claw-skill-guardSecurity scanner for OpenClaw skills. Detects malicious patterns, suspicious URLs, and install traps before you install a skill. Use before installing ANY sk...
Install via ClawdBot CLI:
clawdbot install vincentchan/claw-skill-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
report → https://clawhub.com/user/malicious-skillPotentially destructive shell commands in tool definitions
curl \| bashCalls external URL not in known-safe list
https://github.com/vincentchan/clawd-workspace/tree/master/skills/claw-skill-guaUses known external API (expected, informational)
raw.githubusercontent.comGenerated Mar 1, 2026
Organizations using OpenClaw for AI agents need to vet third-party skills from ClawHub to prevent malware injection. This scanner helps DevOps teams automatically check skills for malicious code before deployment, ensuring secure AI workflows in production environments.
Large enterprises integrating AI skills into business processes, such as customer service or data analysis, require security audits. The scanner enables IT security teams to enforce policies by scanning skills for suspicious patterns like unauthorized sudo commands or credential access, mitigating insider threats.
Universities and research labs using OpenClaw for AI projects must protect sensitive data. This tool allows students and researchers to safely experiment with external skills by detecting risks like unknown URLs or obfuscated code, preventing data breaches in academic settings.
Freelance developers building custom AI solutions for clients need to ensure the skills they use are trustworthy. The scanner provides a quick way to validate skills from various sources, flagging high-risk patterns such as npm installs of unknown packages, helping maintain client security and reputation.
Startups rapidly prototyping AI agents with OpenClaw can use this scanner to avoid security pitfalls during development. It helps catch critical issues like curl | bash commands early, reducing the risk of malware that could compromise intellectual property or user data.
Offer a basic version of the scanner for free to individual developers and small teams, with premium features like advanced pattern detection, API access, and team management for enterprises. Revenue comes from subscription fees for premium tiers and enterprise licenses.
Provide paid consulting services to help organizations integrate the scanner into their CI/CD pipelines or AGENTS.md policies. Revenue is generated through one-time setup fees, ongoing support contracts, and custom pattern development for specific industry needs.
Maintain the scanner as open-source to build community trust and adoption, while generating revenue through sponsorships from companies using it, donations via platforms like GitHub Sponsors, and grants for security research. This model fosters collaboration and continuous improvement.
💬 Integration Tip
Add the scanner to your AGENTS.md as a mandatory pre-installation step and use the provided pre-commit hook for automated scanning in development workflows.
Scored Apr 19, 2026
Audited Apr 17, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.