raini-skill-auditScans installed or remote OpenClaw skills for security risks like credential leaks and suspicious code to prevent supply chain attacks.
Install via ClawdBot CLI:
clawdbot install 0xRaini/raini-skill-auditGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
process.env.API_KEYPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://owasp.org/www-project-top-10-for-large-language-model-applications/Uses known external API (expected, informational)
api.anthropic.comGenerated Mar 1, 2026
Large organizations deploying AI agents across departments use Skill Audit to vet third-party skills before installation. This prevents supply chain attacks where malicious code could steal credentials or exfiltrate sensitive data through seemingly harmless productivity tools.
Individual developers and small teams use this tool to scan locally developed skills or community-shared packages before integrating them into their OpenClaw environment. It helps identify risky patterns like eval() usage or unauthorized network calls that could compromise their development machines.
Companies in regulated industries use Skill Audit to generate security reports for internal compliance teams or external auditors. The structured risk scoring and findings documentation helps demonstrate due diligence in managing AI agent security risks.
Skill marketplace operators integrate Skill Audit into their submission pipelines to automatically flag potentially dangerous skills before they're published. This maintains platform trust by preventing malicious code from reaching end users while educating developers about secure coding practices.
Organizations with mature DevOps practices incorporate Skill Audit into their CI/CD pipelines to automatically scan skills during development and deployment phases. This shifts security left by catching vulnerabilities early, reducing remediation costs and preventing production incidents.
Sell annual enterprise licenses with features like centralized reporting, API access for integration into existing security tools, and priority support. This targets large organizations needing to secure multiple teams and environments with compliance requirements.
Offer a free tier for individual developers scanning local skills, with paid tiers for teams needing collaboration features, historical reports, and advanced scanning rules. The SaaS model provides recurring revenue with low customer acquisition costs through the developer community.
Partner with skill marketplaces to provide scanning as a value-added service, taking a percentage of transactions or charging marketplace operators for quality assurance. This leverages existing platforms' user bases while enhancing their security posture and user trust.
💬 Integration Tip
Integrate Skill Audit into your skill installation workflow using its CLI interface, and consider automating scans in CI/CD pipelines to catch security issues before deployment.
Scored Apr 19, 2026
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou...
Safe command execution for OpenClaw Agents with automatic danger pattern detection, risk assessment, user approval workflow, and audit logging. Use when agen...
Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets, and other threats. Wraps clawhub install with mcp-scan pre-flight checks.