skill-secure-checkerAutomatically scans Python skill code to detect security risks like malicious patterns, hardcoded secrets, dangerous functions, and integrates VirusTotal sca...
Install via ClawdBot CLI:
clawdbot install utopiabenben/skill-secure-checkerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdHardcoded API key or token pattern found in skill definition
sk-123456789...Potentially destructive shell commands in tool definitions
rm -rf /Calls external URL not in known-safe list
https://img.shields.io/badge/status-in%20development-yellowGenerated Apr 17, 2026
Automatically scans AI skill packages before publication on platforms like ClawHub to detect security vulnerabilities such as hardcoded secrets or dangerous functions. Ensures only safe, compliant skills are released to users, reducing risk of data breaches or malicious code.
Integrates into CI/CD pipelines to scan code repositories during development and deployment phases. Provides automated security checks for AI agents, enabling teams to catch issues early and maintain secure coding practices across projects.
Used by organizations to audit internal AI agent skills for compliance with security policies and regulatory standards. Helps identify risks like unauthorized network operations or insecure file handling in custom-built AI tools.
Serves as a teaching aid in coding bootcamps or university courses to demonstrate security best practices in AI agent development. Students learn to identify and mitigate common vulnerabilities through hands-on scanning of their projects.
Enables companies to evaluate security of AI skills sourced from external vendors before integration into their systems. Scans for risks like hidden backdoors or data leakage, supporting due diligence in procurement processes.
Offers basic scanning for free to attract users, with premium features like advanced VirusTotal integration, priority support, and detailed analytics available via subscription. Generates recurring revenue from enterprises and power users.
Sells enterprise licenses that include custom rule sets, on-premises deployment, and integration with internal security tools. Targets large organizations needing tailored solutions for compliance and scalable security management.
Partners with AI skill marketplaces like ClawHub to offer scanning as a built-in service, taking a percentage of transaction fees from skills that pass security checks. Encourages adoption by aligning with platform ecosystems.
💬 Integration Tip
Set up as a pre-publish hook in ClawHub to automate scans before skill releases, ensuring consistent security checks without manual intervention.
Scored Jul 2, 2026
AI Analysis
The skill is a security auditing tool designed to scan other skills for vulnerabilities; its documented functionality (static analysis, secret detection, VirusTotal integration) aligns with its stated purpose. The rule-based signals found (like hardcoded API key examples and shell commands) appear to be illustrative code snippets within the skill's documentation, not actual malicious behavior. No evidence suggests hidden data exfiltration, credential harvesting, or user intent override.
Audited Apr 18, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...