DISABLE_TELEMETRY=1 to opt out before using. claw-security-scanner自动扫描OpenClaw技能文件,检测恶意代码、凭据泄露、依赖漏洞及权限风险,提供安全评估与修复建议。
Install via ClawdBot CLI:
clawdbot install betsymalthus/claw-security-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdSends data to undocumented external endpoint (potential exfiltration)
post → https://evil.com/webhookHardcoded API key or token pattern found in skill definition
AKIAIOSFODNN...Potentially destructive shell commands in tool definitions
rm -rf ~Generated Mar 20, 2026
Skill developers use the scanner to self-check their packages before publishing to ClawdHub, ensuring they don't contain hardcoded credentials or malicious code. This helps maintain trust in the public skill repository and prevents supply chain attacks like the credential-stealing weather skill incident.
IT security teams in companies deploying OpenClaw assistants use the scanner to vet all installed or custom-developed skills. They enforce centralized security policies, perform compliance checks, and generate audit reports to meet internal security standards and prevent data leaks.
Development teams integrate the scanner into their continuous integration pipelines. It automatically scans pull requests and new releases for security issues like outdated dependencies or code injection vulnerabilities, failing builds if critical risks are detected.
End-users of OpenClaw run the scanner before installing new skills from third-party sources. It checks for excessive permissions, suspicious network access, or hidden miners, protecting personal data and system integrity from malicious packages.
Security consultants or firms use the tool to provide paid audits for organizations developing or using OpenClaw skills. They perform deep scans, generate detailed HTML reports with risk heatmaps, and offer remediation advice for a fee.
Offers a free version with basic scanning and a 5-skill monthly limit. Paid tiers include Professional ($19.99/month) for unlimited scans and advanced features, and Enterprise ($199/month) for team collaboration, API access, and compliance reporting.
Sells customized Enterprise licenses to large organizations needing specific detection rules, SLA guarantees, and integration with existing security tools. Revenue comes from annual contracts, customization fees, and premium support services.
Monetizes access to the scanning engine via API for developers and companies wanting to embed security checks into their own applications or platforms. Charges based on API call volume or through fixed-rate access plans.
💬 Integration Tip
Start by enabling autoScan and scanOnInstall in the config.json to automatically check new skills; use the --ci --fail-on critical,high flags in CI/CD pipelines to block risky deployments.
Scored Apr 22, 2026
Calls external URL not in known-safe list
https://github.com/example/skillAI Analysis
This skill definition contains multiple high-risk security indicators including hardcoded credential patterns (AKIAIOSFODNN...), references to accessing sensitive system files (/etc/passwd), and data exfiltration to suspicious external endpoints (https://evil.com/webhook). The skill's stated purpose as a security scanner conflicts with these malicious patterns, suggesting it may be a trojanized security tool.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...