clawhub-publish-conventionsClawHub skill publishing conventions — file inclusion rules, metadata requirements, versioning, and scanner false-positive defense. Use when publishing or up...
Install via ClawdBot CLI:
clawdbot install almohalhel1408/clawhub-publish-conventionsGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Generated May 11, 2026
A developer creates a new cybersecurity automation skill and needs to publish it on ClawHub. They must follow the file inclusion rules, metadata requirements, and versioning conventions to ensure successful publication and scanner clearance.
An AI agent skill requires an update to fix a bug or add a feature. The developer must increment the version, add a changelog, and republish, ensuring all metadata and file inclusions are correct to avoid rejection.
A skill containing legitimate security mechanisms like obfuscation or sandboxing is flagged by ClawHub's scanner. The developer must add a 'Security Disclaimers' section in SKILL.md and README.md explaining the context to clear the scan.
A developer creates a skill that runs untrusted code and needs a secure sandbox. They follow the distroless Docker pattern to build a minimal image without a shell, reducing attack surface while maintaining Python functionality.
A skill spawns subprocesses and must pass the scanner's security checks. The developer implements environment scrubbing and command validation to prevent command injection and secret leakage, ensuring a CLEAN verdict.
Developers publish cybersecurity or automation skills on ClawHub and earn royalties each time their skill is used or subscribed to. Revenue scales with the number of active users or installations.
Companies license specialized skills (e.g., for compliance scanning) internally via ClawHub. They pay an annual fee for a bundle of skills tailored to their security operations.
Expert developers offer consulting to build custom ClawHub skills for clients, including packaging, scanning defense, and publishing. They charge a one-time development fee plus optional maintenance.
💬 Integration Tip
When integrating with ClawHub, always run 'clawhub publish' with the --version and --changelog flags, then wait for the scan before releasing. Embed any excluded files (like Dockerfiles) directly in SKILL.md using collapsible code blocks to ensure users can copy them.
Scored May 11, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...