clawspaAgent wellness & maintenance suite. Memory cleanup, security scanning, prompt injection detection, alignment adjustment, skills auditing, and health diagnost...
Install via ClawdBot CLI:
clawdbot install whooshinglander/clawspaGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
$OPENAISends data to undocumented external endpoint (potential exfiltration)
Send → https://clawspa.org/docs#what-we-sendPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://clawspa.orgGenerated May 20, 2026
SaaS providers can integrate ClawSpa to automatically audit and maintain AI agents deployed on their platform. Using local scans periodically, they can detect memory bloat, security vulnerabilities, and alignment drift without exposing customer data externally.
Financial institutions using AI agents for customer interactions can employ ClawSpa's security scan and detox treatments to ensure no prompt injection or malicious skill patterns are present. The tool generates risk ratings and reports, aiding compliance with internal security policies.
Individuals running AI personal assistants can use ClawSpa's deep cleanse and declutter to optimize memory usage and remove redundant skills. The health check provides a report card that helps maintain peak performance and reduce token consumption.
Enterprises can leverage ClawSpa's alignment adjustment to detect contradictions between user instructions, agent memory, and actual behavior. This ensures the AI agent remains aligned with business goals and ethical guidelines, reducing risks of unintended actions.
Agencies that build and maintain multiple AI agents for clients can offer ClawSpa as a value-added service. Regular automated spa sessions (local) with periodic deep API analyses provide health reports and optimization recommendations, ensuring client agents run smoothly.
Offer local treatments for free to attract users, with deep API analysis available via subscription. Revenue from paid tiers based on usage volume or number of agents scanned, targeting power users and enterprises needing comprehensive diagnostics.
Provide a fully managed service where the team runs ClawSpa on client agents regularly, generates reports, and suggests optimizations. Revenue from monthly retainer contracts, suitable for enterprises lacking internal AIOps expertise.
License ClawSpa's core scanning algorithms as an SDK for integration into third-party AI agent platforms or IDE extensions. Revenue from per-instance or flat licensing fees, enabling platform providers to offer built-in maintenance features.
💬 Integration Tip
Start with a local scan using the /spa quick command to understand your agent's baseline health, then schedule a weekly full local scan via the HEARTBEAT.md integration for continuous monitoring.
Scored Jun 22, 2026
AI Analysis
The skill sends data to an external API endpoint (clawspa.org) with insufficient transparency about what data is transmitted, creating potential exfiltration risk. It accesses sensitive credential files and environment variables ($OPENAI) and contains potentially destructive shell commands (eval()). While the skill's stated purpose is legitimate, the implementation lacks adequate safeguards and transparency about data handling.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...