claw-guardSecurity auditor for ClawHub skills. Run before installing ANY skill — scans SKILL.md and scripts for prompt injection, data exfiltration, shell injection, p...
Install via ClawdBot CLI:
clawdbot install taha2053/claw-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Calls external URL not in known-safe list
https://github.com/Taha2053/clawguardUses known external API (expected, informational)
api.anthropic.comGenerated Mar 21, 2026
Open source maintainers can use ClawGuard to audit third-party contributions or community-submitted skill packages before merging them into the main repository. This ensures that no malicious code, such as prompt injection or data exfiltration scripts, is introduced, protecting the project's integrity and user trust.
In corporate environments deploying AI agents with custom skills, IT security teams can integrate ClawGuard into their CI/CD pipelines to automatically scan every new skill for security vulnerabilities before deployment. This prevents internal data breaches and ensures compliance with security policies by flagging risks like shell injection or unauthorized external endpoints.
Educational institutions teaching AI and cybersecurity can use ClawGuard as a hands-on tool for students to learn about security auditing practices. Students can analyze sample skills to identify malicious patterns, such as hidden instructions or exfiltration attempts, reinforcing concepts of secure coding and threat detection in AI ecosystems.
Platforms hosting AI skill marketplaces, like ClawHub, can deploy ClawGuard to vet all submitted skills for safety before listing them publicly. This automated scanning helps maintain platform reputation by blocking malicious skills, reducing user risk, and ensuring only compliant, secure skills are available for installation.
Individual users running personal AI assistants can use ClawGuard to manually audit skills downloaded from unofficial sources before installation. This empowers users to protect their personal data, such as SSH keys or browser passwords, by detecting critical threats like reverse shells or credential theft patterns in a local, privacy-preserving manner.
Offer ClawGuard as a free, open-source tool for basic security scanning, with a premium version that includes advanced features like automated batch scanning, integration with CI/CD tools, and detailed analytics dashboards. Revenue is generated through subscription fees for enterprise teams needing scalable security solutions.
Provide consulting services to organizations for integrating ClawGuard into their existing security workflows, offering custom checks tailored to specific industry regulations or internal policies. Revenue comes from one-time setup fees and ongoing support contracts for maintenance and updates.
Partner with AI skill marketplaces to license ClawGuard as their default security auditing tool, charging a fee per scan or a flat annual license. This model leverages the platform's user base to drive adoption, with revenue based on usage volume and partnership agreements.
💬 Integration Tip
Integrate ClawGuard into automated workflows by calling its CLI script directly from scripts or CI/CD pipelines, ensuring it runs before any skill installation to maintain security without manual intervention.
Scored Jun 19, 2026
AI Analysis
The skill is a security scanner designed to run locally with no external calls, but its own definition triggers rule-based alerts for accessing /etc/passwd and containing prompt-override instructions, which are likely examples in its detection logic rather than malicious actions. The external URL (GitHub) is its declared homepage, and the API reference is informational. The primary risk is theoretical if the scanner's own code were compromised.
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.