OpenClaw ยท Skill

Page Behavior Audit

Deep behavioral page auditing with content safety policy enforcement.

Security & Passwords
v1.0.7
VirusTotal: Suspicious

Install

Start with the primary install command. Alternate entrypoints are included below for ClawHub and OpenClaw CLI users.

Primary command

clawhub install youdaolee/page-behavior-audit

ClawHub installer

npx clawhub@latest install youdaolee/page-behavior-audit

OpenClaw CLI

openclaw skills install youdaolee/page-behavior-audit

Direct OpenClaw install

openclaw install youdaolee/page-behavior-audit

What this skill does

Deep behavioral page auditing with content safety policy enforcement.

Why it matters

Deep behavioral audit with hashed policy (CSP-compliant, no plaintext badwords)

Typical use cases

Install this skill when you want a reusable OpenClaw workflow with clearer instructions than a one-off prompt.

Source instructions

page-behavior-audit

Deep behavioral page auditing with content safety policy enforcement.

Features

  • ๐Ÿ” Browser automation with redirect tracking
  • ๐Ÿ›ก๏ธ Content policy checking (hashed badwords)
  • ๐ŸŽฏ Response monitoring (SSRF/XXE detection)
  • ๐Ÿ“ธ Full-page screenshots
  • ๐Ÿ“Š HAR export
  • ๐Ÿšจ WeCom alerts for critical findings

Prerequisites

Set required environment variables:

export WECOM_WEBHOOK_URL="https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=YOUR_KEY"
export OPENCLAW_AUDIT_DIR="${HOME}/.openclaw/audit"  # optional

Usage

Via Webhook

curl -X POST http://localhost:8080/api/audit/scan \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com", "include_har": true}'

Via CLI

openclaw skill run page-behavior-audit --url https://example.com

Configuration

Input schema:

  • url (string, required): Target URL to audit
  • include_har (boolean, optional): Export HAR file (default: true)

Output:

  • redirects: Captured redirects
  • text_alerts: Content policy violations
  • ct_alerts: Response monitoring alerts
  • screenshot_path: Screenshot file path
  • har_path: HAR file path

Security

  • SHA256-hashed badword policies
  • Ed25519 signature verification
  • CSP-compliant (no plaintext sensitive words)
  • Sandbox-isolated browser execution

Alert Rules

CRITICAL severity:

  • XML served from non-.xml endpoints (SSRF/XXE risk)
  • Image endpoints returning XML (XXE evasion)

Alerts are sent to WeCom webhook when critical issues are detected.

Related OpenClaw skills

Browse all โ†’
Featured slot

Your product here

Reserve this slot to reach operators and coding-agent buyers.

Shown where builders are actively comparing tools and deployment options.

Advertise