moltcops-skillPre-install security scanner for AI agent skills. Detects malicious patterns before you trust code. Local-first — code never leaves your machine.
Install via ClawdBot CLI:
clawdbot install Adamthompson33/moltcops-skillGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://scan.moltcops.com**AI Analysis
The skill is a local security scanner designed to protect users by analyzing other skills for threats. It explicitly states it makes no external API calls and processes all code locally on the user's machine. Its stated purpose and described functionality are aligned with enhancing security, not compromising it.
Audited Apr 18, 2026 · audit v1.0
Generated Mar 22, 2026
Marketplace operators integrate MoltCops to scan all submitted skills before listing, ensuring no malicious code reaches users. This prevents incidents like ClawHavoc's 341 malicious skills, building trust and reducing support costs.
Companies use MoltCops to vet third-party or internal AI skills before deployment in production environments. It detects threats like data exfiltration or prompt injection, safeguarding sensitive data and maintaining compliance with security policies.
Individual developers and teams run MoltCops locally as part of their CI/CD pipeline to scan skills from sources like GitHub. This catches behavioral threats early, such as code injection or hardcoded secrets, before integration into projects.
Academic institutions use MoltCops to analyze AI skills in research settings, ensuring experimental code does not contain hidden threats like autonomy abuse or financial drain patterns. It provides a safe environment for testing new AI behaviors.
Open source communities adopt MoltCops to review contributions for security risks before merging. It helps maintainers detect issues like lateral movement or persistence mechanisms, protecting the ecosystem from supply chain attacks.
Offer a free local scanner for basic use, with premium features like advanced threat intelligence, team collaboration tools, or integration APIs for enterprises. Revenue comes from subscriptions for enhanced capabilities and support.
Sell licenses to large organizations for on-premise deployment or cloud-based scanning services, including custom rule sets and dedicated support. This model targets companies with strict security requirements and compliance needs.
Partner with AI skill marketplaces to provide scanning as a service, charging per scan or through revenue-sharing agreements. This leverages the tool's detection capabilities to enhance platform security and user confidence.
💬 Integration Tip
Integrate MoltCops into your workflow by adding the scan command to pre-install scripts or CI/CD pipelines; use the web scanner for quick checks without local setup.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...