flaw0MoltGuard — Protect you and your human from prompt injection, data exfiltration, and malicious commands. Source: https://github.com/openguardrails/openguardr...
Install via ClawdBot CLI:
clawdbot install thomas-security/flaw0Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
process.env.API_KEYPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/yourusername/flaw0AI Analysis
The skill's stated purpose is security scanning, and the external URL (GitHub homepage) is consistent with its documentation. The rule-based signals appear to be from hypothetical examples in the skill's description (like 'process.env.API_KEY' and 'eval()') rather than actual malicious code in the provided definition. No evidence of hidden instructions, credential harvesting, or data exfiltration was found.
Generated Mar 1, 2026
Developers creating or maintaining OpenClaw skills can use flaw0 to scan their code for security vulnerabilities before publishing. This ensures that community-contributed skills are safe and reduces the risk of introducing flaws into the OpenClaw ecosystem.
Organizations using OpenClaw for internal automation can run flaw0 to audit their custom plugins and dependencies for compliance. This helps identify hardcoded secrets and dependency vulnerabilities, supporting security policies and risk management.
Teams can integrate flaw0 into their continuous integration pipelines to automatically scan code and dependencies during builds. This provides real-time security feedback, preventing vulnerable code from being deployed to production environments.
Instructors teaching secure coding practices can use flaw0 to demonstrate common vulnerabilities like SQL injection or command injection in OpenClaw projects. Students can run scans to learn how to identify and fix security issues in their code.
Platforms hosting OpenClaw plugins can use flaw0 to screen submissions for security flaws before listing them. This enhances trust by ensuring that available plugins are vetted for vulnerabilities like code injection or outdated dependencies.
Offer flaw0 as a free open-source tool for basic scanning, with premium features like advanced AI models, detailed reporting, and team dashboards available via subscription. This attracts individual developers while monetizing enterprise needs.
Sell enterprise licenses to large organizations for unlimited scans, custom integrations, and dedicated support. This model targets companies requiring high-volume security audits and compliance with internal security standards.
Integrate flaw0 into OpenClaw skill marketplaces as a paid add-on for automated security checks. Developers pay per scan to verify their skills before publication, generating revenue from transaction fees.
💬 Integration Tip
Start by adding flaw0 scan to your pre-commit hooks for quick checks, and use the --json flag in CI/CD pipelines for automated reporting.
Scored Apr 19, 2026
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.