neckr0ik-security-scannerSecurity audit tool for OpenClaw skills. Scans skill directories for common vulnerabilities including hardcoded secrets, unsafe shell commands, prompt inject...
Install via ClawdBot CLI:
clawdbot install neckr0ik/neckr0ik-security-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://owasp.org/www-community/vulnerabilities/Hardcoded_passwordUses known external API (expected, informational)
api.anthropic.comAI Analysis
The skill is a security scanner designed to audit other skills, and its external calls (e.g., to OWASP for vulnerability references and Anthropic's API for AI processing) appear consistent with its stated purpose. The flagged 'unsafe shell' evidence is from example patterns in its own documentation, not actual malicious code execution.
Generated Mar 20, 2026
ClawHub administrators use the scanner to automatically audit all skill submissions before publication, ensuring no vulnerabilities like hardcoded secrets or unauthorized network calls are present. This prevents malicious or insecure skills from being distributed to users, maintaining platform integrity and user trust.
Development teams in regulated industries like finance or healthcare integrate the scanner into their CI/CD pipelines to validate custom OpenClaw skills against internal security policies. It detects critical issues such as shell injection and code execution risks, helping meet compliance standards like GDPR or HIPAA for AI-driven applications.
Open source contributors run the scanner on their skill code before submitting pull requests to public repositories, identifying and fixing medium-level issues like outdated dependencies or unpinned versions. This fosters a secure ecosystem by encouraging best practices and reducing vulnerabilities in community-shared skills.
Instructors in cybersecurity or AI courses use the scanner as a hands-on tool to teach students about common vulnerabilities in AI agent skills, such as prompt injection and file path traversal. Students audit sample skills to learn remediation techniques, building practical security awareness for future developers.
Organizations procuring third-party OpenClaw skills from vendors run the scanner to independently verify security before deployment, checking for high-risk issues like excessive permissions or unauthorized network access. This due diligence minimizes operational risks and ensures vendor skills align with organizational security requirements.
Offer a free version for basic scanning of individual skills, with premium tiers providing advanced features like batch audits, detailed reports, and CI/CD integration. Revenue is generated through subscription fees from enterprises needing comprehensive security oversight for their skill portfolios.
Partner with OpenClaw's ClawHub marketplace to provide mandatory security scanning as part of the skill publication process, charging a fee per scan or taking a commission on published skills. This ensures all listed skills are vetted, enhancing marketplace credibility and user safety.
Provide specialized security consulting services where experts use the scanner to conduct in-depth audits for high-stakes clients, offering tailored remediation advice and compliance support. Revenue comes from project-based fees for audits, training, and ongoing security monitoring.
💬 Integration Tip
Integrate the scanner into your CI/CD pipeline using the provided exit codes to automatically block deployments with critical issues, ensuring security is enforced early in the development cycle.
Scored Apr 19, 2026
Audited Apr 16, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...