skillscannerSecurity scanner for ClawHub skills from Gen Digital. Looks up skill safety via the scan API.
Install via ClawdBot CLI:
clawdbot install rexshang/skillscannerGrade Good — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://ai.gendigital.com/api/scan/lookupCalls external URL not in known-safe list
https://clawhub.ai/author/skill-name`AI Analysis
The skill's external API call (ai.gendigital.com) is directly documented as its core function for security scanning, not a hidden data sink. While it sends skill URLs provided by the user, this is consistent with its stated purpose and does not constitute unauthorized credential harvesting or exfiltration of private user data.
Audited Apr 16, 2026 · audit v1.0
Generated Mar 1, 2026
IT security teams in large organizations use SkillScanner to vet third-party AI skills before deployment, ensuring compliance with internal security policies and preventing unauthorized code execution. This helps mitigate risks like data exfiltration and supply chain attacks by verifying skill safety through automated API scans.
AI skill marketplace platforms integrate SkillScanner into their submission workflows to automatically scan new skills for safety, providing users with trust badges and reducing manual review overhead. This enhances platform credibility by flagging potentially malicious skills before they are listed.
Cybersecurity training programs incorporate SkillScanner as a hands-on tool for teaching students about threat detection in AI ecosystems, focusing on analyzing API responses for severity levels like SAFE or DANGEROUS. This practical exercise helps learners understand real-world risks in skill-based environments.
Organizations in regulated industries such as finance or healthcare use SkillScanner to audit AI skills for compliance with data protection standards, ensuring skills do not access sensitive files or environment variables. This supports adherence to regulations by verifying skill safety before integration into critical systems.
Offer free basic scanning with limited API calls, then charge for higher usage tiers, advanced analytics, or priority support. Revenue is generated through subscription plans targeting developers and enterprises needing frequent skill vetting.
Sell on-premise or private cloud licenses to large organizations for integrating SkillScanner into their internal security toolchains. This model includes custom support, SLA guarantees, and volume discounts based on user count.
Partner with AI skill marketplaces to embed scanning services, earning revenue through referral fees or revenue-sharing agreements based on skill transactions. This leverages existing user bases and enhances trust in partner platforms.
💬 Integration Tip
Integrate SkillScanner into CI/CD pipelines to automatically scan skills during deployment, using the provided curl command to call the API and parse JSON responses for SAFE status before proceeding.
Scored Apr 19, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.