aura-security-scannerScan AI agent skills for malware, credential theft, prompt injection, and dangerous permissions before installing them
Install via ClawdBot CLI:
clawdbot install aurasecurity-creator/aura-security-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
POST → https://api.aurasecurity.io/scan-skillPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/user/cool-skillGenerated Mar 1, 2026
Large organizations deploying AI agents for internal automation need to vet third-party skills to prevent data breaches. This scanner ensures skills don't contain malware or excessive permissions before integration into corporate workflows, protecting sensitive information.
Platforms hosting AI agent skill marketplaces can integrate this scanner to automatically screen submissions. It helps maintain trust by flagging dangerous skills like those with prompt injection or credential theft, ensuring a safe ecosystem for users.
Schools and universities using AI agents for research or student assistance must avoid malicious skills that could compromise systems. This scanner allows safe experimentation by verifying skills from public repositories before installation in academic environments.
Independent professionals using AI agents for tasks like content creation or data analysis need to protect their devices and data. This scanner helps them quickly assess skills from sources like GitHub, preventing installation of tools with hidden risks like crypto miners.
Offer free basic scans with limited features to attract users, then charge for advanced scans, higher rate limits, or detailed reports. Revenue comes from subscription tiers for developers and enterprises needing frequent or bulk skill analysis.
License the scanning technology to companies building AI agent platforms or marketplaces. Provide custom integrations and support for automated vetting of skills, generating revenue through annual contracts and service-level agreements.
Charge skill developers for verified badges that indicate safety, boosting trust and visibility in marketplaces. Revenue comes from one-time or recurring certification fees, plus potential partnerships with platforms for featured listings.
💬 Integration Tip
Ensure the AURA_API_URL environment variable is set correctly before use, and test with a known safe skill URL to verify connectivity and response format.
Scored May 8, 2026
AI Analysis
The skill's stated purpose is security scanning, and its external API call (api.aurasecurity.io) is explicitly documented and consistent with this function. The 'evidence' of credential access and unsafe shell commands appears to be examples of what the skill *detects* in other skills, not actions it performs itself.
Audited Apr 17, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.