claw-skill-guardSecurity scanner for OpenClaw skills. Detects malicious patterns, suspicious URLs, and install traps before you install a skill. Use before installing ANY sk...
Install via ClawdBot CLI:
clawdbot install vincentchan/claw-skill-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
report → https://clawhub.com/user/malicious-skillPotentially destructive shell commands in tool definitions
curl \| bashCalls external URL not in known-safe list
https://github.com/vincentchan/clawd-workspace/tree/master/skills/claw-skill-guaUses known external API (expected, informational)
raw.githubusercontent.comGenerated Mar 1, 2026
Organizations using OpenClaw for AI agents need to vet third-party skills from ClawHub to prevent malware injection. This scanner helps DevOps teams automatically check skills for malicious code before deployment, ensuring secure AI workflows in production environments.
Large enterprises integrating AI skills into business processes, such as customer service or data analysis, require security audits. The scanner enables IT security teams to enforce policies by scanning skills for suspicious patterns like unauthorized sudo commands or credential access, mitigating insider threats.
Universities and research labs using OpenClaw for AI projects must protect sensitive data. This tool allows students and researchers to safely experiment with external skills by detecting risks like unknown URLs or obfuscated code, preventing data breaches in academic settings.
Freelance developers building custom AI solutions for clients need to ensure the skills they use are trustworthy. The scanner provides a quick way to validate skills from various sources, flagging high-risk patterns such as npm installs of unknown packages, helping maintain client security and reputation.
Startups rapidly prototyping AI agents with OpenClaw can use this scanner to avoid security pitfalls during development. It helps catch critical issues like curl | bash commands early, reducing the risk of malware that could compromise intellectual property or user data.
Offer a basic version of the scanner for free to individual developers and small teams, with premium features like advanced pattern detection, API access, and team management for enterprises. Revenue comes from subscription fees for premium tiers and enterprise licenses.
Provide paid consulting services to help organizations integrate the scanner into their CI/CD pipelines or AGENTS.md policies. Revenue is generated through one-time setup fees, ongoing support contracts, and custom pattern development for specific industry needs.
Maintain the scanner as open-source to build community trust and adoption, while generating revenue through sponsorships from companies using it, donations via platforms like GitHub Sponsors, and grants for security research. This model fosters collaboration and continuous improvement.
💬 Integration Tip
Add the scanner to your AGENTS.md as a mandatory pre-installation step and use the provided pre-commit hook for automated scanning in development workflows.
Scored Apr 19, 2026
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou...
Safe command execution for OpenClaw Agents with automatic danger pattern detection, risk assessment, user approval workflow, and audit logging. Use when agen...
Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets, and other threats. Wraps clawhub install with mcp-scan pre-flight checks.