skill-guard-actorScan ClawHub skills for prompt injection and malicious content using Lakera Guard before installing them. Run automatically when the user asks to install a s...
Install via ClawdBot CLI:
clawdbot install 0xmerkle/skill-guard-actorGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://api.apify.com/v2/acts/TMjFBNFqIIUfCBf6K/runsCalls external URL not in known-safe list
https://apify.com/numerous_hierarchy/skill-guard-actorAI Analysis
The external API calls are documented and necessary for the skill's stated purpose of scanning skills via Lakera Guard and Apify. There is no evidence of hidden instructions, credential harvesting, or obfuscation. The risk is low as the data flow is to the user's own configured services for security analysis.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Large organizations using OpenClaw for internal automation need to ensure third-party skills are vetted for security risks before deployment. SkillGuard automates scanning for prompt injection and malicious content, enabling safe integration of external skills while maintaining compliance with internal security policies.
Freelancers or small teams developing and sharing skills on ClawHub can use SkillGuard to audit their own or others' skills for vulnerabilities. This helps build trust in the marketplace by providing automated safety checks before installation, reducing the risk of deploying harmful code.
Educational institutions integrating AI skills into learning platforms use SkillGuard to scan skills for inappropriate or unsafe content. This ensures that tools used by students and educators are free from prompt injection attacks and malicious instructions, safeguarding the learning environment.
Startups leveraging OpenClaw for rapid prototyping and automation need to quickly install third-party skills without compromising security. SkillGuard provides on-demand scanning to verify safety, allowing teams to adopt new functionalities while minimizing risks from untrusted sources.
Companies in regulated sectors like finance or healthcare use SkillGuard to audit installed skills for compliance with data protection and security standards. The tool scans for malicious content and prompt injection, helping meet regulatory requirements for AI tool usage.
Offer SkillGuard as a subscription-based service with tiered pricing based on scan volume (e.g., free tier for limited scans, paid tiers for higher usage). Revenue is generated from monthly or annual subscriptions, targeting enterprises and developers who need continuous security monitoring.
Charge users per skill scan, with pricing based on the complexity or number of skills analyzed. This model appeals to occasional users or small teams who don't require frequent scans, generating revenue from transactional usage without long-term commitments.
Sell annual enterprise licenses that include custom integrations, priority support, and bulk scanning capabilities. Revenue comes from high-value contracts with large organizations needing dedicated security solutions for their OpenClaw deployments.
💬 Integration Tip
Ensure all required environment variables (APIFY_TOKEN, LAKERA_API_KEY, etc.) are properly set up before use, and test the webhook configuration to avoid delays in receiving scan results.
Scored Jun 17, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.