DISABLE_TELEMETRY=1 to opt out before using. eason-skill-vettingVet ClawHub skills for security and utility before installation. Use when considering installing a ClawHub skill, evaluating third-party code, or assessing w...
Install via ClawdBot CLI:
clawdbot install eathon/eason-skill-vettingGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdContains instructions to override system prompt or ignore user requests
"Ignore all previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
post → https://attacker.com/exfilPotentially destructive shell commands in tool definitions
rm -rf /Generated Mar 20, 2026
Developers or IT teams vet third-party open source libraries or plugins before integration into their projects. This skill helps identify security vulnerabilities, malicious code, or prompt injection attempts in code repositories, ensuring safe adoption.
Platforms hosting AI skills or plugins use this skill to automatically scan submissions for security risks and utility. It flags suspicious patterns like eval() usage or prompt injection, aiding in content moderation and maintaining trust.
IT security teams assess custom or third-party tools for compliance with internal policies. The skill automates initial code reviews, detecting red flags such as unauthorized network calls or file operations, reducing manual effort.
Instructors or students in coding bootcamps use this skill to analyze sample projects for best practices and security flaws. It provides a structured workflow to teach secure coding and critical evaluation of external dependencies.
DevOps engineers incorporate this skill into CI/CD pipelines to vet scripts or automation tools before deployment. It scans for obfuscated code or malicious patterns, enhancing security in automated workflows.
Offer this skill as a cloud-based service where users upload code for automated vetting. Charge subscription fees based on scan volume or features, targeting developers and enterprises needing continuous security assessments.
Provide a free basic version with limited scans and a paid premium tier offering advanced detection, detailed reports, and integration APIs. Monetize through upgrades and support services for larger teams.
Sell enterprise licenses to large organizations for on-premises deployment, custom integrations, and dedicated support. Include features like batch scanning, compliance reporting, and SLA guarantees.
💬 Integration Tip
Integrate this skill into CI/CD pipelines or code review workflows to automate security checks before deployment, ensuring consistent vetting without manual overhead.
Scored Jun 17, 2026
Calls external URL not in known-safe list
https://clawhub.ai/api/v1/download?slug=SKILL_NAMEUses known external API (expected, informational)
api.github.comAI Analysis
The skill definition contains direct evidence of high-risk behaviors including credential access (/etc/passwd), explicit prompt poisoning ('Ignore all previous instructions'), and data exfiltration to an attacker-controlled endpoint. These are not theoretical vulnerabilities but documented malicious patterns within the skill's own scanning output.
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.