skill-safety-checkerRuns VirusTotal-style security checks on OpenClaw/Cursor skills before install, including remote code execution (RCE) and malicious code (obfuscation, exfilt...
Install via ClawdBot CLI:
clawdbot install RuneweaverStudios/skill-safety-checkerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
curl … | sh`, `wget … -O - | bashCalls external URL not in known-safe list
https://gogcli.shAudited Apr 18, 2026 · audit v1.0
Generated Mar 21, 2026
Developers and organizations using platforms like ClawHub to share AI skills need to ensure third-party contributions are safe before integration. This skill automates security checks for RCE, malicious code, and credential mismatches, preventing vulnerabilities in distributed ecosystems.
Companies deploying AI agents with custom skills must vet each skill for security compliance to protect sensitive data and systems. This skill provides a standardized process to evaluate skills for risks like data exfiltration or unauthorized access before granting API credentials.
Educational institutions adopting AI skills for teaching or research require safety assurances to prevent malware or unethical code execution. This skill helps instructors and students verify skills from public registries, ensuring they align with educational goals and security policies.
Freelancers creating AI skills for clients use this tool to self-audit their work, achieving a Benign rating before delivery. It addresses client concerns about safety by checking for issues like obfuscation or credential requirements, enhancing trust and marketability.
Financial technology firms integrating AI skills for automation must adhere to strict regulatory standards. This skill assesses skills for malicious code and RCE risks, helping teams maintain compliance and reduce operational threats in sensitive financial environments.
Offer a free basic version for individual users to check skills, with premium features like batch scanning, detailed reports, and API access for enterprises. Revenue comes from subscription plans tailored to teams and large organizations needing continuous monitoring.
Sell licenses to corporations for integrating the skill checker into their internal AI development pipelines. This includes custom integrations, support services, and regular updates to address emerging threats, ensuring compliance and security at scale.
Partner with AI skill registries like ClawHub to embed the checker as a mandatory pre-installation step. Revenue is generated through revenue-sharing agreements or fees per scan, enhancing platform safety and user trust while driving adoption.
💬 Integration Tip
Integrate this skill into automated workflows, such as CI/CD pipelines, to scan new skills upon download or before deployment, ensuring consistent safety checks without manual intervention.
Scored Apr 19, 2026
Connect to 100+ APIs (Google Workspace, Microsoft 365, GitHub, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth. Use this skill when users want to...
Fetch and read transcripts from YouTube videos. Use when you need to summarize a video, answer questions about its content, or extract information from it.
Skill 查找器 | Skill Finder. 帮助发现和安装 ClawHub Skills | Discover and install ClawHub Skills. 回答'有什么技能可以X'、'找一个技能' | Answers 'what skill can X', 'find a skill'. 触发...
Query, design, migrate, and optimize SQL databases. Use when working with SQLite, PostgreSQL, or MySQL — schema design, writing queries, creating migrations, indexing, backup/restore, and debugging slow queries. No ORMs required.
Extract text from PDFs with OCR support. Perfect for digitizing documents, processing invoices, or analyzing content. Zero dependencies required.
Complete toolkit for programmatic video creation with Remotion + React. Covers animations, timing, rendering (CLI/Node.js/Lambda/Cloud Run), captions, 3D, charts, text effects, transitions, and media handling. Use when writing Remotion code, building video generation pipelines, or creating data-driven video templates.