skill-security-scanner-cleanSecurity scanner for OpenClaw skills. Use when installing, updating, or auditing skills to detect malicious backdoors, suspicious code patterns, data exfiltr...
Install via ClawdBot CLI:
clawdbot install cookiemikeliu/skill-security-scanner-cleanGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Audited Apr 16, 2026 · audit v1.0
Generated Mar 21, 2026
A company operates an internal marketplace for custom AI skills. Before any skill is published, the scanner automatically reviews each submission to detect malicious code, ensuring only safe skills are available to employees. This prevents data breaches and system compromises from untrusted skill sources.
A bank uses the scanner to audit third-party AI skills that handle sensitive financial data. It checks for unauthorized data exfiltration, credential theft risks, and suspicious network calls to comply with strict regulatory standards like GDPR and PCI-DSS, reducing legal and security liabilities.
An online learning platform integrates the scanner into its workflow to vet AI skills submitted by students or instructors. It flags dangerous code patterns like eval or system calls, allowing safe experimentation while protecting the platform's infrastructure from malware or cryptojacking attacks.
A healthcare provider deploys AI skills for patient data analysis and uses the scanner to ensure no skill contains spyware or unauthorized data access. This safeguards patient privacy under HIPAA regulations by detecting risks like environment variable access or hidden network requests before installation.
A community-driven repository for AI skills employs the scanner to automatically screen new submissions. It identifies obfuscated code, mining malware, or backdoors, providing verdicts to moderators who can approve or reject skills based on security scores, maintaining trust among users.
Offer the scanner as a cloud-based service where users upload skill packages for automated analysis. Charge a monthly fee based on scan volume, with premium tiers for advanced features like custom rule sets, detailed reporting, and API access for integration into CI/CD pipelines.
Sell on-premise licenses to large organizations that require full control over their security scanning. Provide dedicated support, customization options, and regular updates for new threat signatures, generating revenue through one-time license fees and annual maintenance contracts.
Release a basic version of the scanner for free to attract individual developers and small teams. Monetize by offering premium add-ons such as integration plugins for popular IDEs, advanced analytics dashboards, or priority scanning queues, driving conversions through value-added features.
💬 Integration Tip
Integrate the scanner into your CI/CD pipeline using the provided Python script to automatically block skill installations with critical threats, ensuring security checks are part of every deployment without manual intervention.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...