A security-focused scanning engine designed to detect malicious patterns, reverse shells, and data exfiltration in AI agent extensions.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install openclaw-skill-scanner
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install openclaw-skill-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Skill Scanner is a robust security tool tailored for the Openclaw Skills ecosystem, providing a critical layer of defense against malicious code. By analyzing scripts for high-risk patterns such as obfuscated Base64 payloads, crypto miners, and unauthorized data exfiltration, it ensures that your AI coding environment remains secure and trustworthy.
This tool functions as a gatekeeper, allowing developers to audit third-party integrations from ClawHub before deployment. Whether you are performing a pre-install check or auditing your existing library, Skill Scanner provides a transparent risk assessment to keep your local machine and cloud environments safe from emerging threats in the world of Openclaw Skills.
To begin securing your Openclaw Skills, ensure you have Python 3 installed and follow these steps:
# Navigate to your skill-scanner directory
cd skill-scanner
# Run a scan on all currently installed skills
python3 scanner.py
# Perform a pre-install scan on a new skill from ClawHub
python3 scanner.py --pre-install <clawhub-slug>
# Use the safe install hook wrapper
bash install-hook.sh <clawhub-slug>
| Component | Description |
|---|---|
scanner.py |
The core Python engine responsible for pattern detection and risk scoring. |
whitelist.json |
A configurable registry of known-safe skills and verified-bad signatures. |
report-template.md |
A Markdown template used to output human-readable security audit results. |
| Risk Scores | A taxonomy ranging from 0-29 (Clean) to 70-100 (Dangerous/Malicious). |
--json flag to generate data for CI/CD pipelines or custom security dashboards.Loading
A specialized skill that enables AI agents to join a dedicated social network for cross-agent communication and autonomous engagement.

A multi-timeframe technical analysis engine that generates scored trading signals and structured trade plans for cryptocurrency pairs.

A utility for fetching and summarizing Slack channel histories and specific message threads from workspace links or IDs.

An AI-optimized utility to fetch, format, and summarize Slack channel histories and threaded conversations for seamless context gathering.

Virtually Us is a professional managed hosting service that deploys and configures your private AI assistant using Openclaw Skills within 24 hours.

A social networking skill for AI agents to register, post updates, and engage with other bots in specialized communities.








































