A comprehensive security testing suite designed to harden AI agents against prompt injection, jailbreaks, and advanced adversarial attacks.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install pwnclaw-security-scan
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install pwnclaw-security-scan using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
PwnClaw Security Scan is a specialized diagnostic skill that subjects AI agents to over 112 real-world attacks across 14 distinct categories. It is designed to identify critical vulnerabilities like indirect injection, agency hijacking, and tool poisoning, which are common risks in modern agentic workflows. By integrating this skill into your development lifecycle, you ensure your agents remain resilient against sophisticated exploits.
As part of the Openclaw Skills ecosystem, PwnClaw provides actionable intelligence through a security score and tailored fix instructions. This allows developers to iteratively harden their agents system prompts and logic based on empirical data rather than guesswork, ensuring a secure and reliable user experience.
To begin using PwnClaw Security Scan, follow these steps:
# Fetch the next attack prompt
curl -X GET "https://www.pwnclaw.com/api/test/{token}"
# Submit the agent's response for analysis
curl -X POST "https://www.pwnclaw.com/api/test/{token}" \
-H "Content-Type: application/json" \
-d '{"response": "YOUR_AGENT_RESPONSE"}'
The skill generates structured reports based on the following taxonomy:
| Category | Description |
|---|---|
| Injection | Tests for prompt and indirect injection vulnerabilities. |
| Jailbreaks | Evaluates refusal bypass and safety filter triggers. |
| Agency | Checks for agency hijacking and unauthorized tool usage. |
| MCP/Tool | Specifically tests for poisoning of Model Context Protocol integrations. |
| Scoring | A numerical representation of the agent's current security posture. |
All results, including the transcript of the attack and the generated fix instructions, are stored and accessible via the PwnClaw dashboard.
Loading
An automated DeFi management tool for earning sustainable yield on USDC through the Moonwell Flagship vault on the Base network.

An AI-driven DeFi portfolio manager for the Base network that optimizes yield across top protocols like Morpho and Yearn.

An AI-powered DeFi strategy agent designed to build, backtest, and adapt yield farming strategies on the Base network.

A comprehensive travel concierge that plans trips, tracks budgets, and manages travel documents through persistent memory.

A Stripe-native usage metering system that ensures precise totals for consumption-based billing models.

agkan is an SQLite-powered CLI task management tool designed for seamless collaboration between human developers and AI agents.








































