A mandatory security gatekeeper that performs deep code analysis to detect malicious patterns before installing any Openclaw Skills.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install clawhub-skill-scanner
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install clawhub-skill-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The ClawHub Skill Scanner serves as a critical security layer for AI agent environments. It acts as a mandatory gatekeeper designed to analyze external code from ClawHub, GitHub, or other sources before any installation occurs. By inspecting for malicious behaviors like credential harvesting, reverse shells, or unauthorized data exfiltration, it ensures that every addition to your Openclaw Skills library is safe and verified.
Inspired by real-world supply chain attacks like the ClawHavoc campaign, this tool provides developers and power users with the peace of mind needed when extending agent capabilities. It identifies high-risk patterns without creating excessive noise, focusing specifically on threats that could compromise your system or leak sensitive data while ignoring common API or configuration patterns.
Clone the repository and ensure Python 3 is installed. You can then run the scanner directly against any directory containing Openclaw Skills.
# Basic scan of a skill directory
python3 scripts/scan_skill.py /path/to/skill
# Get results in JSON format for automation
python3 scripts/scan_skill.py /path/to/skill --json
# Run scan and only proceed with installation if the code is safe
python3 scripts/scan_skill.py /path/to/skill --install-if-safe
The scanner organizes its audit data into a structured report that can be exported for automated workflows.
| Component | Description |
|---|---|
| Risk Score | A numeric value (0-100) determining the safety tier (Safe, Caution, Danger, Blocked). |
| Critical Findings | A list of severe vulnerabilities like reverse shells or credential access with line numbers. |
| Warning Findings | Suspicious patterns like raw socket usage or file deletions that require review. |
| Metadata | Includes files scanned, total lines of code, and specific malicious patterns detected. |
Loading
Automate the generation and downloading of AI images by driving ChatGPT through Playwright browser automation.

An AI-powered performance marketing agent that automates campaign management, keyword research, and cross-platform reporting for major ad networks.

An AI-powered advertising agent for managing multi-channel ad campaigns across Google, Meta, LinkedIn, and TikTok using natural language.

An autonomous research copilot that manages the full scientific lifecycle from brainstorming to final reporting with a focus on reproducibility.

A sophisticated task management skill for Openclaw Skills that translates natural language into structured docstore commands for lists, boards, and planning.

A powerful bridge for AI agents to control Windows host processes, applications, and files directly from a WSL2 environment.








































