A specialized security tool that automatically audits Openclaw Skills ZIP files for suspicious patterns and risk levels.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install skill-audit-guardian
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install skill-audit-guardian using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Skill Audit Guardian is a critical security utility designed to protect developers and system administrators from malicious or poorly written code. It serves as a gateway for Openclaw Skills, scanning compressed ZIP archives before they are installed in a production environment. By leveraging heuristic scanning and automated sorting, it ensures that your agent ecosystem remains secure and compliant.
This tool is particularly valuable for teams managing large libraries of Openclaw Skills, providing a consistent and automated way to vet third-party contributions. It transforms the manual task of code review into a streamlined workflow, classifying every package based on its potential risk profile and providing clear, actionable insights through a generated security dashboard.
Ensure your system has the required dependencies: bash, python3, unzip, and rg (ripgrep).
To perform a single audit on a ZIP file:
bash scripts/skill-zip-audit.sh ~/Desktop/skill-drop/example.zip
To enable continuous monitoring and automatic sorting of Openclaw Skills:
bash scripts/skill-zip-watch.sh ~/Desktop/skill-drop
The skill organizes audit results into a specific folder hierarchy and generates a metadata-rich dashboard:
| Directory/File | Description |
|---|---|
~/Desktop/skill-drop/safe |
Verified Openclaw Skills with no high-risk flags. |
~/Desktop/skill-drop/caution |
Packages containing suspicious patterns requiring review. |
~/Desktop/skill-drop/remove |
High-risk Openclaw Skills identified as potentially malicious. |
~/Desktop/skill-drop/failed |
Files that could not be properly unzipped or parsed. |
~/Desktop/skill-audit-pro.html |
A security dashboard providing plain-English reasoning for each flag. |
Loading
A high-performance image generation skill that utilizes the Gemini 3 Pro model via internal Google Antigravity endpoints.

Maintain a clean and discoverable documentation environment through non-destructive maintenance cycles and systematic archiving.

Automate meeting preparation and daily developer status reports by syncing Google Calendar schedules with GitHub commit history.

A specialized utility that strips AI-generated writing patterns and stock phrases from text to ensure a natural, human-sounding tone.

A bridge for AI agents to engage in real-world human discussions and gather sentiment across a network of partner websites via the Protico community widget.

A distributed communication layer that connects multiple OpenClaw instances across different devices into a unified, collaborative agent network.








































