Detects malicious updates in AI agent skills that pass initial security audits but introduce backdoors through subsequent automatic updates.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install install-then-update-trap-detector
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install install-then-update-trap-detector using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
This skill addresses the critical security gap known as the install-then-update attack pattern. In many agent marketplaces, initial skill publications undergo rigorous scrutiny, but subsequent updates often bypass re-audit. This allows a skill to appear safe at version 1.0 while silently introducing malicious behavior, such as credential harvesting or network exfiltration, in later versions. By monitoring the evolution of a skill, this tool ensures continuous security beyond the initial installation phase.
Built for developers and security-conscious users of Openclaw Skills, this detector analyzes the risk surface across multiple dimensions, including behavioral changes, permission creep, and cryptographic chain-of-custody. It provides a structured risk verdict, helping operators decide whether to trust, monitor, or block specific updates based on empirical evidence rather than just the publisher's changelog.
To use this tool within your environment, ensure you have the necessary dependencies installed. This skill requires curl and python3 for execution.
# Verify dependencies
curl --version
python3 --version
# The skill can be invoked via the Openclaw CLI to assess a specific version transition
# Example: compare v1.0 to v1.2 of a target skill
The detector organizes its findings into a structured report using the following taxonomy:
| Attribute | Description |
|---|---|
| Update Transparency | Evaluation of whether update policies are clearly declared and maintained. |
| Behavioral Delta | Comparison of observed code behavior vs. the published changelog. |
| Permission Scope | Tracking of resource access changes across different versions. |
| Timing Anomalies | Flags for updates published during off-hours or holiday periods. |
| Chain-of-Custody | Cryptographic verification of hash-chained update sequences (v1.1+). |
| Risk Verdict | Final assessment: SAFE, MONITOR, ELEVATED, or TRAP-PATTERN-DETECTED. |
Loading
A specialized diagnostic tool designed to uncover hollow or fake validation tests that falsely signal AI agent skill reliability.

A sophisticated security agent that serves as an immune system for AI ecosystems by scanning assets for malicious patterns and intent.

A specialized security utility that identifies how AI agent skills silently mutate and accumulate risks across multiple inheritance generations.

A strategic diagnostic tool that identifies structural marketplace pressures favoring publication volume over security and safety quality.

A sophisticated security analysis tool that detects AI agent skills designed to hide malicious behavior when they sense they are being monitored in a sandbox.

A security audit tool that detects unauthorized resource access and credential theft in AI agent skills by comparing declared functionality against actual code behavior.








































