OpenClaw ยท Skill
Page Behavior Audit
Deep behavioral page auditing with content safety policy enforcement.
Install
Start with the primary install command. Alternate entrypoints are included below for ClawHub and OpenClaw CLI users.
Primary command
clawhub install youdaolee/page-behavior-auditClawHub installer
npx clawhub@latest install youdaolee/page-behavior-auditOpenClaw CLI
openclaw skills install youdaolee/page-behavior-auditDirect OpenClaw install
openclaw install youdaolee/page-behavior-auditWhat this skill does
Deep behavioral page auditing with content safety policy enforcement.
Why it matters
Deep behavioral audit with hashed policy (CSP-compliant, no plaintext badwords)
Typical use cases
Install this skill when you want a reusable OpenClaw workflow with clearer instructions than a one-off prompt.
Source instructions
page-behavior-audit
Deep behavioral page auditing with content safety policy enforcement.
Features
- ๐ Browser automation with redirect tracking
- ๐ก๏ธ Content policy checking (hashed badwords)
- ๐ฏ Response monitoring (SSRF/XXE detection)
- ๐ธ Full-page screenshots
- ๐ HAR export
- ๐จ WeCom alerts for critical findings
Prerequisites
Set required environment variables:
export WECOM_WEBHOOK_URL="https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=YOUR_KEY"
export OPENCLAW_AUDIT_DIR="${HOME}/.openclaw/audit" # optional
Usage
Via Webhook
curl -X POST http://localhost:8080/api/audit/scan \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com", "include_har": true}'
Via CLI
openclaw skill run page-behavior-audit --url https://example.com
Configuration
Input schema:
url(string, required): Target URL to auditinclude_har(boolean, optional): Export HAR file (default: true)
Output:
redirects: Captured redirectstext_alerts: Content policy violationsct_alerts: Response monitoring alertsscreenshot_path: Screenshot file pathhar_path: HAR file path
Security
- SHA256-hashed badword policies
- Ed25519 signature verification
- CSP-compliant (no plaintext sensitive words)
- Sandbox-isolated browser execution
Alert Rules
CRITICAL severity:
- XML served from non-.xml endpoints (SSRF/XXE risk)
- Image endpoints returning XML (XXE evasion)
Alerts are sent to WeCom webhook when critical issues are detected.