Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/nickromanek/clawbridge/securitygit clone --depth 1 https://github.com/NickRomanek/clawbridgeWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00465 |
| Opus 5 | $0.00000 | $0.00233 |
| Sonnet 5 | $0.00000 | $0.00093 |
| Haiku 4.5 | $0.00000 | $0.00047 |
Grade A, and why
security scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Pre-Release Security Scan
Run this before /deploy to catch security issues. Three-step process: scan, triage, report.
Step 1: Run Semgrep locally
pip install semgrep 2>/dev/null
semgrep scan --config auto --config p/python --config p/secrets --config p/owasp-top-ten --severity WARNING clawbridge.py clawbridge_mcp.py
If Semgrep is not installed, install it first. Parse the output and categorize findings by severity.
Step 2: Run the security-auditor agent
After Semgrep completes, launch the security-auditor subagent to do a deeper review focusing on:
- Any Semgrep findings that need human judgment (true positive vs false positive)
- Memory/context poisoning paths
- Prompt injection vectors
- Network exposure (WebSocket, CORS, rate limiting)
- Subprocess security (engine launches, key handling)
- Dashboard XSS (especially in dynamically rendered content)
Step 3: Report
Present a summary table with:
- CRITICAL/HIGH findings that MUST be fixed before deploy
- MEDIUM findings that should be tracked
- LOW/informational findings to note
- False positives to ignore (explain why)
Past findings to watch for
- v0.5.5:
--host 127.0.0.1was not a valid OpenClaw flag — broke the gateway silently. Always verify CLI flags against--help. - v0.5.5: Python
\nin JS regex broke entire dashboard script block. Semgrep won't catch this — it's a Python-in-JS escaping issue. - v0.5.3: Engine error messages leaked API keys before
safety_redact()was applied. - Ongoing: No CSP header on dashboard. Memory poisoning via task result previews in daily logs. WebSocket accepts missing Origin header when no auth is set.
Decision guide
- 0 CRITICAL/HIGH → Safe to
/deploy - Any CRITICAL → Fix before deploying, no exceptions
- HIGH only → Fix if quick (<30 min), otherwise document and track for next release
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 44 lines · 0 tokens per session scan A 2bbdb73e4234
security is a command published in the GitHub repository NickRomanek/clawbridge (23 stars, last pushed 5mo ago), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 465 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
pr-address
Address PR review comments on current branch.
git-pr-push
Create git commit and push branch as PR using git + GitHub CLI.
objective-create
Create a structured objective through guided conversation.
analyze_diamond_feedback
Fetches all comments for the PR associated with the current branch, identifies feedback from Diamond review tool, analyzes it, and presents a plan to address the issues.
objective-update-with-landed-pr
Update objective issue after landing a PR.
plan-save
Save the current session's plan to GitHub as an issue.