jax-skill-security-scannerOpenClaw技能安全扫描器 - 专业级安全审计工具,检测敏感操作、木马后门,保护您的AI助手生态安全
Install via ClawdBot CLI:
clawdbot install jasonshieh/jax-skill-security-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"Calls external URL not in known-safe list
https://github.com/jax-npm/skill-security-scannerAI Analysis
This is a legitimate security scanning tool that intentionally contains security-related keywords and patterns to detect them in other skills. The 'ignore previous instructions' appears in the context of detecting prompt injection attacks, not as malicious behavior. The GitHub URL is the package's own repository, consistent with its stated purpose.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 20, 2026
Marketplace operators can integrate this scanner into their skill submission pipeline to automatically audit new skills for security risks before approval. It helps prevent malicious skills from being published, ensuring user safety and maintaining platform integrity by detecting sensitive operations and AI poisoning attempts.
Organizations developing custom AI agents for internal use can employ this tool to audit in-house or third-party skills for security vulnerabilities. It ensures compliance with IT security policies by scanning for backdoors, data exfiltration risks, and unauthorized network communications, protecting sensitive corporate data.
Development teams can incorporate this scanner into their CI/CD pipelines to perform automated security checks on skill code during builds. It identifies risks like dangerous commands or trojan patterns early, enabling proactive remediation and reducing the attack surface in production environments.
Security consultants can use this tool to provide detailed audits for clients using AI assistants, generating reports on skill vulnerabilities. It helps assess overall ecosystem safety, recommend mitigations, and demonstrate compliance with security standards through structured outputs like JSON or markdown.
Academics and researchers can utilize the scanner to study emerging AI-specific threats, such as prompt injection or jailbreak attacks, across skill repositories. It aids in analyzing attack patterns, contributing to security research and developing countermeasures for AI assistant ecosystems.
Offer a free basic version for individual developers or small teams, with premium features like advanced reporting, custom rule sets, and API access for enterprise clients. Revenue is generated through subscription tiers, targeting larger organizations needing comprehensive security audits.
License the scanner to AI assistant platforms or marketplaces as a built-in security module, charging based on usage volume or a flat annual fee. This model leverages partnerships to embed the tool into existing ecosystems, providing value through enhanced safety and trust.
Provide consulting services for custom integrations, security training, and tailored audits using the scanner. Revenue comes from project-based fees and ongoing support contracts, catering to businesses with specific compliance needs or complex deployment environments.
💬 Integration Tip
Integrate via CI/CD pipelines using JSON output for automated risk checks, and configure environment variables for default scan paths to streamline deployment.
Scored Jun 17, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.