openclaw-safe-guard提供对已安装 Skills 的静态安全扫描,检测权限风险、恶意代码和依赖风险并生成中文风险评估报告。
Install via ClawdBot CLI:
clawdbot install ansengu11/openclaw-safe-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
exec(Calls external URL not in known-safe list
https://github.com/ansengu11/openclaw-safe-guardUses known external API (expected, informational)
api.github.comAI Analysis
This skill is a security scanner designed to audit other OpenClaw skills, and its external API calls (GitHub API) are consistent with its stated purpose of fetching skill metadata. While it requires broad filesystem access to read other skills' directories, this is necessary for its scanning function and is transparently documented. No evidence of credential harvesting, data exfiltration, or hidden malicious behavior was found.
Generated Mar 20, 2026
This skill is used by developers or administrators of OpenClaw-based platforms to perform static security scans on installed or third-party skills. It helps identify permission risks, malicious code, and dependency vulnerabilities in AI agent skill packages, ensuring platform integrity and user safety.
Organizations deploying AI agents for business automation use this skill to audit custom or external skills before integration. It scans for security flaws like shell execution risks or sensitive data exposure, supporting compliance and risk management in corporate environments.
Universities or research labs utilizing OpenClaw for AI experiments employ this skill to validate the safety of experimental skills. It provides automated vulnerability detection and Chinese-language reports, aiding in secure prototyping and academic integrity.
Marketplaces hosting OpenClaw skills use this tool to screen submissions for security issues before listing. It checks for malware, permission overreach, and dependency risks, enhancing trust and reducing liability for platform operators.
Teams integrate this skill into continuous integration workflows to automatically scan new or updated skill code. It flags security risks early in development, supporting secure deployment practices and reducing manual audit overhead.
Offer a basic version for free with core scanning features, then charge for advanced capabilities like detailed reporting, API access, or priority support. This attracts individual developers while monetizing enterprise users needing enhanced security.
License the skill to companies for internal use, providing customization, integration support, and regular updates. Target businesses with large AI deployments that require ongoing security monitoring and compliance assistance.
Collaborate with AI skill marketplaces to offer scanning as a value-added service. Charge per scan or take a commission on transactions, helping platforms ensure safety and build user confidence in listed skills.
💬 Integration Tip
Ensure all required system tools (curl, jq, git, grep, find) are installed and test in an isolated environment first to avoid exposing sensitive data from other skills.
Scored Apr 19, 2026
Audited Apr 16, 2026 · audit v1.0
Use the ClawdHub CLI to search, install, update, and publish agent skills from clawdhub.com. Use when you need to fetch new skills on the fly, sync installed skills to latest or a specific version, or publish new/updated skill folders with the npm-installed clawdhub CLI.
Mission control dashboard for OpenClaw - real-time session monitoring, LLM usage tracking, cost intelligence, and system vitals. View all your AI agents in o...
Transcribe YouTube videos to text by extracting captions and subtitles directly from the video URL using yt-dlp without audio processing.
Manage a self-hosted Trello-like board via `wekancli`. Create, move and archive cards, lists and boards on a WeKan server. Use when user asks about task boar...
Proactive security monitoring, threat scanning, and auto-remediation for OpenClaw deployments
Create or improve SOUL.md files for OpenClaw agents through guided conversation. Use when designing agent personality, crafting a soul, or saying "help me create a soul". Supports self-improvement.