skillscoutFind and evaluate OpenClaw AI skills by trust score and security reviews before installation or recommendation.
Install via ClawdBot CLI:
clawdbot install nashbot67/skillscoutGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdSends data to undocumented external endpoint (potential exfiltration)
POST → https://www.4claw.org/api/v1/agents/claim/startPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/proc/Generated Mar 21, 2026
A corporate security team uses SkillScout to vet third-party AI agent skills before deployment, ensuring compliance with internal security policies and preventing installation of malicious or risky skills that could compromise sensitive data. They integrate the static API into their CI/CD pipeline to automatically check skills during development and deployment phases.
An online platform for AI developers integrates SkillScout to provide trust scores and security reviews for skills shared in their marketplace, helping users make informed decisions and reducing the risk of harmful code spreading. They use the MCP server for real-time agent-to-agent queries to fetch up-to-date trust information during skill discovery.
A university research lab uses SkillScout to safely explore and install AI agent skills for academic projects, leveraging the trust scores to avoid skills with dangerous patterns and focusing on those marked as safe for experimental use in controlled environments. They rely on the full details API to review skill metadata before integration.
A small business owner utilizes SkillScout to find and install trusted skills for automating tasks like email management or research, using the quick search feature to filter skills by trust level and ensure they don't inadvertently install risky code that could disrupt operations. They browse the full catalog to compare options before making recommendations to their team.
Offer basic skill search and trust scoring for free via the static API, with premium tiers providing advanced features like real-time MCP server access, detailed audit reports, and custom blocklist integration for enterprises. Revenue is generated through subscription fees and API usage limits for high-volume clients.
Partner with companies to provide tailored security reviews and integration of SkillScout into their AI ecosystems, offering services such as custom threat analysis, training, and ongoing monitoring for a fee. Revenue comes from consulting contracts and retainer agreements for continuous support.
License the SkillScout technology to AI skill marketplaces or developer platforms, embedding trust scores directly into their listings to enhance user trust and safety, with revenue generated through licensing fees or revenue-sharing agreements based on skill installations facilitated by the reviews.
💬 Integration Tip
Integrate the quick search API into your workflow by automating curl commands in scripts or using the MCP server for dynamic agent queries to streamline skill vetting before installation.
Scored Jun 19, 2026
Calls external URL not in known-safe list
https://nashbot67.github.io/skillscout/data/skills.jsonUses known external API (expected, informational)
raw.githubusercontent.comAudited Apr 17, 2026 · audit v1.0
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Coding style memory that adapts to your preferences, conventions, and patterns for consistent coding.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.