skill-hubOpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.
Install via ClawdBot CLI:
clawdbot install phenixstar/skill-hubGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://github.com/PhenixStar/openclaw-skills-collectionUses known external API (expected, informational)
raw.githubusercontent.comGenerated Mar 1, 2026
A software development team uses Skill Hub to discover and vet new AI skills for automating code reviews or DevOps tasks. They search for skills by category, assess credibility scores, and install secure tools to enhance their workflow without security risks.
An IT security department employs Skill Hub to scan all installed AI skills for malicious patterns and prompt injection vulnerabilities. They run regular vetting on categories like data handling to ensure compliance and prevent unauthorized access in corporate environments.
Educators and content creators use Skill Hub to find skills for generating educational materials or managing spreadsheets. They browse the catalog by credibility, install vetted tools, and quickly check for updates to maintain access to the latest AI capabilities.
A tech startup leverages Skill Hub to discover new AI skills for market research or customer service automation. They search with keywords, vet top unvetted skills for safety, and sync the catalog to stay updated on emerging tools for competitive advantage.
Offer Skill Hub as a free basic tool for skill discovery and vetting, with premium features like advanced security scans, priority sync, and API access for enterprise teams. Revenue comes from subscription tiers and custom integrations.
Provide consulting services where experts use Skill Hub to audit and recommend AI skills for clients in specific industries. Revenue is generated through project-based fees for security assessments, skill integration, and training workshops.
Operate a marketplace where developers can list their AI skills, with Skill Hub used for discovery and vetting. Revenue is earned through commissions on skill installations or featured listings, leveraging the tool's credibility scoring to drive trust.
💬 Integration Tip
Integrate Skill Hub into existing CI/CD pipelines to automate skill vetting during deployment, ensuring only secure tools are used in production environments.
Scored Apr 19, 2026
AI Analysis
The skill's external API usage (GitHub, raw.githubusercontent.com) is consistent with its stated purpose of skill discovery and sync from curated public repositories. While the rule-based signals flag prompt poisoning instructions and unsafe shell patterns, these appear to be examples or documentation within the skill's own scripts, not active malicious behavior targeting the user or system.
Audited Apr 16, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.