GuardSkills for Openclaw

A proactive security scanner that performs static analysis on skills to detect malicious patterns before they are installed.

felixondesk
v1.2.1
Feb 23, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install guardskills

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install guardskills using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is GuardSkills?

GuardSkills serves as a critical security gate for any developer or user interacting with the ecosystem of Openclaw Skills. It acts as a static analysis tool that scans skill content for dangerous signatures, including credential exfiltration, remote code execution, destructive filesystem operations, and unauthorized privilege escalation. By running these checks before installation, it ensures that your AI agent environment remains secure and untainted by malicious code from external sources.

This utility is designed to be the first point of contact whenever you encounter new Openclaw Skills. Whether you are downloading from ClawHub, GitHub, or using local files, GuardSkills provides a clear risk decision—ranging from SAFE to CRITICAL—allowing you to make informed decisions about the software you permit your AI agents to execute.

GuardSkills Use Cases

  • Scanning Openclaw Skills from ClawHub or GitHub before adding them to your agent environment.
  • Performing local audits on custom-developed skills to ensure no accidental security vulnerabilities exist.
  • Integrating automated security gates into CI/CD pipelines to verify skill safety programmatically.
  • Preventing the execution of obfuscated payloads or suspicious network activity within a developer's workspace.

How GuardSkills Works

  1. The user identifies a skill source, such as a local path or a remote URL for Openclaw Skills.
  2. The developer executes a guardskills scan command (e.g., scan-clawhub, scan-local, or add --dry-run).
  3. GuardSkills parses the skill files and metadata, looking for specific malicious patterns and risky logical chains.
  4. The tool outputs a risk decision (SAFE, WARNING, UNSAFE, CRITICAL, or UNVERIFIABLE) along with a suggested action.
  5. If the result is SAFE, the user can proceed with the standard installation of their Openclaw Skills; otherwise, the process is blocked or requires manual override.

GuardSkills Setup

To secure your environment, install the guardskills binary using npm. This allows you to verify any Openclaw Skills before they interact with your system.

npm install -g guardskills

Verify the installation by running a scan on a known skill slug:

guardskills scan-clawhub <owner/skill-slug>

GuardSkills Data Schema & Taxonomy

GuardSkills evaluates the structure and content of Openclaw Skills and provides structured feedback based on the following classification system:

Decision Meaning Recommended Action
SAFE No high-risk patterns detected Proceed with installation
WARNING Suspicious patterns found Request explicit user confirmation
UNSAFE High-risk patterns detected Block installation automatically
CRITICAL Malicious intent identified Hard block; do not install
UNVERIFIABLE Content cannot be analyzed Block and inform user

Users can also output these results in machine-readable format using the --json flag for integration with other tools managing Openclaw Skills.

GuardSkills Advanced Features

  • CI Mode: Use the --ci flag for deterministic gatekeeping in automated environments without interactive prompts.
  • Strict Thresholds: Enable the --strict flag to apply more rigorous security policies when evaluating Openclaw Skills.
  • Dry-Run Integration: Use the --dry-run flag with the add command to scan GitHub repositories before any files are written to disk.
  • Manual Overrides: Advanced users can use --force or --allow-unverifiable to bypass blocks if they have manually audited the code.
  • Pattern Detection: Scans specifically for RCE chains, credential theft, and suspicious network activity patterns.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*