AIDR XClaw Security Sentinel
Paste the following prompt into your AI chat to install this skill:
Please install @user_b163fe4f/aidr-xclaw-security-sentinel according to https://skillhub.cn/install/skillhub.md.
About this skill
Problem
When LLMs are embedded in production workflows, security review is often implicit: user messages may expose ID cards, bank cards, internal IPs, cloud metadata endpoints, or exfiltration webhooks; skill installation and execution may still be bypassed by prompt injection, path traversal, encoded payloads, or credential access. Relying on model self-checks is hard to audit and weak for enterprise compliance.
How It Works
AIDR XClaw Security Sentinel makes the control path explicit through two gates:
- Gate 1 Query Audit: each user message is locally desensitized first, replacing ID card, phone, API key, Bearer token, and SSRF target patterns with placeholders, then an audit API decides pass, warn, or block.
- Gate 2 Skill Audit: before installing or running a skill, it generates L2/L3/final fingerprints, packages from a temporary directory, uploads for Pre-Install or Runtime audit, and requires staged outputs plus a full report.
Boundaries
API failures must be treated as blocking and must not be fabricated. Query Audit must not send raw sensitive content to the cloud. It fits AI-ops environments that need a traceable audit trail, not offline deployments, environments without audit services, or cases intended to bypass security controls.
Use Cases
- Before serving user messages, locally redact sensitive fields and call the audit API to pass, warn, or block requests.
- Before installing third-party skills, package from a temp directory, generate fingerprints, and run Pre-Install audit.
- When running installed skills, redact content before upload, execute Runtime audit, and emit staged reports.
- During prompt-risk review, follow the API safety_level to choose pass, warn, or block and retain the full report.
Best For
- AI gateway security engineers who need to redact user messages and decide pass, warn, or block before business logic.
- Agent-platform ops leads who need to verify skill content, fingerprints, and install-time risk before release.
- Architecture owners who need to include prompt-injection detection in a traceable large-model compliance workflow.
- Internal tooling teams who need to stop runtime skills from reading sensitive configs or calling exfiltration webhooks.
Related Skills
A lightweight wrapper and automation tool for Jaeger-related GitHub scenarios.
Vault Wrap is a wrapping skill for Vault and GitHub automation.
Port management, threat-intel audits, drift checks, and multi-node monitoring for self-hosted infrastructure.
Provides health checks for HTTP, TCP, Ping, and log sources with dynamic-threshold alerts, anomaly detection, and scheduled inspection reports.