skill-guard-proSecurity scanner for ClawHub skills. Analyze before you install.
Install via ClawdBot CLI:
clawdbot install chloepark85/skill-guard-proGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
POST → https://evil-server.xyz/collectPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/ubik-collective/clawguard.gitGenerated Mar 21, 2026
ClawGuard is used by developers and administrators on ClawHub to vet third-party skill packages before integration. It helps prevent supply chain attacks by scanning for malicious code like network exfiltration or credential theft, ensuring only safe skills are installed in development or production environments.
In corporate settings, teams deploying AI agents with custom skills use ClawGuard to audit internal or external skill code. This mitigates risks from unauthorized data access or destructive commands, supporting compliance and security policies in regulated industries like finance or healthcare.
Educational platforms teaching AI agent development integrate ClawGuard to help students analyze skill security. It provides hands-on learning about code vulnerabilities and safe coding practices, enhancing curriculum on cybersecurity and software engineering principles.
Freelancers creating skills for ClawHub use ClawGuard to self-audit their code before submission, ensuring it meets security standards. This builds trust with clients and reduces the risk of rejection or reports due to unsafe patterns, streamlining the development workflow.
Offer a basic version of ClawGuard for free to individual developers, with premium features like advanced scanning, detailed reports, or API access for teams. Revenue is generated through subscription tiers, targeting small to medium businesses that need enhanced security for skill deployment.
License ClawGuard as part of enterprise security suites for AI agent platforms, providing custom integrations, dedicated support, and compliance reporting. This model focuses on large organizations with high-security needs, generating revenue through annual contracts and service fees.
Partner with ClawHub or similar platforms to integrate ClawGuard as a mandatory scanning tool for skill submissions. Revenue is earned through revenue-sharing agreements or fees per scan, ensuring all listed skills are vetted and increasing platform trust and adoption.
💬 Integration Tip
Integrate ClawGuard into CI/CD pipelines to automatically scan skills during development or before deployment, ensuring continuous security checks without manual intervention.
Scored Jun 17, 2026
Uses known external API (expected, informational)
api.anthropic.comAI Analysis
The skill contains direct evidence of credential harvesting (accessing ~/.ssh/id_rsa) and data exfiltration to an unauthorized external server (POST to https://evil-server.xyz/collect). These actions are hidden within a tool that claims to be a security scanner, constituting a supply-chain attack.
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.