clawguarddevinSecurity scanner for OpenClaw/Clawdbot skills - detect malicious patterns before installation
Install via ClawdBot CLI:
clawdbot install devinfloyd1/clawguarddevinGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-boAI Analysis
The skill is a security scanner designed to detect malicious patterns in other skills, and the flagged signals are examples of what it detects, not actions it performs. The external URL is a documented, legitimate research blog. No evidence suggests the skill itself exfiltrates data or contains hidden malicious instructions.
Generated Mar 22, 2026
Developers and DevOps teams can use ClawGuard to scan third-party skill packages before integrating them into their Clawdbot workflows, ensuring no malicious code is introduced. This is critical for maintaining secure automation pipelines in CI/CD environments, especially when dealing with community-contributed skills from repositories.
Institutions teaching cybersecurity or bot development can deploy ClawGuard as a learning tool to analyze skill code for security vulnerabilities and malicious patterns. It helps students understand real-world threats like reverse shells and data exfiltration in a controlled setting, reinforcing best practices in secure coding.
Large organizations using Clawdbot for business automation can integrate ClawGuard into their security protocols to vet all skills before deployment. This mitigates risks from insider threats or compromised packages, protecting sensitive data and infrastructure from attacks like credential harvesting or C2 communications.
Cybersecurity analysts and researchers can leverage ClawGuard to scan and catalog malicious skills, using its IOC database to identify emerging threats in the Clawdbot ecosystem. This supports ongoing monitoring and reporting on campaigns like ClawHavoc, aiding in proactive defense strategies.
Offer a basic version of ClawGuard for free to individual users and small teams, with advanced features like real-time IOC updates, detailed reporting, and API access available through a subscription. This model encourages adoption while generating revenue from enterprises needing enhanced security tools.
Sell enterprise licenses to large organizations, including custom integrations, dedicated support, and tailored IOC databases. This model targets businesses with strict compliance needs, providing ongoing maintenance and training services to ensure effective use of the scanner in corporate environments.
Integrate ClawGuard into existing security or development platforms as a value-added service, earning revenue through partnership agreements or revenue sharing. This model expands reach by leveraging established channels, such as CI/CD tool providers or cybersecurity suites, to offer scanning as part of their offerings.
💬 Integration Tip
Integrate ClawGuard into CI/CD pipelines by running scans automatically before skill deployments, using the JSON output format for easy parsing and alerting in tools like Jenkins or GitHub Actions.
Scored Jun 19, 2026
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...