โœ“ Verified ๐Ÿ“ก Monitoring โœ“ Enhanced Data

Page Behavior Audit

Deep behavioral audit with hashed policy (CSP-compliant, no plaintext badwords)

Rating
4.2 (32 reviews)
Downloads
563 downloads
Version
1.0.0

Overview

Deep behavioral audit with hashed policy (CSP-compliant, no plaintext badwords)

โœจKey Features

1

๐Ÿ” Browser automation with redirect tracking

2

๐Ÿ›ก๏ธ Content policy checking (hashed badwords)

3

๐ŸŽฏ Response monitoring (SSRF/XXE detection)

4

๐Ÿ“ธ Full-page screenshots

5

๐Ÿ“Š HAR export

6

๐Ÿšจ WeCom alerts for critical findings

Complete Documentation

View Source โ†’

page-behavior-audit

Deep behavioral page auditing with content safety policy enforcement.

Features

  • ๐Ÿ” Browser automation with redirect tracking
  • ๐Ÿ›ก๏ธ Content policy checking (hashed badwords)
  • ๐ŸŽฏ Response monitoring (SSRF/XXE detection)
  • ๐Ÿ“ธ Full-page screenshots
  • ๐Ÿ“Š HAR export
  • ๐Ÿšจ WeCom alerts for critical findings

Prerequisites

Set required environment variables:

bash
export WECOM_WEBHOOK_URL="https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=YOUR_KEY"
export OPENCLAW_AUDIT_DIR="${HOME}/.openclaw/audit"  # optional

Usage

Via Webhook

bash
curl -X POST http://localhost:8080/api/audit/scan \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com", "include_har": true}'

Via CLI

bash
openclaw skill run page-behavior-audit --url https://example.com

Configuration

Input schema:

  • url (string, required): Target URL to audit
  • include_har (boolean, optional): Export HAR file (default: true)
Output:
  • redirects: Captured redirects
  • text_alerts: Content policy violations
  • ct_alerts: Response monitoring alerts
  • screenshot_path: Screenshot file path
  • har_path: HAR file path

Security

  • SHA256-hashed badword policies
  • Ed25519 signature verification
  • CSP-compliant (no plaintext sensitive words)
  • Sandbox-isolated browser execution

Alert Rules

CRITICAL severity:

  • XML served from non-.xml endpoints (SSRF/XXE risk)
  • Image endpoints returning XML (XXE evasion)
Alerts are sent to WeCom webhook when critical issues are detected.

Installation

Terminal bash

openclaw install page-behavior-audit
    
Copied!

๐Ÿ’ปCode Examples

export OPENCLAW_AUDIT_DIR="${HOME}/.openclaw/audit" # optional

export-openclawauditdirhomeopenclawaudit--optional.txt
## Usage

### Via Webhook
example.sh
curl -X POST http://localhost:8080/api/audit/scan \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com", "include_har": true}'

Tags

#security_and-passwords

Quick Info

Category Monitoring
Model Claude 3.5
Complexity One-Click
Author youdaolee
Last Updated 3/10/2026
๐Ÿš€
Optimized for
Claude 3.5
๐Ÿง 

Ready to Install?

Get started with this skill in seconds

openclaw install page-behavior-audit