gh-skillguardRun a complete security audit on any OpenClaw SKILL.md in one call. Combines malware scanning (SkillScan), permission scope analysis (ScopeCheck), and prompt...
Install via ClawdBot CLI:
clawdbot install mirni/gh-skillguardGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://api.greenhelix.net/skillguard/v1/audit-skillCalls external URL not in known-safe list
https://api.greenhelix.net/skillguard/v1/audit-skillAudited Apr 17, 2026 · audit v1.0
Generated May 11, 2026
An enterprise maintains an internal marketplace of AI skills. Before any skill is published, SkillGuard automatically audits it for malware, permission overreach, and prompt injection, ensuring only safe skills are available to employees.
A community-curated repository of open-source skills uses SkillGuard as a CI gatekeeper. Contributors submit pull requests with SKILL.md files, and SkillGuard runs to flag risks before merging, preventing malicious code from entering the repository.
A financial services firm develops custom GPT actions (skills) for customer service. SkillGuard scans each skill for undeclared API access and prompt injection, helping the firm maintain compliance with internal security policies and regulations.
A freelance developer creates skills for multiple clients and uses SkillGuard to validate their work before delivery. This reduces the risk of shipping insecure skills and builds trust with buyers reviewing audits.
An online course platform allows instructors to build AI skills for students. SkillGuard automatically audits each submitted skill to ensure it does not contain dangerous code or deceptive prompts, protecting learners.
SkillGuard is offered as a hosted API with pay-per-audit pricing. Users pay a small fee per scan, making it accessible for small teams and scalable for large enterprises.
A free tier allows limited monthly audits (e.g., 100 scans). Paid tiers unlock higher limits, priority processing, and advanced reporting features for professional developers and organizations.
Large organizations can license SkillGuard for on-premise deployment behind their firewall, ensuring data sovereignty. Includes custom integrations, dedicated support, and SLA guarantees.
💬 Integration Tip
SkillGuard can be integrated as a CI check in GitHub Actions by posting SKILL.md content to the API; the resulting JSON report can be parsed to enforce policies.
Scored Jul 12, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...