TopRank Skills

Home / Claw Skills / Git / GitHub / afrexai-cybersecurity-engine
Official OpenClaw rules 72%

afrexai-cybersecurity-engine

Complete cybersecurity assessment, threat modeling, and hardening system. Use when conducting security audits, threat modeling, penetration testing, incident response, or building security programs from scratch. Works with any stack — zero external dependencies.

Stars

0

Installs

0

Status

ACTIVE

Visibility

PUBLIC

安装方式

直接复制以下提示词,发送给你的 AI 助手即可完成安装。

请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 afrexai-cybersecurity-engine 技能。 若已安装,则直接安装 afrexai-cybersecurity-engine 技能。

Overview

Skill Key
1kalin/afrexai-cybersecurity-engine
Author
1kalin
Source Repo
openclaw/skills
Version
-
Source Path
skills/1kalin/afrexai-cybersecurity-engine
Latest Commit SHA
f00f16fd038c884a722223488eb4450778ad73bc

Extracted Content

SKILL.md excerpt

# Cybersecurity Engine

Complete methodology for security assessment, threat modeling, vulnerability management, incident response, and security program design. No tools required — pure agent knowledge that works with any codebase, infrastructure, or organization.

## Phase 1: Security Posture Assessment

### Quick Health Check (5 minutes)

Run through these three tiers:

**Tier 1 — Critical (fix today):**
- [ ] Default credentials in production
- [ ] Secrets in source code or environment files committed to git
- [ ] No authentication on admin endpoints
- [ ] SQL injection in user-facing forms
- [ ] Unencrypted sensitive data at rest
- [ ] Public S3 buckets or cloud storage
- [ ] No HTTPS enforcement
- [ ] Root/admin running application processes

**Tier 2 — High (fix this week):**
- [ ] Dependencies with known CVEs (CVSS ≥ 7.0)
- [ ] No rate limiting on authentication endpoints
- [ ] Missing CSRF protection on state-changing operations
- [ ] Verbose error messages leaking stack traces
- [ ] No input validation on API endpoints
- [ ] Weak password policy (< 12 chars, no complexity)
- [ ] Session tokens in URL parameters
- [ ] No logging of authentication events

**Tier 3 — Medium (fix this sprint):**
- [ ] Missing security headers (CSP, HSTS, X-Frame-Options)
- [ ] No automated dependency scanning in CI
- [ ] Overprivileged service accounts
- [ ] No secret rotation policy
- [ ] Missing account lockout after failed attempts
- [ ] No security.txt or responsible disclosure policy
- [ ] Cookies without Secure/HttpOnly/SameSite flags

**Score:** Count failures. 0-2 = solid. 3-5 = needs work. 6+ = stop shipping features, fix security.

### Full Assessment Brief

```yaml
assessment:
  name: "[Project/Org Name] Security Assessment"
  date: "YYYY-MM-DD"
  assessor: "[Agent/Person]"
  scope:
    applications:
      - name: "[App Name]"
        type: "web|api|mobile|desktop|iot"
        tech_stack: "[languages, frameworks, DBs]"
        hosting: "cloud|on-prem|hybrid"...

README excerpt

# 🛡️ AfrexAI Cybersecurity Engine

Complete cybersecurity assessment, threat modeling, penetration testing, and security program design — all in one agent skill. Zero external dependencies.

## Install

```bash
clawhub install afrexai-cybersecurity-engine
```

## What It Does

Transform your AI agent into a security engineer that can:

- **Assess** any application or infrastructure's security posture in minutes
- **Threat model** using STRIDE+ methodology with risk scoring
- **Audit** against OWASP Top 10 with specific fix patterns and code examples
- **Harden** servers, containers, and cloud environments with copy-paste configs
- **Manage vulnerabilities** with severity SLAs and scanning schedules
- **Respond to incidents** with step-by-step playbooks and communication templates
- **Design security programs** from scratch (quarterly roadmap)
- **Score security** with a 100-point rubric across 8 dimensions

## Quick Start

```
"Audit security of my Node.js API"
"Threat model our payment processing flow"
"Harden my AWS infrastructure"
"Create an incident response plan for our team"
"Score the security of our SaaS platform"
```

## What's Inside

| Phase | Topic | Key Deliverables |
|-------|-------|-----------------|
| 1 | Posture Assessment | 3-tier health check, full assessment brief YAML |
| 2 | Threat Modeling | STRIDE analysis, threat register, priority rules |
| 3 | Application Security | OWASP Top 10 checklists with fix patterns |
| 4 | Infrastructure | Network, container, and cloud hardening configs |
| 5 | Vulnerability Management | Lifecycle, SLAs, report templates, scanning schedule |
| 6 | Incident Response | SEV-1-4 playbooks, post-mortem template, comms |
| 7 | Security Headers | Copy-paste HTTP headers and cookie config |
| 8 | Auth Deep Dive | Password policy, JWT checklist, OAuth/OIDC |
| 9 | Security Program | 4-quarter roadmap, metrics dashboard |
| 10 | Penetration Testing | Recon, 4-phase testing, report template |
| 11 | Supply Chain | Dependenc...

Related Claw Skills

heyixuan2

bambu-studio-ai

★ 41

Bambu Lab 3D printer control and automation. Activate when user mentions: printer status, 3D printing, slice, analyze model, generate 3D, AMS filament, print monitor, Bambu Lab, or any 3D printing task. Full pipeline: search → generate → analyze → colorize → preview → open BS → user slice → print → monitor. Supports all 9 Bambu Lab printers (A1 Mini, A1, P1S, P2S, X1C, X1E, H2C, H2S, H2D).

capt-marbles

geo-optimization

★ 1

Generative Engine Optimization (GEO) for AI search visibility. Optimize content to appear in ChatGPT, Perplexity, Claude, and Google AI Overviews. Use when optimizing websites, pages, or content for LLM discoverability and citation.

carlulsoe

parakeet-stt

★ 0

Local speech-to-text with NVIDIA Parakeet TDT 0.6B v3 (ONNX on CPU). 30x faster than Whisper, 25 languages, auto-detection, OpenAI-compatible API. Use when transcribing audio files, converting speech to text, or processing voice recordings locally without cloud APIs.

carlzhao007

feishu-process-feedback

★ 0

飞书消息自动处理与进度反馈技能。安装后后台运行,监听飞书任务消息并自动创建独立进程处理。 在处理前后发送实时进度反馈(任务确认、进度百分比、完成通知)。 支持任务类型识别、智能解析、错误重试、并发控制、状态持久化。 使用场景:飞书自动化工作流、任务进度追踪、批量任务处理、需要实时反馈的场景。

cartoonitunes

bottyfans

★ 0

BottyFans agent skill for autonomous creator monetization. Lets AI agents register, build a profile, publish posts (public, subscriber-only, or pay-to-unlock), upload media, accept USDC subscriptions and tips on Base, send and receive DMs, track earnings, and appear on the creator leaderboard. Use this skill when an agent needs to monetize content, interact with fans, manage a creator profile, handle payments in USDC, or operate as an autonomous creator on the BottyFans platform.

camopel

ddgs-search

★ 0

Free multi-engine web search via ddgs CLI (DuckDuckGo, Google, Bing, Brave, Yandex, Yahoo, Wikipedia) + arXiv API search. No API keys required. Use when user needs web search, research paper discovery, or when other skills need a search backend. Drop-in replacement for web-search-plus.