skll-scanSecurity scanning tool for OpenClaw Skills. Detects malicious code patterns, extracts domains, and checks threat intelligence APIs. Use when: installing new...
Install via ClawdBot CLI:
clawdbot install niuqun2003/skll-scanGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
POST → https://urlhaus-api.abuse.ch/v1/host/Potentially destructive shell commands in tool definitions
Exec (Accesses system directories or attempts privilege escalation
/etc/cronCalls external URL not in known-safe list
https://urlhaus-api.abuse.ch/Generated Mar 21, 2026
A marketplace for distributing OpenClaw Skills uses skill-scan to automatically vet all submissions before listing. It scans for malicious code and suspicious domains, ensuring only safe Skills are available to users, reducing security risks and building trust in the platform.
A large corporation deploys OpenClaw Skills across its operations and uses skill-scan for periodic security audits. It scans installed Skills to detect unauthorized changes or new threats, helping maintain compliance and prevent data breaches from compromised extensions.
Developers of OpenClaw Skills integrate skill-scan into their CI/CD pipelines to automatically scan code before deployment. This ensures security checks are part of the development workflow, catching vulnerabilities early and streamlining safe Skill distribution.
A training organization uses skill-scan as a hands-on tool in courses about AI security. Students learn to analyze Skill code for threats, understand risk scoring, and apply best practices, preparing them for roles in cybersecurity and AI development.
A security firm offers a monitoring service that uses skill-scan to track threats in OpenClaw Skills across client networks. It scans for malicious patterns and domains, providing alerts and reports to help clients respond to emerging security risks proactively.
Offer skill-scan as a free open-source tool with basic scanning features. Generate revenue by selling premium subscriptions for advanced threat intelligence APIs, priority support, and enhanced reporting capabilities to enterprise users.
Provide skill-scan as a cloud-based service where users upload Skill code for scanning via an API or web interface. Charge based on scan volume, number of Skills analyzed, or through tiered plans with different threat intelligence integrations.
Offer consulting services to help organizations integrate skill-scan into their existing security frameworks. Revenue comes from custom integrations, training workshops, and ongoing support for security audits and compliance needs.
💬 Integration Tip
Integrate skill-scan into automated workflows by using its JSON export feature for easy parsing and logging in CI/CD pipelines or security dashboards.
Scored Jun 17, 2026
Uses known external API (expected, informational)
googleapis.comAI Analysis
The skill's external API calls to abuse.ch and googleapis.com are consistent with its stated purpose of threat intelligence checking and do not appear to exfiltrate user data. The signals identified are related to the tool's own scanning operations, not hidden malicious behavior, and no credential harvesting or obfuscation is present.
Audited Apr 17, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...