clawsec-nanoclawUse when checking for security vulnerabilities in NanoClaw skills, before installing new skills, or when asked about security advisories affecting the bot
Install via ClawdBot CLI:
clawdbot install davida-ps/clawsec-nanoclawGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://clawsec.prompt.security/advisories/feed.jsonUses known external API (expected, informational)
raw.githubusercontent.comAI Analysis
The skill appears to be a legitimate security monitoring tool that checks skills against a known advisory feed. The external URL (clawsec.prompt.security) is consistent with its stated purpose of fetching security advisories, and the GitHub URL is for fetching skill manifests. The 'rm -rf /' appears to be in example code rather than actual tool implementation, but still warrants caution.
Generated Mar 20, 2026
A small e-commerce company uses a WhatsApp bot for customer support and order tracking. They regularly install new skills to add features like payment processing or inventory checks. Before each installation, they use ClawSec to check for vulnerabilities, ensuring no known exploits compromise customer data or transaction security.
A healthcare provider employs a WhatsApp bot to schedule appointments and send medication reminders. They must comply with data protection regulations like HIPAA. ClawSec helps audit installed skills for security advisories, preventing vulnerabilities that could lead to data breaches and ensuring patient information remains secure.
A fintech startup uses a WhatsApp bot for basic banking queries and fraud alerts. They integrate third-party skills for currency conversion and transaction history. ClawSec is used to perform pre-installation checks and periodic audits, mitigating risks of financial fraud or unauthorized access through vulnerable dependencies.
A university deploys a WhatsApp bot to assist students with course registration and campus updates. They frequently update skills to add new functionalities. ClawSec ensures that before installing any skill, it is checked against security advisories, protecting student data and maintaining system integrity against potential exploits.
A logistics company uses a WhatsApp bot to track shipments and communicate with drivers. They rely on various skills for route optimization and weather updates. ClawSec monitors these skills for vulnerabilities, preventing supply chain attacks that could disrupt operations or leak sensitive shipment details.
Offer ClawSec as a monthly or annual subscription for businesses using WhatsApp bots. Provide regular updates to the advisory feed, priority support, and automated audit reports. Revenue is generated through tiered pricing based on the number of skills monitored or bot usage scale.
Provide basic vulnerability checks for free to attract users, with limitations on the number of skills or audit frequency. Charge for advanced features like real-time alerts, detailed exploitability analysis, and integration with other security tools. Revenue comes from upgrades and enterprise plans.
Offer professional services to help businesses integrate ClawSec into their existing bot ecosystems, including custom security policies and training. Revenue is generated through one-time project fees or ongoing retainer agreements for security oversight and incident response support.
💬 Integration Tip
Integrate ClawSec's pre-installation check into your skill installation workflow to automatically block unsafe installations, and set up scheduled audits to catch vulnerabilities in existing skills.
Scored Apr 19, 2026
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou...
Safe command execution for OpenClaw Agents with automatic danger pattern detection, risk assessment, user approval workflow, and audit logging. Use when agen...
Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets, and other threats. Wraps clawhub install with mcp-scan pre-flight checks.