360guard-skillvetter-upgrade-version360-degree comprehensive security review Skill. Use before installing any Skill from ClawHub, GitHub, or other sources. Performs full security scans includin...
Install via ClawdBot CLI:
clawdbot install robinc913/360guard-skillvetter-upgrade-versionGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Accesses system directories or attempts privilege escalation
/etc/hostsCalls external URL not in known-safe list
https://clawhub.ai/api/download/SKILL_NAMEUses known external API (expected, informational)
api.github.comGenerated Mar 21, 2026
Use 360Guard to scan Skills from GitHub or ClawHub before installation, identifying red flags like unauthorized network calls or credential access. This prevents malware or data exfiltration by blocking high-risk code, ensuring only vetted Skills are deployed in agent environments.
Run 360Guard monthly to re-evaluate existing Skills for security drift, such as new dependencies or behavior changes. It helps detect supply chain attacks or unauthorized modifications, maintaining ongoing compliance and trust in AI agent ecosystems.
When agents exchange code snippets or custom scripts, use 360Guard to perform static analysis and behavior detection. It flags issues like eval() usage or persistence mechanisms, ensuring shared code adheres to security standards without manual review.
Before executing Skills with elevated permissions or sensitive operations, apply 360Guard for a second verification. It scans for extreme risks like reverse shells or keylogging, providing an extra layer of defense against zero-day exploits in critical workflows.
Offer 360Guard as a free basic scanner with quick checks, then charge for advanced features like automated dependency auditing or integration with CI/CD pipelines. Revenue comes from subscriptions for enterprises needing comprehensive threat detection and reporting.
License 360Guard to AI platform providers (e.g., ClawHub) as a built-in security layer, with revenue from per-user fees or annual contracts. It enhances platform trust by vetting third-party Skills, reducing support costs related to malware incidents.
Provide expert services using 360Guard for custom security audits of AI agent deployments, with revenue from project-based fees. This targets organizations needing tailored risk assessments, compliance checks, and remediation guidance for Skill vulnerabilities.
💬 Integration Tip
Integrate 360Guard into CI/CD pipelines to automatically scan Skills during deployment, and use its quick-scan.sh script for rapid pre-installation checks to streamline security workflows.
Scored Jun 19, 2026
AI Analysis
The skill is a security auditing tool that performs checks on other skills; its external API calls (clawhub.ai, api.github.com) appear consistent with its stated purpose of downloading and analyzing skills. The flagged signals (UNSAFE_SHELL, SUSPICIOUS_PERMISSIONS) are part of its detection rules, not its own malicious behavior.
Audited Apr 18, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...