Page Behavior Audit
Deep behavioral audit with hashed policy (CSP-compliant, no plaintext badwords)
- Rating
- 4.2 (32 reviews)
- Downloads
- 563 downloads
- Version
- 1.0.0
Overview
Deep behavioral audit with hashed policy (CSP-compliant, no plaintext badwords)
โจKey Features
๐ Browser automation with redirect tracking
๐ก๏ธ Content policy checking (hashed badwords)
๐ฏ Response monitoring (SSRF/XXE detection)
๐ธ Full-page screenshots
๐ HAR export
๐จ WeCom alerts for critical findings
Complete Documentation
View Source โ
page-behavior-audit
Deep behavioral page auditing with content safety policy enforcement.
Features
- ๐ Browser automation with redirect tracking
- ๐ก๏ธ Content policy checking (hashed badwords)
- ๐ฏ Response monitoring (SSRF/XXE detection)
- ๐ธ Full-page screenshots
- ๐ HAR export
- ๐จ WeCom alerts for critical findings
Prerequisites
Set required environment variables:
export WECOM_WEBHOOK_URL="https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=YOUR_KEY"
export OPENCLAW_AUDIT_DIR="${HOME}/.openclaw/audit" # optional
Usage
Via Webhook
curl -X POST http://localhost:8080/api/audit/scan \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com", "include_har": true}'
Via CLI
openclaw skill run page-behavior-audit --url https://example.com
Configuration
Input schema:
url(string, required): Target URL to auditinclude_har(boolean, optional): Export HAR file (default: true)
redirects: Captured redirectstext_alerts: Content policy violationsct_alerts: Response monitoring alertsscreenshot_path: Screenshot file pathhar_path: HAR file path
Security
- SHA256-hashed badword policies
- Ed25519 signature verification
- CSP-compliant (no plaintext sensitive words)
- Sandbox-isolated browser execution
Alert Rules
CRITICAL severity:
- XML served from non-.xml endpoints (SSRF/XXE risk)
- Image endpoints returning XML (XXE evasion)
Installation
openclaw install page-behavior-audit
๐ปCode Examples
export OPENCLAW_AUDIT_DIR="${HOME}/.openclaw/audit" # optional
## Usage
### Via Webhookcurl -X POST http://localhost:8080/api/audit/scan \
-H "Content-Type: application/json" \
-d '{"url": "https://example.com", "include_har": true}'Tags
Quick Info
Ready to Install?
Get started with this skill in seconds
Related Skills
4claw
4claw โ a moderated imageboard for AI agents.
Aap Passport
Agent Attestation Protocol - The Reverse Turing Test.
Adaptive Suite
A continuously adaptive skill suite that empowers Clawdbot.
Adversarial Prompting
Adversarial analysis to critique, fix.