openclaw-skill-toolsGenerate and security-scan OpenClaw SKILL.md files. Use when creating new OpenClaw skills, scanning skills for security vulnerabilities like prompt injection...
Install via ClawdBot CLI:
clawdbot install krishnakumarmahadevan-cmd/openclaw-skill-toolsGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://portal.toolweb.in/apis/tools/openclawCalls external URL not in known-safe list
https://portal.toolweb.inAI Analysis
The skill's external API call is explicitly documented as its core functionality for generating and scanning skills, which aligns with its stated purpose. While it sends data to an external endpoint, this is a declared feature, not a hidden exfiltration mechanism, and no credential harvesting or obfuscation is present.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 21, 2026
A company building custom AI agents for clients uses this skill to generate standardized SKILL.md files for each new agent's capabilities, ensuring consistent documentation. They also scan third-party skills from ClawHub before integrating them to prevent security vulnerabilities like prompt injection in their multi-agent systems.
A large organization's security team audits all OpenClaw skills deployed internally, using the scanner to check for data exfiltration or credential theft risks. They enforce policies by scanning skills before installation on employee devices, especially in regulated industries like finance or healthcare.
A maintainer of a public ClawHub repository uses this tool to vet community-submitted skills for malicious code like permission abuse before publishing. They generate SKILL.md files for approved skills to ensure they meet formatting standards and include proper triggers for agent activation.
A freelancer creating custom OpenClaw skills for small businesses uses the generator to quickly produce professional documentation for clients. They scan existing skills from unknown sources before recommending installations, helping clients avoid scope creep or security issues in their automation workflows.
An instructor teaching AI agent development workshops uses this skill to demonstrate secure skill creation and auditing practices. Students learn to generate SKILL.md files for their projects and scan sample skills for vulnerabilities like prompt injection, reinforcing best practices in hands-on labs.
Revenue is generated through API calls tracked for billing, where users pay per scan or generation request via their TOOLWEB_API_KEY. This model scales with usage, appealing to developers and enterprises needing frequent security audits or skill documentation.
Companies purchase annual licenses for unlimited scans and generations, integrating the tool into their CI/CD pipelines for automated skill vetting. This includes premium support, custom security checks, and compliance reporting for regulated industries.
The skill is bundled as a premium tool within ClawHub or other AI agent marketplaces, where users pay a fee to access advanced security scanning features. Revenue shares come from marketplace transactions, encouraging adoption among skill publishers and users.
💬 Integration Tip
Ensure TOOLWEB_API_KEY is set in the environment before use, and test with a simple skill scan to verify API connectivity and output formats.
Scored Apr 19, 2026
Transform AI agents from task-followers into proactive partners that anticipate needs and continuously improve. Now with WAL Protocol, Working Buffer, Autonomous Crons, and battle-tested patterns. Part of the Hal Stack 🦞
Clawdbot documentation expert with decision tree navigation, search scripts, doc fetching, version tracking, and config snippets for all Clawdbot features
Display and control HTML content on connected Mac, iOS, or Android nodes via a web-based canvas with live reload and remote actions.
Backup and restore OpenClaw data. Use when user asks to create backups, set up automatic backup schedules, restore from backup, or manage backup rotation. Handles ~/.openclaw directory archiving with proper exclusions.
Use the ClawdHub CLI to search, install, update, and publish agent skills from clawdhub.com. Use when you need to fetch new skills on the fly, sync installed skills to latest or a specific version, or publish new/updated skill folders with the npm-installed clawdhub CLI.
Coding workflow with planning, implementation, verification, and testing for clean software development.