A proactive security scanner that performs static analysis on skills to detect malicious patterns before they are installed.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install guardskills
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install guardskills using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
GuardSkills serves as a critical security gate for any developer or user interacting with the ecosystem of Openclaw Skills. It acts as a static analysis tool that scans skill content for dangerous signatures, including credential exfiltration, remote code execution, destructive filesystem operations, and unauthorized privilege escalation. By running these checks before installation, it ensures that your AI agent environment remains secure and untainted by malicious code from external sources.
This utility is designed to be the first point of contact whenever you encounter new Openclaw Skills. Whether you are downloading from ClawHub, GitHub, or using local files, GuardSkills provides a clear risk decision—ranging from SAFE to CRITICAL—allowing you to make informed decisions about the software you permit your AI agents to execute.
To secure your environment, install the guardskills binary using npm. This allows you to verify any Openclaw Skills before they interact with your system.
npm install -g guardskills
Verify the installation by running a scan on a known skill slug:
guardskills scan-clawhub <owner/skill-slug>
GuardSkills evaluates the structure and content of Openclaw Skills and provides structured feedback based on the following classification system:
| Decision | Meaning | Recommended Action |
|---|---|---|
| SAFE | No high-risk patterns detected | Proceed with installation |
| WARNING | Suspicious patterns found | Request explicit user confirmation |
| UNSAFE | High-risk patterns detected | Block installation automatically |
| CRITICAL | Malicious intent identified | Hard block; do not install |
| UNVERIFIABLE | Content cannot be analyzed | Block and inform user |
Users can also output these results in machine-readable format using the --json flag for integration with other tools managing Openclaw Skills.
--ci flag for deterministic gatekeeping in automated environments without interactive prompts.--strict flag to apply more rigorous security policies when evaluating Openclaw Skills.--dry-run flag with the add command to scan GitHub repositories before any files are written to disk.--force or --allow-unverifiable to bypass blocks if they have manually audited the code.Loading
A powerful CLI tool for generating high-resolution AI images and performing sophisticated image-to-image edits using the Jimeng 4.0 model.

A high-performance financial scanner that extracts top gainers and losers from US, HK, and CN markets into structured JSON format.

ATLAS is an elite autonomous manager designed to oversee, maintain, and scale the ARGOS crypto trading bot ecosystem using advanced Python automation.

ATLAS is an elite autonomous manager designed to run, scale, and maintain crypto trading bot ecosystems 24/7 with zero-downtime goals.

A powerful MCP server that enables AI agents to control your existing Chrome browser, manage tabs, and automate web interactions seamlessly.

A powerful MCP-based skill that allows AI agents to control your existing Chrome browser for advanced automation tasks.








































