Clawned for Openclaw

Clawned is a specialized security agent that inventories, analyzes, and syncs security data for all your Openclaw Skills to a centralized dashboard.

jenish-sojitra
v1.0.1
Feb 25, 2026
0
933
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install clawnedhub

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install clawnedhub using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Clawned?

Clawned serves as the primary security layer for users who extensively utilize various Openclaw Skills. It acts as an automated auditor that discovers every installed skill within your environment, extracts essential metadata, and evaluates them for potential security risks. By integrating directly with the Clawned dashboard, it provides a high-level overview of your agent ecosystem's health.

The tool is built with a security-first mindset, ensuring that sensitive data like environment variables or secrets are never exposed during standard operations. Whether you are a solo developer or part of a larger team, Clawned provides the visibility needed to manage Openclaw Skills safely and efficiently, bridging the gap between rapid automation and robust cybersecurity.

Clawned Use Cases

  • Auditing third-party Openclaw Skills for malicious patterns or vulnerabilities.
  • Maintaining a real-time inventory of all installed agent capabilities across different local directories.
  • Automating security compliance checks through scheduled cron jobs to ensure a clean development environment.
  • Performing deep-dive source code analysis on specific Openclaw Skills before they are enabled in production workflows.

How Clawned Works

  1. The agent parses your local configuration to identify the locations of all Openclaw Skills.
  2. It executes an inventory command to catalog metadata such as versions, owners, and unique slugs.
  3. During a sync operation, this metadata is securely transmitted to the Clawned dashboard for monitoring.
  4. For deep-tissue analysis, users can manually trigger a scan of a specific skill directory, which analyzes source files for security threats.
  5. The agent reports the security status back to the user, highlighting any flags or required updates.

Clawned Setup

To get started, you must configure your API key within your openclaw.json file to allow the agent to communicate with the security dashboard:

{
  "skills": {
    "entries": {
      "clawned": {
        "enabled": true,
        "env": {
          "CLAWNED_API_KEY": "cg_your_api_key_here",
          "CLAWNED_SERVER": "https://api.clawned.io"
        }
      }
    }
  }
}

Once configured, you can verify the status of the security agent using the following command:

python3 {baseDir}/scripts/agent.py status

Clawned Data Schema & Taxonomy

Clawned organizes its data based on the level of analysis required, ensuring a balance between security insights and user privacy.

Data Component Scope Storage/Transmission
Skill Metadata Name, Owner, Version, Slug Synced to Clawned dashboard during sync operations.
Analysis Files .py, .js, .md source files Processed only during explicit local scan commands.
Configuration ~/.openclaw/openclaw.json Read locally to resolve skill paths; secrets are never uploaded.
Exclusion List .env files, secrets, keys Strictly ignored by all scanning and syncing logic.

Clawned Advanced Features

  • Scheduled Security Audits: Leverage the Openclaw cron system to automatically run a sync and check all Openclaw Skills every 6 hours.
  • Targeted Local Scanning: Deep-scan specific directories to analyze the source code of newly downloaded Openclaw Skills without affecting the rest of the system.
  • Privacy-Centric Syncing: Standard operations only transmit metadata, ensuring your logic and private data stay local.
  • Multi-Directory Support: Automatically discovers Openclaw Skills located in various paths defined via extraDirs in the global configuration.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*