scan-skillDeep security analysis of an individual skill before installation
Install via ClawdBot CLI:
clawdbot install itsnishi/scan-skillGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdPotentially destructive shell commands in tool definitions
eval(Audited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Large organizations can integrate this skill into their AI agent deployment pipeline to automatically scan third-party skills before installation. This ensures compliance with internal security policies and prevents malicious code from entering production environments, reducing risk of data breaches or system compromise.
Marketplaces hosting AI agent skills can use this scanner to vet submissions from contributors, providing a security badge for verified skills. This builds trust with users, encourages safe skill adoption, and helps maintain platform integrity by filtering out potentially harmful content.
Individual developers or small teams creating custom skills can run this tool locally to self-audit their work before sharing or deploying. It helps identify unintentional security vulnerabilities, such as improper tool permissions or hidden code patterns, improving overall skill quality and safety.
Healthcare providers using AI agents for tasks like patient data analysis can employ this skill to ensure any added skills meet strict regulatory standards (e.g., HIPAA). Scanning for injection techniques and unauthorized tools helps maintain data privacy and avoid compliance violations.
Offer this scanning tool as a cloud-based service with monthly or annual subscriptions. Provide detailed reports, API access for integration, and regular updates for new threat detection. Revenue comes from tiered pricing based on scan volume or enterprise features.
Release a free basic version for individual users, with advanced features like batch scanning, historical analysis, and priority support available in paid tiers. Monetize through upgrades, targeting businesses and developers who need more comprehensive security insights.
Provide custom integration of the scanner into clients' existing AI agent workflows, along with consulting for security best practices. Revenue is generated from project-based fees, ongoing support contracts, and training sessions for teams adopting the tool.
💬 Integration Tip
Integrate this skill into automated CI/CD pipelines to scan skills during development and before deployment, ensuring continuous security monitoring without manual intervention.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...