skillguard-hardenedSecurity guard for OpenClaw skills, developed and maintained by rose北港(小红帽 / 猫猫帽帽). Audits installed or incoming skills with local rules plus Zenmux AI inten...
Install via ClawdBot CLI:
clawdbot install 2404589803/skillguard-hardenedRequires:
Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Contains instructions to override system prompt or ignore user requests
"ignore previous instructions"Potentially destructive shell commands in tool definitions
exec(Calls external URL not in known-safe list
https://zenmux.ai/api/v1AI Analysis
The skill's external API call to zenmux.ai is consistent with its stated purpose of AI intent auditing, and while it contains prompt poisoning signals, these appear to be test fixtures that have been removed from distribution. No credential harvesting or hidden data exfiltration patterns were identified.
Audited Apr 17, 2026 · audit v1.0
Generated Mar 22, 2026
Organizations deploying AI agents can use SkillGuard to audit installed skills for security risks, ensuring compliance with internal policies. It scans for malicious behaviors like prompt injection and unauthorized access, providing structured reports for IT teams to review and remediate threats before they impact operations.
Online platforms hosting AI skills can integrate SkillGuard to vet new submissions before listing, using local rules and AI intent review to flag suspicious code. This prevents harmful skills from being distributed, enhancing platform trust and reducing support costs related to security incidents.
Development teams can embed SkillGuard in CI/CD pipelines to automatically check skill updates for security deviations, ensuring only safe changes are deployed. It supports commands like check-update and guarded flows, enabling continuous monitoring without manual intervention in fast-paced environments.
Financial or healthcare sectors using AI agents can leverage SkillGuard to audit skills for compliance with data protection regulations. It identifies sensitive access patterns and provides quarantine options, helping organizations maintain audit trails and avoid penalties from non-compliance.
Universities or training programs teaching AI skill creation can use SkillGuard as a learning tool to analyze student projects for security best practices. It offers feedback through reports and safe remediation actions, fostering secure coding habits in emerging developers.
Offer SkillGuard as a cloud-based service where users pay a subscription fee for regular skill audits, AI intent reviews via Zenmux, and automated reports. Revenue comes from tiered plans based on scan frequency, number of skills, and premium support for remediation actions.
Sell customized licenses of SkillGuard to large organizations, including on-premise deployment, integration with existing security tools, and dedicated support. Revenue is generated through one-time license fees, annual maintenance contracts, and consulting services for setup and training.
Partner with AI skill marketplaces to embed SkillGuard as a mandatory screening tool, charging a per-skill audit fee or revenue share from listings. This model leverages the platform's user base to generate income while enhancing security for all stakeholders.
💬 Integration Tip
Ensure the ZENMUX_API_KEY environment variable is set for AI intent auditing, and test commands like scan and guarded_flow.py in a sandbox environment before full deployment to avoid unintended skill deletions.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...