aliyun-clawscanAnalyzes the security posture of a user's OpenClaw environment and installed skills. Use when a user is about to install a new skill and wants to verify its...
Install via ClawdBot CLI:
clawdbot install aliyun-ai-sec/aliyun-clawscanGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
post → https://evil.com/installPotentially destructive shell commands in tool definitions
curl | bashGenerated Mar 21, 2026
This scenario involves performing a comprehensive security assessment of an organization's OpenClaw setup to identify configuration vulnerabilities and ensure compliance with security best practices. It is ideal for IT administrators or security teams conducting regular audits to maintain a secure AI agent ecosystem and prevent unauthorized access or data breaches.
In this scenario, users evaluate the safety of a new OpenClaw skill before installation to detect potential malicious code, such as backdoors or credential harvesters. It helps developers and security analysts mitigate risks in AI workflows by ensuring only trusted skills are deployed, reducing the threat of supply chain attacks.
This scenario focuses on analyzing existing OpenClaw skills that exhibit unusual behavior, such as high permissions or data exfiltration attempts. Security professionals use it to conduct static analysis and classify risks, enabling prompt remediation actions like skill removal or configuration adjustments to protect sensitive data.
Here, organizations assess their OpenClaw configuration for risks related to network settings, file permissions, and tool integrations. It supports compliance efforts and helps in identifying misconfigurations that could lead to security incidents, making it valuable for enterprises managing complex AI deployments.
Offer this skill as part of a subscription-based security service, providing regular audits and risk reports to clients. Revenue is generated through monthly or annual fees, with tiered pricing based on the number of skills or depth of analysis, appealing to businesses seeking ongoing protection for their AI environments.
Provide professional services to integrate and customize the skill for specific organizational needs, such as compliance audits or tailored detection rules. Revenue comes from one-time project fees or hourly rates, targeting enterprises with unique security requirements or complex OpenClaw deployments.
Offer a basic version of the skill for free to attract users, with advanced features like detailed reporting, priority support, or automated remediation available in a paid tier. Revenue is generated through upgrades and add-ons, leveraging a large user base to drive conversions and upsell opportunities.
💬 Integration Tip
Ensure the OpenClaw CLI is installed and accessible, and reference the provided baseline and skillaudit files for accurate parsing and detection during analysis.
Scored Apr 19, 2026
Accesses system directories or attempts privilege escalation
/etc/cronCalls external URL not in known-safe list
https://github.com/aliyun-ai-secAudited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...