A comprehensive security vulnerability scanner for identifying prompt injection, malware, and dependency risks in AI agent skills and MCP servers.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install aiclude-security-scan
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install aiclude-security-scan using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
AIclude Security Scanner is a robust security tool built to safeguard the ecosystem of Openclaw Skills and Model Context Protocol (MCP) servers. It provides developers and security teams with the ability to instantly audit AI integrations for specialized threats that traditional scanners often miss. By focusing on AI-native vulnerabilities such as tool poisoning and prompt injection, it ensures that your automated workflows remain secure and trustworthy.
This skill functions by analyzing both local source code and remote packages, leveraging a multi-engine architecture to provide a deep-dive assessment of a target's risk profile. Whether you are building new Openclaw Skills or integrating third-party tools, this scanner provides the visibility needed to mitigate supply chain attacks, permission abuse, and malicious code execution before they reach production.
/security-scan command, specifying a package name or a local directory path.To use the security scanner within your environment supporting Openclaw Skills, simply invoke the command. No manual installation of the engines is required as they are managed via the AIclude cloud or sandbox environment.
# Scan a remote package by name
/security-scan --name <package-name>
# Scan your current local directory
/security-scan .
The scanner generates a detailed report structure to help developers understand and fix vulnerabilities. The data is organized as follows:
| Component | Details |
|---|---|
| Risk Level | Categorized as CRITICAL, HIGH, MEDIUM, LOW, or INFO. |
| Vulnerability List | Precise code locations, descriptions, and severity levels. |
| Risk Assessment | A summary of the potential impact of found vulnerabilities on Openclaw Skills. |
| Remediation | Step-by-step instructions on how to patch or mitigate the identified risks. |
| Metadata | Includes auto-detected target type (mcp-server or skill) and used engines. |
Loading
A powerful productivity engine that synchronizes Slack, Strava, and Harvest data into automated daily notes and a local SQLite database.

A comprehensive toolkit for AI agents to deploy contracts, bridge assets, and interact with the Abstract ZK Stack Layer 2 network.

A creative customization toolkit for personalizing the Claude Code mascot's appearance and color schemes within your terminal.

A self-supervising manager for long-running AI agent tasks with progress tracking and periodic reporting.

A specialized security auditing skill designed to scan and report vulnerabilities within MCP servers and AI agent packages.

OpenSoul provides AI agents with an immutable, blockchain-based audit log for persistent memory, self-reflection, and economic autonomy.








































