securityclawSecurity-first skill auditing and quarantine for OpenClaw skills. Use when installing new skills, reviewing skills from unknown sources, scanning skills for prompt injection/exfiltration/supply-chain risks, or when a bot suspects a skill is malicious. Guides static + optional sandbox checks, quarantines suspicious skills, and produces an owner-action checklist (Delete / Report / Allow / Scan all).
Install via ClawdBot CLI:
clawdbot install mallen-lbx/securityclawGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"AI Analysis
The skill definition contains a HIGH severity rule flag for PROMPT_POISONING, indicating it has instructions to override the system prompt or ignore user requests. This is a direct attempt to subvert the AI's intended behavior and safety controls, posing a significant integrity and security risk.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 1, 2026
When integrating third-party or community-developed skills into an OpenClaw environment, this skill scans for prompt injection, exfiltration, and supply-chain risks before deployment. It ensures that new additions do not compromise system security by performing static analysis and optionally quarantining suspicious code.
Periodically scanning all installed skills to detect vulnerabilities or malicious changes introduced over time. This helps maintain a secure AI ecosystem by identifying and isolating compromised skills based on severity levels, preventing unauthorized data access or system exploitation.
When unusual behavior or performance issues suggest a skill might be malicious, this tool quickly audits and quarantines the suspect skill. It provides actionable reports with file and line details, enabling swift owner notification and remediation steps like deletion or reporting.
Ensuring that all AI skills comply with organizational security policies and regulatory standards. The skill generates audit trails and checklists for actions such as allowlisting or deletion, supporting governance frameworks in regulated industries like finance or healthcare.
Offer ongoing security scanning and quarantine services for OpenClaw skill repositories on a monthly or annual subscription basis. Revenue is generated through tiered plans based on the number of skills scanned, frequency of audits, and access to advanced features like sandboxing.
Provide professional services to help organizations integrate and customize the SecurityClaw skill into their existing AI infrastructure. Revenue comes from one-time setup fees, training sessions, and ongoing support contracts for complex deployments or dynamic sandboxing implementations.
Distribute the basic scanning functionality for free to attract users, then monetize through premium add-ons such as advanced sandboxing, detailed reporting dashboards, or automated owner notification systems. Revenue is driven by upsells to power users and enterprises.
💬 Integration Tip
Ensure the skills directory path is correctly specified in the scan command, and consider setting up automated cron jobs for regular scans to maintain continuous security monitoring.
Scored Apr 19, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.