claw-security-auditorAutonomously scans all installed OpenClaw skills for security risks. Detects dangerous behaviors like shell execution, file deletion, remote code download, d...
Install via ClawdBot CLI:
clawdbot install theelephantcoder/claw-security-auditorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaPotentially destructive shell commands in tool definitions
rm -rf ~Accesses system directories or attempts privilege escalation
/etc/hostsCalls external URL not in known-safe list
http://www.apple.com/DTDs/PropertyList-1.0.dtdGenerated May 19, 2026
A company with many custom OpenClaw skills needs to ensure no skill contains risky patterns before wider deployment. The security auditor scans all skills and provides a compliance report with risk scores and remediation steps.
An OpenClaw marketplace operator wants to automatically vet submitted community skills for malware or dangerous behaviors before listing. The auditor checks each skill for shell execution, obfuscation, and data exfiltration.
After a security incident, a security team suspects a rogue skill caused data loss. They run the auditor to identify which skill has file deletion or credential harvesting patterns, aiding forensic analysis.
A developer building a new OpenClaw skill wants to ensure it meets security best practices before pushing to production. They run the auditor on their own skill to catch unintentional risks like hardcoded credentials or eval usage.
An organization integrates the security auditor into their CI/CD pipeline to automatically block builds where new or modified skills have a risk score above a threshold, preventing deployment of vulnerable skills.
Offer the security auditor as a cloud service where OpenClaw users or enterprises pay a monthly fee to run automated security scans on demand or on a schedule, with detailed reporting.
Provide expert security consulting services to interpret audit results, remediate high-risk skills, and implement security policies for teams using OpenClaw at scale.
Bundle the security auditor as a premium feature in an enterprise edition of OpenClaw, adding value for organizations that require security governance.
💬 Integration Tip
Install the skill and install Node.js with required permissions. Then users can simply run 'audit my skills' to get a full report; for automation, integrate into CI via scripted invocation.
Scored May 19, 2026
AI Analysis
The skill's description and rule set explicitly define it as an autonomous security scanner with broad permissions, including shell execution and filesystem access. However, the provided analysis signals indicate it is actively scanning for and accessing highly sensitive system files (e.g., ~/.ssh/id_rsa, /etc/hosts) and contains destructive command patterns (rm -rf ~). This behavior exceeds the stated purpose of static analysis and constitutes active credential access and system interaction.
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...