skillscan-wrapperSecurity audit tool for AI agent skills. Scans skill packages for malware, credential theft, and suspicious patterns before installation. Defensive security...
Install via ClawdBot CLI:
clawdbot install cyzlmh/skillscan-wrapperGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
upload → https://scanner.example.com/api/reportCalls external URL not in known-safe list
https://gitee.com/random_player/cmic-skill-scannerAudited Apr 21, 2026 · audit v1.0
Generated Oct 5, 2026
A security team at a large enterprise needs to approve AI agent skills for employee use. They run the scanner against every skill package before allowing installation into the corporate environment. This prevents credential theft and data exfiltration from untrusted marketplace skills.
A skill marketplace or registry wants to protect its users by scanning uploaded packages automatically. They integrate the wrapper into their CI pipeline to flag malicious patterns before a skill is published. This reduces takedowns and builds platform trust.
A solo developer installs many community skills and wants a quick local safety check. They run a single-command review on any downloaded skill package and inspect the risk rating summary. This catches suspicious patterns without needing a full security stack.
Banks and healthcare companies must prove due diligence on third-party AI tooling. The scanner produces markdown reports that feed into compliance documentation and audit trails. Optional enterprise upload sends findings to the organization's security dashboard.
When a malicious skill is suspected in production, the response team scans the affected package and related directory in batch mode. Findings help determine data exfiltration scope and affected credentials. Results are exported for forensic records.
Distribute the wrapper and native engine for free to drive adoption, then monetize the optional enterprise reporting backend and external engine bridge. Teams pay for centralized dashboards, alerting, and cross-skill analytics.
Offer a hosted scanning-as-a-service where customers upload skill packages to a controlled endpoint and receive risk reports. The wrapper's user-controlled --upload-url fits naturally as the client of this service.
Security firms use the tool as the technical backbone while selling human review, remediation guidance, and compliance certification for skill publishers and enterprises. The open license makes it easy to embed in service engagements.
💬 Integration Tip
Verify the shipped binary's SHA-256 checksum against the published value before first run, and start by scanning a known-safe skill to confirm baseline behavior. Keep --upload-url unset unless you intentionally want to send reports to your own enterprise endpoint.
Scored Oct 5, 2026
Meta-skill for AI agent self-improvement. Analyzes runtime logs to detect error patterns, regressions, and inefficiencies, then generates structured improvem...
Stop waiting for prompts. Keep working.
Turn OpenClaw into a learning-loop agent with seeded workspace rules, skill promotion, reflective memory, and proactive maintenance.
Meta-agent skill for orchestrating complex tasks through autonomous sub-agents. Decomposes macro tasks into subtasks, spawns specialized sub-agents with dynamically generated SKILL.md files, coordinates file-based communication, consolidates results, and dissolves agents upon completion. MANDATORY TRIGGERS: orchestrate, multi-agent, decompose task, spawn agents, sub-agents, parallel agents, agent coordination, task breakdown, meta-agent, agent factory, delegate tasks
Complete toolkit for creating autonomous AI agents and managing Discord channels for OpenClaw. Use when setting up multi-agent systems, creating new agents, or managing Discord channel organization.
Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentic...