security-checkerSecurity scanner for Python skills before publishing to ClawHub. Use before publishing any skill to check for dangerous imports, hardcoded secrets, unsafe file operations, and dangerous functions like eval/exec/subprocess. Essential for maintaining trust and ensuring published skills are safe for others to install and run.
Install via ClawdBot CLI:
clawdbot install johstracke/security-checkerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Audited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Developers creating Python skills for ClawHub use this tool to scan their code before publishing, ensuring it doesn't contain dangerous imports, hardcoded secrets, or unsafe operations. This helps maintain trust and safety in the community by preventing malicious or vulnerable code from being distributed.
Open-source project maintainers integrate this scanner into their CI/CD pipelines to automatically check contributions for security risks like eval/exec usage or exposed secrets. It ensures code quality and reduces manual review effort, especially for projects with many contributors.
Instructors in coding bootcamps or university courses use this tool to teach students about common security pitfalls in Python, such as avoiding hardcoded API keys and dangerous functions. It provides practical, hands-on feedback to reinforce safe development habits.
Companies with internal skill development teams deploy this scanner to enforce security policies, ensuring all custom Python tools meet safety standards before deployment. It helps prevent data breaches and operational risks by flagging risky code patterns automatically.
Marketplace operators like ClawHub use this tool to vet submitted skills, scanning for vulnerabilities before listing them publicly. This builds user trust by ensuring all available skills are safe and reduces support issues related to malicious code.
Offer a basic version for free to attract users, with premium features like detailed reporting, integration with CI/CD tools, or advanced scanning for obfuscated code. Revenue comes from subscriptions for teams or enterprises needing enhanced security.
License the scanner to platforms like ClawHub or other AI marketplaces, where it's embedded as a mandatory pre-publish check. Revenue is generated through licensing fees based on usage volume or a flat annual rate for platform-wide integration.
Provide consulting services to organizations needing tailored security scans, such as adding custom rules for specific industries or integrating with proprietary systems. Revenue comes from project-based fees and ongoing support contracts.
💬 Integration Tip
Integrate the scanner into pre-commit hooks or CI pipelines to automate security checks, ensuring all code changes are scanned before merging or publishing.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...