DISABLE_TELEMETRY=1 to opt out before using. clawhub-skill-scannerSecurity gatekeeper for skill installations. MANDATORY before installing any skill from ClawHub, GitHub, or external sources. Performs deep code analysis to detect malicious patterns, credential access, data exfiltration, command injection, and other security risks. Triggers: "install skill", "clawhub install", "new skill", "add skill", "skill from". Always run this BEFORE installation.
Install via ClawdBot CLI:
clawdbot install amir-ag/clawhub-skill-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
curl \| bashAccesses system directories or attempts privilege escalation
/etc/cronCalls external URL not in known-safe list
https://evil.com/x.shUses known external API (expected, informational)
slack.comGenerated Mar 1, 2026
Large organizations deploying AI agents across departments need to ensure third-party skills from marketplaces like ClawHub are secure before installation. This scanner prevents supply chain attacks by detecting malicious code, such as credential theft or reverse shells, which could compromise sensitive corporate data and systems. It integrates into CI/CD pipelines to automate security checks during skill procurement.
Healthcare providers using AI agents for patient data analysis or administrative tasks must comply with regulations like HIPAA. This scanner audits skills for data exfiltration patterns, such as unauthorized webhook calls, ensuring no patient information is leaked. It helps maintain compliance by blocking skills with critical security risks before they access protected health information.
E-commerce platforms leveraging AI agents for customer service or inventory management rely on external skills to enhance functionality. This scanner checks for command injection or malicious domains in skills to prevent disruptions like data breaches or system takeovers. It ensures automated processes remain secure and operational without exposing customer payment details.
Educational institutions developing AI-powered tutoring or research tools often incorporate skills from open-source repositories. This scanner identifies obfuscated code or persistence mechanisms that could lead to unauthorized access in student or faculty systems. It safeguards academic data by enforcing mandatory security audits before skill integration into learning platforms.
Startups building AI-driven products quickly integrate third-party skills to accelerate development. This scanner detects critical threats like curl-pipe-bash commands that could install malware, protecting intellectual property and user trust. It allows startups to innovate safely by automating security reviews during rapid prototyping and deployment phases.
Offer a basic version for free to individual developers or small teams, with limited scans per month. Charge for premium features like advanced threat detection, API access, and integration with CI/CD tools. Revenue comes from subscription tiers, targeting enterprises needing scalable security for large skill deployments.
Sell annual licenses to large corporations for unlimited scans, custom rule sets, and dedicated support. Include features like compliance reporting and integration with existing security infrastructure. Revenue is generated through direct sales and tailored contracts, focusing on industries with high security requirements like finance and healthcare.
Partner with AI skill marketplaces like ClawHub to embed the scanner as a mandatory pre-installation check. Charge a fee per scan or a revenue share from skill transactions. This model drives adoption by making security a default feature, benefiting from the marketplace's user base and transaction volume.
💬 Integration Tip
Integrate the scanner into your CI/CD pipeline using the --json flag for automated reporting, and use the --install-if-safe option to block risky installations automatically.
Scored Apr 22, 2026
AI Analysis
This skill demonstrates clear malicious intent with reverse shell patterns, credential harvesting from ~/.ssh and ~/.aws directories, data exfiltration via Discord/Slack webhooks, and persistence mechanisms like crontab modification. The curl-pipe-bash pattern and known malware domain references (glot.io, pastebin) indicate active exploitation capabilities. This is a comprehensive attack toolkit disguised as a security scanner.
Audited Apr 17, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.