A robust security auditing tool designed to detect vulnerabilities, credential leaks, and unsafe code within Openclaw Skills before they are executed.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install agent-audit-scanner
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install agent-audit-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Agent Audit Scanner is a specialized security framework tailored for developers and power users of the Openclaw ecosystem. It serves as a gatekeeper, analyzing scripts, configurations, and metadata to identify critical threats such as prompt injection, obfuscated shell commands, and privilege escalation.
By adhering to the 10 OWASP Agentic AI threat categories, this skill ensures that every addition to your agentic workflow is vetted against 49+ detection rules. Integrating this scanner into your routine helps maintain a hardened environment, protecting sensitive files and system integrity from malicious or poorly configured Openclaw Skills that could compromise your workspace.
First, install the core auditing engine via pip:
pip install agent-audit && agent-audit --version
Once installed, the scanner can be invoked through the agent or directly via CLI using the bundled scripts to audit your Openclaw Skills.
The skill organizes its security intelligence and reporting based on the following structure:
| Component | Description |
|---|---|
| Metadata Frontmatter | Scans for risky flags like always:true or suspicious network endpoints in SKILL.md. |
| Config Files | Audits .mcp.json and openclaw.json for hardcoded tokens and broad filesystem access. |
| Source Code | Analyzes .py, .sh, .js, and .ts files for obfuscated commands and credential leaks. |
| Risk Mapping | Maps findings to the 56-rule OWASP ASI categorization for standardized reporting. |
Loading
A machine-first venture intelligence skill for identifying and scoring high-signal startup opportunities via read-first API workflows.

A context-recovery tool that allows AI agents to search and retrieve information from past session transcripts.

A powerful tool for minting and managing permanent, on-chain identities and behavioral traits for AI agents on the Base network.

A headless-ready integration for the Box CLI to manage cloud content and leverage Box AI directly from your agent.

A sophisticated logging and feedback framework that enables AI coding agents to autonomously capture learnings and fix recurring errors.

A high-performance Android WebView container SDK featuring preloading, instance reuse, and seamless JS-Native bidirectional communication.








































