skulk-skill-scannerScan OpenClaw skill folders for security red flags before installing or publishing. Detects data exfiltration, credential theft, prompt injection, destructiv...
Install via ClawdBot CLI:
clawdbot install adainthelab/skulk-skill-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
exec(Uses known external API (expected, informational)
api.anthropic.comAudited Apr 17, 2026 · audit v1.0
Generated Mar 20, 2026
A platform like ClawHub uses this scanner to automatically vet skills submitted by developers before listing them, ensuring they meet security standards. It integrates into the CI/CD pipeline to flag malicious patterns such as data exfiltration or credential theft, protecting end-users from supply chain attacks.
An organization deploying OpenClaw agents internally uses the scanner to audit custom skills developed in-house before enabling them in production environments. This ensures compliance with security policies by detecting risks like destructive commands or privilege escalation, reducing insider threats.
Independent developers creating skills for OpenClaw use the tool to self-audit their code before publishing to marketplaces, catching issues like obfuscation or unauthorized network access. This builds trust with users and prevents rejection due to security failures, enhancing reputation.
Training programs or workshops on AI agent security incorporate the scanner as a hands-on tool for students to analyze skill code for red flags. It helps learners identify common attack vectors like prompt injection, reinforcing best practices in secure coding.
Offer the scanner as a free, open-source tool for basic scanning to attract users, then charge for premium features like advanced rule sets, custom domain allowlists, or integration support. Revenue comes from subscriptions for enterprises needing enhanced security audits.
Partner with AI agent platforms like ClawHub to embed the scanner as a mandatory security check for skill submissions, charging a fee per scan or a licensing fee. This ensures marketplace safety while generating revenue from platform operators seeking to reduce fraud.
Provide consulting services to organizations for customizing the scanner, such as adding industry-specific rules or integrating it into existing DevOps pipelines. Revenue is generated through project-based fees and ongoing support contracts for tailored security solutions.
💬 Integration Tip
Integrate the scanner into CI/CD pipelines using the --json flag for automated reporting, and customize the SAFE_DOMAINS array to reduce false positives in your specific environment.
Scored Apr 19, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.