skill-scanner-guardSecurity gate for OpenClaw AgentSkills. Scans folder/ClawHub skills with cisco-ai-defense/skill-scanner before installation. Supports manual scans, staged in...
Install via ClawdBot CLI:
clawdbot install jason-allen-oneal/skill-scanner-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/cisco-ai-defense/skill-scannerAudited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
Large organizations deploying AI agents can use this skill to enforce security policies on third-party skill installations. It ensures that only vetted skills without high-risk vulnerabilities are integrated into production environments, reducing attack surfaces and maintaining compliance with internal security standards.
Platforms hosting AI agent skills, like ClawHub, can integrate this scanner to automatically screen uploaded skills for security issues before listing. This prevents malicious or vulnerable skills from being distributed, protecting end-users and maintaining trust in the marketplace ecosystem.
Teams automating AI agent deployments can embed this skill into their CI/CD pipelines to scan skills during build or deployment stages. It blocks high-risk skills from progressing to production, ensuring secure and reliable agent updates without manual intervention.
Research institutions using AI agents for experiments can employ this scanner to validate skills sourced from open repositories. It helps prevent the introduction of compromised code into sensitive research environments, safeguarding data integrity and operational continuity.
MSPs offering AI agent management services can use this skill to provide security scanning as a value-added feature. It allows them to monitor and quarantine risky skills across client deployments, enhancing service reliability and security posture for diverse customer bases.
Offer this scanner as part of a monthly subscription for continuous skill monitoring and updates. Revenue is generated through tiered plans based on scan frequency, number of skills, or integration support, appealing to businesses needing ongoing security assurance.
Sell perpetual licenses to large organizations for internal use, including customization and priority support. Revenue comes from one-time license fees plus annual maintenance contracts, targeting industries with strict regulatory requirements like finance or healthcare.
Integrate the scanner into a skill marketplace and charge a commission on each skill sale that passes security checks. Revenue is earned as a percentage of transactions, incentivizing safe skill listings and building trust among buyers and sellers.
💬 Integration Tip
Ensure the skill-scanner environment is properly set up with required binaries like uv and systemctl, and configure systemd user units for auto-scanning to automate security enforcement without manual oversight.
Scored Apr 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...