A comprehensive security scanner designed to protect OpenClaw agents from malicious skills, hallucinated packages, and prompt injection attacks.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install clawproof-security
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install clawproof-security using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
ClawProof Security provides a robust defense layer for autonomous AI agents. As Openclaw Skills can execute code and manage dependencies, they introduce unique risks such as supply chain attacks and data exfiltration. This tool acts as a gatekeeper, analyzing every action before execution.
By integrating deep skill scanning and real-time behavioral analysis, it ensures that your Openclaw Skills remain safe and compliant with enterprise security standards. It specifically targets threats like the ClawHavoc malware and prevents the common LLM issue of package name hallucination.
To secure your environment for Openclaw Skills, install the scanner globally using npm:
npm install -g agent-security-scanner-mcp
To initialize the MCP server for automatic protection in your AI-powered IDE (like Cursor or Claude Code), run:
npx agent-security-scanner-mcp init openclaw
You can also verify the installation by running the doctor command:
npx agent-security-scanner-mcp doctor
ClawProof organizes its security intelligence using several metadata layers and export formats to ensure transparency and compatibility:
| Component | Description |
|---|---|
| Threat Rules | 1700+ security rules covering 12 programming languages including Python and JS |
| Malware Signatures | 121 specific patterns targeting the ClawHavoc malware family and OpenClaw exfiltration |
| Package Registry | A verified local cache of 4.3M+ packages from npm, PyPI, Go, and Ruby |
| SARIF Output | Standardized JSON format for integration with enterprise security tabs in GitHub or GitLab |
Loading
A comprehensive financial data retrieval tool for AI agents to access real-time and historical Chinese market data via the THS iFinD API.

A professional-grade financial data integration providing real-time and historical market data for the Chinese financial market.

A specialized tool for fetching and displaying daily lunch menus from restaurants across Umeå via live data.

A comprehensive data retrieval tool for querying Umeå municipal open data regarding infrastructure, demographics, and environment.

A comprehensive integration for managing Miniflux RSS instances, enabling AI agents to browse, search, and organize feeds.

A hardware-integration skill that allows AI agents to detect and react to physical impacts or shakes on a MacBook using the built-in accelerometer.








































