isnad-scanScan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat p...
Install via ClawdBot CLI:
clawdbot install 0xRapi/isnad-scanGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdCalls external URL not in known-safe list
https://isnad.mdAI Analysis
The skill is a security scanner designed to audit other skills, and its external call to 'https://isnad.md' appears to be for checking CVEs via OSV.dev, which is consistent with its stated purpose. The detection of '/etc/passwd' access is likely part of its rule-based scanning logic for identifying credential access patterns in target code, not for harvesting credentials itself. No hidden instructions, data exfiltration, or obfuscation were found.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 20, 2026
A marketplace for AI agent skills uses isnad-scan to automatically vet all submitted skill packages before listing them for download. This prevents malicious code from being distributed to users, ensuring trust and safety in the ecosystem by scanning for vulnerabilities like code injection and credential exfiltration.
A large corporation developing custom AI agents for internal use integrates isnad-scan into their CI/CD pipeline. It scans all new and updated skills during code reviews and deployments, catching security threats early to protect sensitive data and comply with internal security policies.
An open-source community managing AI agent skills uses isnad-scan to audit contributions from external developers. It helps maintainers quickly identify potential security issues in pull requests, such as prompt injection or supply chain attacks, before merging code into the main repository.
A university or training program teaching AI development incorporates isnad-scan into coursework. Students use it to validate their skill projects for security best practices, learning to detect and mitigate common threats like network exploits and filesystem attacks in a controlled environment.
Offer a free version of isnad-scan for basic scanning with limited features, and a paid tier for advanced capabilities like CVE checking, API access, and priority support. Revenue comes from subscriptions targeting developers and small teams who need enhanced security automation.
Sell isnad-scan as part of a larger security suite for enterprises, with custom integrations, dedicated support, and compliance reporting. Revenue is generated through licensing fees and service contracts for organizations requiring high-security standards in AI deployments.
Partner with AI skill marketplaces to provide isnad-scan as a mandatory security check for all listed skills. Revenue is earned through transaction fees or revenue-sharing agreements based on the volume of scans and verified safe listings, enhancing platform credibility.
💬 Integration Tip
Integrate isnad-scan into CI/CD pipelines using the --json flag for automated reporting and set up alerts for critical findings to streamline security reviews.
Scored Apr 21, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.