Secure Skill Installer for Openclaw

A security-focused gateway that scans and validates Openclaw Skills using the ClawDex API before allowing installation.

smintlife
v1.0.1
Feb 5, 2026
0
0
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install secure-install

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install secure-install using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Secure Skill Installer?

The Secure Skill Installer is an essential security layer designed to protect your local environment when expanding your AI agent's capabilities. By acting as a verified gatekeeper, it ensures that any new Openclaw Skills you wish to add are thoroughly vetted against known threats. This skill bridges the gap between discovery and deployment, providing peace of mind for developers who prioritize system integrity.

Leveraging the powerful ClawDex API by koi.ai, the Secure Skill Installer provides real-time security verdicts. It automates the risk assessment process, categorizing incoming code as benign, unknown, or malicious, and enforces a strict human-in-the-loop approval workflow. This ensures that no unauthorized or dangerous Openclaw Skills can be executed without explicit user consent and verified safety reports.

Secure Skill Installer Use Cases

  • Safely installing third-party Openclaw Skills from community repositories.
  • Implementing a mandatory security audit for AI agent capabilities in enterprise environments.
  • Preventing the execution of malicious scripts by blocking flagged packages automatically.
  • Verifying the safety status of unknown skills through the ClawDex API before testing.

How Secure Skill Installer Works

  1. The user triggers the workflow by providing the name of the desired Openclaw Skills to the installer.
  2. The skill executes a scan via the scanSkillApi, querying the ClawDex API by koi.ai for a security verdict.
  3. The system interprets the verdict: malicious results trigger an immediate block, unknown results issue a high-risk warning, and benign results confirm safety.
  4. A detailed security report is presented to the user, including the specific verdict and safety warnings.
  5. The skill waits for an explicit 'Yes' from the user before proceeding.
  6. Only after manual approval does the agent call the executeClawhubInstall function to finalize the setup.

Secure Skill Installer Setup

To use this skill, ensure you have the clawhub binary installed and accessible in your system path. This skill acts as a wrapper around the standard installation process to add a security layer for all your Openclaw Skills.

# Verify clawhub installation
clawhub --version

# Usage within your AI agent
secure-install <skill-name>

Secure Skill Installer Data Schema & Taxonomy

The Secure Skill Installer utilizes a structured response format from the ClawDex API to determine the safety of Openclaw Skills.

Property Type Description
verdict String The safety status: "malicious", "unknown", or "benign".
skill-name String The target identifier for the skill being scanned.
approval_status Boolean Whether the user has explicitly granted permission to install.

Secure Skill Installer Advanced Features

  • Strict Malicious Blocking: Automatically terminates the installation process if the ClawDex API returns a malicious verdict.
  • Interactive Risk Assessment: Provides clear, actionable warnings for Openclaw Skills with an unknown security status.
  • API-Driven Intelligence: Directly integrates with koi.ai threat intelligence for up-to-the-minute security data.
  • Audit Trail: Encourages a secure-by-default workflow for all AI agent capability expansions.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*