A documentation-first security skill providing transparency and guidance for performing static analysis on third-party tools.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install crawsecure
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install crawsecure using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
CrawSecure is a documentation-centric security skill designed for the ecosystem to promote security awareness and transparency. Its primary purpose is to provide a clear framework for understanding, documenting, and guiding the safe usage of static analysis tools. By focusing on documentation rather than execution, it provides a safe environment for developers to learn about risk signals without introducing new attack vectors. This skill helps users evaluate the safety of various Openclaw Skills by defining what constitutes dangerous behavior and how to interpret security findings.
The skill serves as the central reference point for the external CrawSecure CLI, ensuring that users understand the trust boundaries and security philosophy required for modern development. It emphasizes local, offline analysis and provides a standardized classification system for identifying safe, medium, and high-risk patterns in code and configuration files.
To add this documentation-only skill to your environment, use the standard installation command for your agent. Note that this skill requires no special permissions and operates in a read-only capacity.
# Install the CrawSecure documentation skill
openclaw install crawsecure
To perform actual security scans, you must independently install the CrawSecure CLI from its official GitHub repository or official website.
CrawSecure organizes security information based on risk levels and behavioral patterns. The documentation follows this metadata structure:
| Category | Description | Scope |
|---|---|---|
| Risk Signal | Detection logic for dangerous or destructive commands | Static Analysis |
| File Sensitivity | Identification of private keys, .env, and .ssh files | Credential Security |
| Trust Boundaries | Definition of read-only, network-less, and execution-less limits | Operational Security |
| Classification | SAFE, MEDIUM, and HIGH risk categorization levels | Risk Assessment |
Loading
A specialized operational toolkit designed for rescue agents to diagnose, repair, and maintain OpenClaw Gateway instances.

An automated pipeline for gathering and synthesizing media and entertainment industry news from 65+ specialized sources.

A specialized management toolkit for Cobo TSS Nodes, providing automated installation, service management, and secure MPC share maintenance.

A high-precision skill for retrieving and validating real-time Geekbench benchmark scores for the latest mobile flagship devices.

A comprehensive collaboration skill that connects AI agents to Minibook instances for project management, threaded discussions, and roadmap tracking.

A zero-dependency security middleware that sanitizes email and calendar data to prevent prompt injection and malicious exfiltration in AI agents.








































