Skill Scanner for Openclaw

A security-focused scanning engine designed to detect malicious patterns, reverse shells, and data exfiltration in AI agent extensions.

epwhesq
v1.0.0
Feb 4, 2026
1
1.8k
3

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install openclaw-skill-scanner

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install openclaw-skill-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Skill Scanner?

Skill Scanner is a robust security tool tailored for the Openclaw Skills ecosystem, providing a critical layer of defense against malicious code. By analyzing scripts for high-risk patterns such as obfuscated Base64 payloads, crypto miners, and unauthorized data exfiltration, it ensures that your AI coding environment remains secure and trustworthy.

This tool functions as a gatekeeper, allowing developers to audit third-party integrations from ClawHub before deployment. Whether you are performing a pre-install check or auditing your existing library, Skill Scanner provides a transparent risk assessment to keep your local machine and cloud environments safe from emerging threats in the world of Openclaw Skills.

Skill Scanner Use Cases

  • Auditing third-party skills for hidden malicious payloads like reverse shells or crypto miners.
  • Running automated pre-installation checks to ensure Openclaw Skills are safe before they are added to your workflow.
  • Generating JSON-formatted security reports for compliance and auditing purposes.
  • Monitoring for data exfiltration attempts through suspicious outbound URL redirects or environment variable reading.

How Skill Scanner Works

  1. The scanner engine initializes by loading predefined detection patterns and the local whitelist configuration.
  2. It traverses the target skill directory or specific file, performing heuristic analysis against known security threats like pipe-to-shell commands or dangerous functions.
  3. The logic calculates a risk score (0-100) based on the severity and frequency of detected anomalies.
  4. A detailed report is generated, categorizing the findings into Green (Clean), Yellow (Suspicious), or Red (Dangerous) risk levels.
  5. If integrated via the provided install-hook, the scanner can automatically block the installation of high-risk Openclaw Skills.

Skill Scanner Setup

To begin securing your Openclaw Skills, ensure you have Python 3 installed and follow these steps:

# Navigate to your skill-scanner directory
cd skill-scanner

# Run a scan on all currently installed skills
python3 scanner.py

# Perform a pre-install scan on a new skill from ClawHub
python3 scanner.py --pre-install <clawhub-slug>

# Use the safe install hook wrapper
bash install-hook.sh <clawhub-slug>

Skill Scanner Data Schema & Taxonomy

Component Description
scanner.py The core Python engine responsible for pattern detection and risk scoring.
whitelist.json A configurable registry of known-safe skills and verified-bad signatures.
report-template.md A Markdown template used to output human-readable security audit results.
Risk Scores A taxonomy ranging from 0-29 (Clean) to 70-100 (Dangerous/Malicious).

Skill Scanner Advanced Features

  • Pre-install Automation: Automatically download, scan, report, and cleanup a skill before committing to an installation.
  • Machine-Readable Reports: Use the --json flag to generate data for CI/CD pipelines or custom security dashboards.
  • Safe Install Hook: A dedicated bash wrapper that forces a security check prior to any skill installation command.
  • Deep Obfuscation Detection: Specifically targets long Base64 strings placed near execution functions to catch hidden payloads in Openclaw Skills.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*