClawSec release key.
set -euo pipefail
SKILL_NAME="picoclaw-self-pen-testing"
VERSION="0.0.5"
REPO="prompt-security/clawsec"
TAG="${SKILL_NAME}-v${VERSION}"
BASE="https://github.com/${REPO}/releases/download/${TAG}"
ZIP_NAME="${SKILL_NAME}-v${VERSION}.zip"
TMP_DIR="$(mktemp -d)"
trap 'rm -rf "$TMP_DIR"' EXIT
RELEASE_PUBKEY_SHA256="711424e4535f84093fefb024cd1ca4ec87439e53907b305b79a631d5befba9c8"
curl -fsSL "$BASE/checksums.json" -o "$TMP_DIR/checksums.json"
curl -fsSL "$BASE/checksums.sig" -o "$TMP_DIR/checksums.sig"
curl -fsSL "$BASE/signing-public.pem" -o "$TMP_DIR/signing-public.pem"
curl -fsSL "$BASE/$ZIP_NAME" -o "$TMP_DIR/$ZIP_NAME"
curl -fsSL "$BASE/SKILL.md" -o "$TMP_DIR/SKILL.md"
curl -fsSL "$BASE/skill.json" -o "$TMP_DIR/skill.json"
ACTUAL_PUBKEY_SHA256="$(openssl pkey -pubin -in "$TMP_DIR/signing-public.pem" -outform DER | shasum -a 256 | awk '{print $1}')"
if [ != ];
>&2
1
openssl -d -A - -out
openssl pkeyutl -verify -rawin -pubin \
-inkey \
-sigfile \
- >/dev/null
() {
-v shasum >/dev/null 2>&1;
shasum -a 256 | awk
| awk
}
() {
asset=
path=
expected=
[ -z ];
>&2
1
actual=
[ != ];
>&2
1
}
expected_archive=
[ -z ];
>&2
1
actual_archive=
[ != ];
>&2
1
verify_manifest_file
verify_manifest_file
Only install or extract the archive after this verification succeeds.
Scope
This skill only performs local, read-only posture-review analysis against an existing Picoclaw posture profile.
It flags:
- public Web UI exposure
- disabled UI auth
- unrestricted workspace/tooling
- unsigned verification mode
- MCP trust-boundary review needs
- scheduler persistence review
- plaintext secret markers
- multi-channel auth review
Usage
node scripts/self_pen_test.mjs --profile ~/.picoclaw/security/clawsec/current-profile.json
Validation
python utils/validate_skill.py skills/picoclaw-self-pen-testing
node skills/picoclaw-self-pen-testing/test/self_pen_test.test.mjs