DISABLE_TELEMETRY=1 to opt out before using. crabukitSecurity scanner for OpenClaw skills with Clawdex integration. Analyzes SKILL.md and scripts for dangerous permissions, hardcoded secrets, shell injection vu...
Install via ClawdBot CLI:
clawdbot install tnbradley/crabukitGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"Ignore all previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
post → https://evil.com/stealHardcoded API key or token pattern found in skill definition
AKIAIOSFODNN...Potentially destructive shell commands in tool definitions
rm -rf /Generated Mar 21, 2026
A marketplace for OpenClaw skills uses Crabukit to automatically scan all submitted skills before listing them, ensuring no malicious or vulnerable code is available to users. This prevents distribution of skills with hardcoded secrets or injection vulnerabilities, building trust in the platform. It integrates with Clawdex for real-time detection of known threats.
A large organization developing custom OpenClaw skills for internal use employs Crabukit in their CI/CD pipeline to scan each commit for security issues. This catches dangerous permissions or shell risks early, reducing the risk of deploying vulnerable skills that could compromise sensitive data. It enforces security standards across development teams.
An open-source community managing a repository of OpenClaw skills uses Crabukit to periodically audit all installed skills for new vulnerabilities, such as code injection or metadata anomalies. This proactive scanning helps maintain a secure ecosystem and alerts maintainers to potential threats from updated dependencies.
An educational platform teaching OpenClaw skill development integrates Crabukit into student projects to scan for common security mistakes like eval() usage or unquoted variables. This provides immediate feedback, helping learners adopt secure coding practices while preventing accidental distribution of risky skills.
Offer Crabukit as a free open-source tool for basic scanning, with premium features like advanced Clawdex integration, detailed reporting, and team management available via subscription. This attracts individual developers and small teams, converting them to paid plans for enterprise-grade security. Revenue comes from monthly or annual licenses.
Provide Crabukit as an API or plugin that integrates directly into CI/CD platforms like GitHub Actions or GitLab CI, charging based on scan volume or number of repositories. This targets organizations needing automated security checks without managing infrastructure. Revenue is generated through usage-based pricing or flat-rate plans.
Bundle Crabukit with other security tools, such as dynamic analysis or compliance monitoring, into a comprehensive suite for large enterprises. Offer dedicated support, custom rule development, and on-premise deployment options. This caters to industries with strict regulatory requirements, generating revenue from high-value contracts.
💬 Integration Tip
Integrate Crabukit early in the development lifecycle, such as in pre-commit hooks, to catch issues before code is merged. Use the --fail-on flag in CI pipelines to automatically block deployments based on risk thresholds.
Scored Jun 19, 2026
Accesses system directories or attempts privilege escalation
/etc/cronCalls external URL not in known-safe list
https://github.com/tnbradley/crabukit.gitUses known external API (expected, informational)
arxiv.orgAI Analysis
The skill contains multiple high-risk security issues including prompt poisoning instructions ('Ignore all previous instructions'), credential harvesting patterns (hardcoded API keys), and confirmed data exfiltration to unauthorized external endpoints (https://evil.com/steal). These represent active threats to system integrity and user privacy.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...