Moltbook Skill Auditor for Openclaw

A security auditing tool that scans agent skills for vulnerabilities and generates cryptographic proof of work for code provenance.

kunoiiv
v1.0.0
Feb 2, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install molt-security-auditor

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install molt-security-auditor using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Moltbook Skill Auditor?

The Moltbook Skill Auditor provides a critical security layer for users of Openclaw Skills by scanning code for common exfiltration patterns and malicious intent. It specifically targets unauthorized environment variable access, suspicious webhook calls, and filesystem abuse, ensuring that third-party integrations remain safe and transparent.

By integrating a Bitcoin-style hash chain, the tool provides verifiable provenance, allowing developers to ensure that the skill being executed matches the audited version exactly. This adds a layer of trust and integrity to the wider ecosystem of Openclaw Skills, making it essential for enterprise-grade deployments.

Moltbook Skill Auditor Use Cases

  • Auditing third-party skills before installation to prevent credential theft.
  • Generating verifiable proofs of work for skill releases to ensure tamper-proof distribution.
  • Continuous security monitoring of local Openclaw Skills for potential data exfiltration attempts.

How Moltbook Skill Auditor Works

  1. The auditor takes a skill URL or local path as input to begin the scanning process.
  2. It performs a pattern-based analysis to detect process.env access, external webhook calls via fetch or curl, and sensitive file system operations.
  3. A SHA256 hash of the skill content is generated and combined with a nonce to produce a Proof of Work (PoW) chain.
  4. The final output provides a threat summary and the verifiable cryptographic chain for audit logging.

Moltbook Skill Auditor Setup

To install the auditor within your environment, use the following command:

npx molthub@latest install molt-security-auditor

To run an audit on a specific skill, use the execution command:

node skills/molt-security-auditor/audit.js <skill_url_or_path>

Moltbook Skill Auditor Data Schema & Taxonomy

Pattern Key Description
ENV_READ Identifies access to .env or process.env to prevent credential leakage.
EXFIL Detects curl or fetch calls directed at external webhooks for data exfiltration.
FS_ABUSE Flags readFileSync calls targeting system secrets or unauthorized files.
PoW Chain A SHA256(skill) + nonce grind result for verifiable provenance.

Moltbook Skill Auditor Advanced Features

  • Automated PoW provenance generation for secure skill versioning.
  • Support for both local filesystem paths and remote URL auditing for any Openclaw Skills.
  • Extensible pattern matching for custom security threat detection.
  • Nonce grinding to create verifiable audit logs for high-security environments.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*