skill-guard-securitySecurity auditing for OpenClaw agent skills. Scans skills for dangerous patterns, vulnerable dependencies, and suspicious behaviors before installation.
Install via ClawdBot CLI:
clawdbot install jonathanliu811026/skill-guard-securityGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → http://localhost:3402/api/auditCalls external URL not in known-safe list
http://localhost:3402/api/auditAI Analysis
The external endpoint referenced (localhost:3402) is for the skill's own local API server, not an unauthorized external service. The skill's stated purpose is security auditing, and the documented behavior aligns with this function. No evidence of credential harvesting, obfuscation, or hidden instructions overriding safety was found.
Audited Apr 17, 2026 · audit v1.0
Generated May 13, 2026
Enterprises can use SkillGuard to automatically scan any third-party agent skill before deployment, ensuring no malicious code or vulnerable dependencies are introduced into their AI infrastructure. This reduces the risk of supply chain attacks and compliance violations.
Development teams integrate SkillGuard into their CI/CD pipelines to automatically audit skills during build or deployment stages. If a skill scores 'DANGEROUS', the pipeline can fail, preventing risky skills from reaching production.
Agent skill marketplaces like ClawHub can run SkillGuard on every new submission to assign a security rating before listing. This builds trust and helps users make informed decisions.
Individuals running AI agents at home can scan skills before adding them to their personal assistant, protecting against data theft or system compromise. This is especially useful for smart home or productivity agents.
Companies evaluating skills from external vendors can use SkillGuard to generate automated security reports, accelerating vendor risk assessments and due diligence processes.
Offer free scanning for limited skills per month, while paid tiers include unlimited scans, advanced reporting, and priority support. Revenue comes from subscription fees.
Charge per API call for skill audits, targeting CI/CD platforms, marketplaces, and security tools that need to integrate scanning into their workflows.
License the SkillGuard engine to marketplace platforms or DevOps vendors who embed it into their own products. Revenue comes from licensing fees or revenue sharing.
💬 Integration Tip
Integrate via CLI for quick local scans or use the API server for automated pipeline integration. Start with `npx skillguard-audit --path ./my-skill` on your skill folder.
Scored May 13, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...