tommo-skill-guardSecurity scanner for OpenClaw agent skills. Pre-install check via ClawHub page, local pattern scanning via read tool (zero exec), integrity verification. Use...
Install via ClawdBot CLI:
clawdbot install tommot2/tommo-skill-guardGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://clawhub.ai/skills/tommo-skill-guardUses known external API (expected, informational)
api.openai.comAI Analysis
The skill is a security scanner designed for read-only analysis of other skills, with no evidence of sending user data to unauthorized servers, hidden malicious instructions, or credential harvesting. Its external URL reference is to its own homepage for security status checks, which aligns with its stated purpose, and it explicitly avoids execution risks by using only the `read` tool.
Generated Aug 15, 2026
A developer wants to install a new skill from ClawHub but is concerned about security risks. They use Skill Guard to check the ClawHub page for security flags and review the skill's metadata before installation, preventing potential malware or malicious code from entering their environment.
An organization has accumulated many skills over time and wants to ensure no skill contains dangerous patterns or hardcoded secrets. They run a local pattern scan on all installed skills using Skill Guard, which reads files without executing them, and generates a report for review.
After a security incident, a security analyst suspects a skill may have been tampered with or contains malicious code. They use Skill Guard's integrity check to compare current files against a known baseline, identifying any unauthorized modifications.
A compliance officer needs to ensure that third-party skills used in their company meet security standards. They use Skill Guard to scan skills for risky patterns and to flag any suspicious behavior, ensuring compliance with internal security policies.
A DevSecOps team wants to continuously monitor skills for new vulnerabilities. They use Skill Guard to periodically scan skills and check ClawHub for flags, integrating it into their CI/CD pipeline to catch issues early.
Offer the basic scanning features for free, but provide advanced features like automated integrity checks, scheduled scans, and priority support as part of a subscription.
License the tool to enterprises that require bulk scanning, custom pattern definitions, and integration with their internal security workflows.
Bundle Skill Guard with security consulting services, offering installation, configuration, and ongoing security audits for a premium fee.
💬 Integration Tip
Integrate Skill Guard into the installation workflow by prompting users to run 'scan' before installing new skills, and schedule regular scans via a cron job or CI pipeline.
Scored Jul 8, 2026
Audited Apr 18, 2026 · audit v1.0
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...