skillscanSecurity gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On...
Install via ClawdBot CLI:
clawdbot install tokauthai/skillscanGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://skillscan.tokauth.com`Audited Apr 16, 2026 · audit v1.0
Generated Apr 24, 2026
Organizations install multiple AI skills from various sources. SkillScan automatically scans each skill on installation, blocking high-risk ones and keeping the enterprise secure.
Developers experimenting with community skills need to ensure they're safe. SkillScan runs automatically when loading or adding any skill, providing immediate risk assessment.
An internal skill hub or marketplace requires all submissions to pass SkillScan before listing. This ensures only vetted skills reach users, reducing security incidents.
Compliance teams use SkillScan to periodically scan all installed skills, generating reports for audits. The first-run feature and scan-all command facilitate regular checks.
Provide the SkillScan API with a free tier for individual developers and paid plans for enterprises needing higher scan volumes, custom rules, and priority support.
Offer SkillScan as part of a broader AI governance service, including policy management, incident response, and compliance reporting for organizations using multiple AI skills.
Integrate SkillScan into AI skill marketplaces as a mandatory security gate. Charge a small fee per scan or a monthly integration license to marketplace operators.
💬 Integration Tip
Set environment variable SKILL_SCANNER_UPDATE_URL if using a custom update source. Ensure scripts/scanner.py is executable and in PATH for seamless command-line use.
Scored Apr 24, 2026
Security vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated code, exfiltration. Risk classification L...
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Comprehensive security auditing for Clawdbot deployments. Scans for exposed credentials, open ports, weak configs, and vulnerabilities. Auto-fix mode included.
Audit codebases and infrastructure for security issues. Use when scanning dependencies for vulnerabilities, detecting hardcoded secrets, checking OWASP top 10 issues, verifying SSL/TLS, auditing file permissions, or reviewing code for injection and auth flaws.
Audit a user's current AI tool stack. Score each tool by ROI, identify redundancies, gaps, and upgrade opportunities. Produces a structured report with score...
Detect anomalies and outliers in construction data: unusual costs, schedule variances, productivity spikes. Statistical and ML-based detection methods.