A security-focused gateway that scans and validates Openclaw Skills using the ClawDex API before allowing installation.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install secure-install
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install secure-install using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Secure Skill Installer is an essential security layer designed to protect your local environment when expanding your AI agent's capabilities. By acting as a verified gatekeeper, it ensures that any new Openclaw Skills you wish to add are thoroughly vetted against known threats. This skill bridges the gap between discovery and deployment, providing peace of mind for developers who prioritize system integrity.
Leveraging the powerful ClawDex API by koi.ai, the Secure Skill Installer provides real-time security verdicts. It automates the risk assessment process, categorizing incoming code as benign, unknown, or malicious, and enforces a strict human-in-the-loop approval workflow. This ensures that no unauthorized or dangerous Openclaw Skills can be executed without explicit user consent and verified safety reports.
scanSkillApi, querying the ClawDex API by koi.ai for a security verdict.executeClawhubInstall function to finalize the setup.To use this skill, ensure you have the clawhub binary installed and accessible in your system path. This skill acts as a wrapper around the standard installation process to add a security layer for all your Openclaw Skills.
# Verify clawhub installation
clawhub --version
# Usage within your AI agent
secure-install <skill-name>
The Secure Skill Installer utilizes a structured response format from the ClawDex API to determine the safety of Openclaw Skills.
| Property | Type | Description |
|---|---|---|
verdict |
String | The safety status: "malicious", "unknown", or "benign". |
skill-name |
String | The target identifier for the skill being scanned. |
approval_status |
Boolean | Whether the user has explicitly granted permission to install. |
Loading
A comprehensive automation tool for downloading Xiaohongshu videos and generating full resource packs including transcripts and AI summaries.

A powerful content extraction tool that converts complex web pages into clean, AI-ready markdown using the Jina Reader API.

An AI-driven cryptocurrency trading bot for Upbit featuring real-time monitoring, GLM-4.7 analysis, and automated execution.

A powerful cost-reduction tool for Openclaw Skills that optimizes token usage through intelligent model routing and local heartbeat providers.

A natural language interface to query and analyze your WhatPulse computer usage statistics using a local SQLite database.

A lightweight monitoring tool designed to track the health, logs, and resource performance of n8n instances running in Docker containers.








































