skill-security-scan-dxxScan installed OpenClaw skills for potential security risks. Use when you want to check if skills contain dangerous commands, access sensitive paths, or have...
Install via ClawdBot CLI:
clawdbot install ntaffffff/skill-security-scan-dxxGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/hostsAI Analysis
This skill is a security scanning tool designed to detect risks in other skills; its own code is not provided for analysis, but the description and signals found are the *targets* of its scan, not its own behaviors. No evidence suggests it exfiltrates data, overrides user intent, or contains hidden malicious instructions.
Audited Apr 16, 2026 · audit v1.0
Generated May 13, 2026
Integrate the scanner into a CI/CD pipeline to automatically scan new or updated skills before deployment. This ensures only secure skills are promoted to production, reducing the risk of supply chain attacks.
Security teams in large organizations use the scanner to enforce policy compliance across all installed skills. Generate monthly risk reports for audits and ensure only approved skills are used.
Marketplace operators run the scanner on submitted skills to flag dangerous commands or access patterns before listing. This builds trust and protects end-users from malicious skills.
Security trainers use the scanner as a demo tool to show how common malicious patterns (e.g., rm -rf /, fork bombs) are detected. Helps developers understand secure coding practices.
Individual developers periodically scan their local skill installations to identify hidden risks. Provides peace of mind when using third-party skills from various sources.
Offer a basic scan for free (e.g., 3 skills per month) and charge for unlimited scans, custom risk rules, and premium reporting features.
Wrap the scanner as a REST API and charge per scan or monthly subscription. Integrates into CI/CD pipelines, marketplaces, or governance tools.
Provide expert security audits of skill ecosystems using the scanner as a tool. Offer remediation recommendations and custom policy development.
💬 Integration Tip
Run the scanner via cron or CI/CD hook daily. For real-time protection, integrate with policy engines to block installation of risky skills.
Scored May 13, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...