security-skill-scannerScans OpenClaw skills for security vulnerabilities and suspicious patterns before installation
Install via ClawdBot CLI:
clawdbot install anikrahman0/security-skill-scannerGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdSends data to undocumented external endpoint (potential exfiltration)
POST → http://data-collector.xyz/logContains telemetry, tracking, or analytics calls not mentioned in documentation
Telemetry**: Doesn't sendPotentially destructive shell commands in tool definitions
eval(Generated Mar 1, 2026
AI agent platforms can integrate this scanner to automatically vet third-party skills submitted by developers before listing them in marketplaces. This ensures all available skills meet basic security standards, reducing the risk of malicious skills harming end-users' systems or data. It acts as a first-line defense in the skill approval workflow.
Large organizations deploying internal AI assistants can use this scanner to review custom-built skills for security compliance. IT security teams can scan skills for suspicious patterns like unauthorized data exfiltration or unsafe system commands before allowing installation on corporate devices. This helps enforce security policies in AI-driven automation.
Open-source developers creating skills for community platforms can run this scanner during development to self-audit their code for accidental security issues, such as hardcoded credentials or unsafe API calls. It serves as a quality assurance tool to build trust and encourage adoption by flagging potential risks early in the development cycle.
Educational institutions teaching AI agent development can incorporate this scanner into curricula to demonstrate security best practices. Students learn to identify and avoid malicious patterns in skill instructions, fostering awareness of AI safety principles. It provides hands-on experience with real-world security analysis tools.
Freelance security consultants can offer skill auditing services to clients who need independent verification of AI agent skills. Using this scanner, they can generate detailed risk reports for skills sourced from third parties, helping businesses make informed decisions about installation and reducing liability from security breaches.
Offer a free basic version of the scanner for individual users, with premium features like batch scanning, advanced pattern detection, and integration APIs for enterprises. Revenue comes from subscription fees for teams and organizations needing enhanced security workflows and support. This model encourages widespread adoption while monetizing advanced needs.
Partner with AI agent platform providers to embed the scanner as a core security service, charging licensing fees based on usage volume or number of scans. Revenue is generated through B2B contracts that include customization, maintenance, and regular updates to threat detection patterns. This leverages the growing demand for integrated security in AI ecosystems.
Provide bespoke consulting services to businesses that require tailored security scanning solutions, such as custom whitelists, industry-specific pattern detection, or integration with existing security tools. Revenue comes from project-based fees and ongoing support contracts, targeting organizations with unique compliance or operational requirements.
💬 Integration Tip
Integrate the scanner into CI/CD pipelines for skill development to automate security checks before deployment, ensuring consistent safety reviews.
Scored Apr 22, 2026
Calls external URL not in known-safe list
https://github.com/anikrahman0/security-skill-scanner.gitUses known external API (expected, informational)
api.anthropic.comAI Analysis
The skill is a legitimate security scanner tool that analyzes other skills for vulnerabilities. The external API calls are to expected services like GitHub and AI providers for its functionality. The 'data-collector.xyz' endpoint appears to be example evidence in the scanner's detection output, not actual behavior of the scanner itself.
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.