ScamShield Verifier for Openclaw

A security-first skill that verifies repositories, wallet addresses, and smart contracts using the ScamShield Sentinel API to prevent malicious interactions.

marcodzano-lgtm
v1.0.3
Feb 21, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install scamshield-verifier

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install scamshield-verifier using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is ScamShield Verifier?

The ScamShield Verifier is a critical security layer designed for agents operating in high-risk Web3 and AI environments. As a key component of the Openclaw Skills ecosystem, it ensures that your agent never interacts with malicious code or fraudulent contracts by vetting every target against a global threat intelligence database.

By leveraging ephemeral processing on Base L2, this skill provides real-time safety checks without compromising local data privacy. It acts as a gatekeeper for developers and AI operators, providing an automated way to verify the reputation of repository names, wallet addresses, and transaction hashes before any action is taken.

ScamShield Verifier Use Cases

  • Validating the safety of a GitHub repository before cloning it to a local environment.
  • Verifying the reputation of a Web3 wallet address before initiating a transaction.
  • Vetting third-party Openclaw Skills to ensure they are not flagged as malicious.
  • Checking smart contract addresses for known security threats or exit scams.

How ScamShield Verifier Works

  1. The agent identifies a potential risk target, such as a repository name, wallet address, or transaction hash.
  2. The skill initiates a secure GET request to the ScamShield Sentinel API endpoint with the target identifier.
  3. The API processes the target against its global database of threat intelligence hosted on Base L2.
  4. If the API returns a safe status, the agent continues its task; if malicious, the skill forces an immediate abort and issues a high-priority warning to the user.

ScamShield Verifier Setup

To integrate this security layer into your Openclaw Skills workflow, you must provide a valid API key through your environment variables.

export SCAMSHIELD_API_KEY="your_api_key_here"

The agent uses this key in the Authorization header for all verification requests.

ScamShield Verifier Data Schema & Taxonomy

The ScamShield Verifier operates with a strict minimal-data policy to ensure privacy.

Parameter Description Requirement
target Short identifier (repo name, wallet address, or hash) Required
status Security assessment result (safe/malicious) Response
SCAMSHIELD_API_KEY Bearer token for API authentication Env Variable

Note: The skill is strictly prohibited from transmitting source code, private keys, or sensitive local files.

ScamShield Verifier Advanced Features

  • Proactive Execution Blocking: Automatically halts the agent's workflow if a malicious status is detected to prevent compromised operations.
  • Base L2 Threat Intel: Utilizes decentralized intelligence for verified, up-to-date threat data.
  • Zero-Knowledge Privacy: Only small identifiers are sent to the API, ensuring your project code remains local and secure within Openclaw Skills.
  • Seamless Web3 Integration: Designed specifically for agents interacting with blockchain protocols and smart contracts.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Requires
Github Stars: 0
forks: 0

Featured*