ClawHub Skill Scanner for Openclaw

A mandatory security gatekeeper that performs deep code analysis to detect malicious patterns before installing any Openclaw Skills.

amir-ag
v0.1.0
Feb 6, 2026
1
2.9k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install clawhub-skill-scanner

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install clawhub-skill-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is ClawHub Skill Scanner?

The ClawHub Skill Scanner serves as a critical security layer for AI agent environments. It acts as a mandatory gatekeeper designed to analyze external code from ClawHub, GitHub, or other sources before any installation occurs. By inspecting for malicious behaviors like credential harvesting, reverse shells, or unauthorized data exfiltration, it ensures that every addition to your Openclaw Skills library is safe and verified.

Inspired by real-world supply chain attacks like the ClawHavoc campaign, this tool provides developers and power users with the peace of mind needed when extending agent capabilities. It identifies high-risk patterns without creating excessive noise, focusing specifically on threats that could compromise your system or leak sensitive data while ignoring common API or configuration patterns.

ClawHub Skill Scanner Use Cases

  • Validating safety before running a install command for new Openclaw Skills.
  • Auditing manual skill downloads or code copies from untrusted repositories.
  • Verifying the security of Openclaw Skills sourced directly from GitHub or external URLs.
  • Integrating automated security checks into a CI/CD pipeline for agent skill deployment.

How ClawHub Skill Scanner Works

  1. The scanner is triggered manually or via a wrapper script before the installation of any Openclaw Skills.
  2. It performs a deep static code analysis on the target folder, searching for critical patterns like command injections, reverse shells, and data exfiltration.
  3. A risk score (0-100) is calculated based on the severity and frequency of findings, with critical hits weighted heavily.
  4. The tool generates a detailed report categorizing threats as CRITICAL (blocking) or WARNING (review required).
  5. Based on the final score, the installation is either auto-approved, flagged for manual review, or strictly blocked to prevent system compromise.

ClawHub Skill Scanner Setup

Clone the repository and ensure Python 3 is installed. You can then run the scanner directly against any directory containing Openclaw Skills.

# Basic scan of a skill directory
python3 scripts/scan_skill.py /path/to/skill

# Get results in JSON format for automation
python3 scripts/scan_skill.py /path/to/skill --json

# Run scan and only proceed with installation if the code is safe
python3 scripts/scan_skill.py /path/to/skill --install-if-safe

ClawHub Skill Scanner Data Schema & Taxonomy

The scanner organizes its audit data into a structured report that can be exported for automated workflows.

Component Description
Risk Score A numeric value (0-100) determining the safety tier (Safe, Caution, Danger, Blocked).
Critical Findings A list of severe vulnerabilities like reverse shells or credential access with line numbers.
Warning Findings Suspicious patterns like raw socket usage or file deletions that require review.
Metadata Includes files scanned, total lines of code, and specific malicious patterns detected.

ClawHub Skill Scanner Advanced Features

  • Automation-ready JSON output mode for integration with existing security toolchains.
  • Conditional installation flag to streamline the deployment of verified Openclaw Skills.
  • Detection of sophisticated obfuscation techniques, including base64 pipes and dynamic code compilation.
  • Customizable risk scoring thresholds to match the security posture of your specific environment.
  • Pattern-based detection for credential exfiltration targeting .env files and cloud provider secrets.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*