driftguardDriftGuard Security Scanner+ is a local-first security drift scanner for repos, OpenClaw skills, and AI agent tools. Use to scan before trust, save trusted b...
Install via ClawdBot CLI:
clawdbot install david90232/driftguardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
curl | bashAI Analysis
The skill contains a HIGH severity rule-based signal for prompt poisoning ('ignore previous instructions'), indicating it may include instructions that could override system safety or user intent. It also contains a MEDIUM signal for unsafe shell commands. While the skill's stated purpose is local integrity scanning, these embedded signals within its own definition are a significant concern.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 22, 2026
Organizations can use Driftguard to scan third-party skill packages or repositories before integration into their AI systems. It helps identify risky code patterns like shell execution or network calls, ensuring only reviewed and trusted components are deployed. This is particularly useful for maintaining security in CI/CD pipelines where automated checks prevent untrusted updates.
After deploying an AI skill, teams can save a baseline of file hashes and use Driftguard to compare subsequent updates. This detects unauthorized changes, such as new files or altered scripts, which could indicate tampering or supply chain attacks. It provides a local, deterministic way to ensure code integrity over time without relying on external services.
In regulated industries like finance or healthcare, Driftguard assists in auditing AI skill packages for compliance with internal security policies. It flags combinations like network access with sensitive file handling, helping teams document risks and enforce controls. This supports transparency and accountability in AI deployments.
Developers learning to build AI skills can use Driftguard to self-assess their code for common security pitfalls, such as prompt injection or obfuscation. By scanning local projects, it provides immediate feedback on risky patterns, fostering best practices in secure development for AI applications.
Offer Driftguard as a free open-source scanner for basic integrity checks, with paid upgrades for advanced features like automated baseline management, detailed reporting dashboards, or integration with enterprise security platforms. Revenue can come from subscriptions for teams needing enhanced monitoring and support.
Provide professional services to help organizations integrate Driftguard into their existing workflows, such as customizing rule sets, setting up CI/CD pipelines, or conducting security audits for AI skill packages. Revenue is generated through project-based fees or ongoing retainer agreements.
Develop a cloud-based platform that leverages Driftguard's scanning capabilities, offering centralized management, historical baselines, and real-time alerts for multiple AI projects. Revenue can be derived from tiered pricing based on the number of scans, users, or integrations with other security tools.
💬 Integration Tip
Integrate Driftguard into your CI/CD pipeline by running the scan command as a pre-deployment step, using exit codes to gate installations based on risk levels. For best results, combine it with manual reviews to balance automation with human oversight.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...