skill-guardScan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads, hardcoded secrets, and other threats. Wraps clawhub install with mcp-scan pre-flight checks.
Install via ClawdBot CLI:
clawdbot install jamesouttake/skill-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"IGNORE PREVIOUS INSTRUCTIONS"Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://github.com/invariantlabs-ai/mcp-scanAI Analysis
This skill is a security scanner designed to protect users by analyzing other skills before installation. It uses the legitimate, publicly documented mcp-scan tool from Invariant Labs/Snyk for analysis. The flagged signals are examples of what it detects in malicious skills, not behaviors of the scanner itself.
Generated Mar 1, 2026
Large organizations deploying AI agents across departments use skill-guard to vet third-party skills before installation, ensuring no hidden prompt injections or data exfiltration risks compromise sensitive corporate data. This prevents unauthorized access to internal systems and maintains compliance with security policies.
Software development teams integrate skill-guard into their CI/CD pipelines to automatically scan new or updated ClawHub skills during testing phases. This catches AI-specific threats like malicious code patterns before deployment, reducing the risk of supply chain attacks in production environments.
Academic institutions and researchers use skill-guard to safely experiment with diverse ClawHub skills for AI agent projects, blocking installations that contain hardcoded secrets or toxic flows. This protects student data and research integrity from potential breaches or manipulation.
Independent consultants and small agencies leverage skill-guard to securely install skills for client projects, verifying content for prompt injections and hidden instructions to prevent agent compromise. This builds trust with clients by ensuring reliable and safe AI functionality.
Open source contributors and maintainers use skill-guard to review community-submitted skills for security vulnerabilities before integration into shared repositories. This helps maintain project safety by catching threats like malware payloads early in the contribution process.
Offer a free basic version of skill-guard for individual users with limited scans, and a paid tier for enterprises with advanced features like batch scanning, detailed reporting, and priority support. Revenue comes from subscription fees and custom integration services.
License skill-guard to large corporations as part of their AI security suite, providing volume discounts and dedicated support. Revenue is generated through annual licensing contracts and optional training or consulting packages for deployment.
Partner with ClawHub and other AI platform providers to bundle skill-guard as a default security feature, earning revenue through referral fees or revenue-sharing agreements. This model leverages existing user bases to drive adoption and monetization.
💬 Integration Tip
Integrate skill-guard into your existing workflow by replacing direct clawhub install commands with the safe-install script, and set up automated scans in development environments to catch threats early.
Scored Apr 19, 2026
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.