Skill Auditor for Openclaw

A comprehensive security auditing tool designed to detect malicious code, prompt injection, and obfuscated payloads in Openclaw Skills before installation.

aiwithabidi
v2.0.0
Feb 15, 2026
0
652
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install skill-auditor-v2

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install skill-auditor-v2 using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Skill Auditor?

Skill Auditor v2.0 is an essential security utility for developers and administrators using Openclaw Skills. It functions as a multi-layered static analysis engine that scrutinizes skill directories for potential threats, including data exfiltration, shell execution, and filesystem escapes. By merging threat intelligence with automated deobfuscation, it ensures that every skill integrated into your AI agent environment meets a rigorous security standard.

The tool is specifically designed to handle the unique vulnerabilities associated with AI agents, such as prompt injection and social engineering tactics hidden within metadata. Whether you are auditing third-party contributions or verifying your own code before publication, Skill Auditor provides a transparent, score-based assessment of a skill's safety profile.

Skill Auditor Use Cases

  • Scanning third-party Openclaw Skills from ClawHub or GitHub before local deployment.
  • Reviewing skill updates for security regressions or newly introduced vulnerabilities.
  • Verifying your own skills for compliance with security best practices before public release.
  • Triggering automated security reviews when an agent detects suspicious requests like "is this skill safe?" or "check security".

How Skill Auditor Works

  1. The scanner initializes by loading the Indicator of Compromise (IoC) database containing known malicious IPs, domains, and regex patterns.
  2. It performs Layer 1 Static Pattern Analysis to detect high-risk operations such as network calls, environment variable access, and dynamic imports.
  3. Layer 2 Deobfuscation kicks in to extract and decode Base64 or Hex-encoded strings, which are then re-scanned for hidden malicious payloads.
  4. Layer 3 Threat Intelligence maps every finding to specific MITRE ATT&CK IDs and checks against the integrated IoC database.
  5. The system calculates a final 0-100 numeric risk score based on the severity and context of the findings, including special checks for typosquatting and zero-width characters.

Skill Auditor Setup

To get started with auditing your Openclaw Skills, ensure you have python3 installed and follow these steps:

  1. Navigate to your local skill directory and run the audit script:
python3 ./scripts/audit_skill.py /path/to/skill --human
  1. To audit a skill directly from ClawHub using its slug:
python3 ./scripts/audit_skill.py --slug skill-name --human
  1. Use the quarantine workflow for a secure audit followed by an installation prompt:
bash ./scripts/quarantine.sh /path/to/skill

Skill Auditor Data Schema & Taxonomy

Skill Auditor organizes its security intelligence and findings using the following structure:

Component Description
references/ioc-database.json Structured threat data including malicious IPs, domains, and signature patterns.
references/known-patterns.md Human-readable documentation of the threat patterns the scanner looks for.
SHA256 Inventory A generated inventory of file hashes to ensure integrity during the audit lifecycle.
MITRE ATT&CK Mapping Metadata tags on findings that align with industry-standard cybersecurity frameworks.

Skill Auditor Advanced Features

  • Recursive Deobfuscation: Automatically decodes Base64 and Hex payloads and re-runs the entire scan on the decoded content.
  • Prompt Injection Detection: Specific patterns designed to identify attempts to hijack agent behavior through specialized instruction sets.
  • Typosquatting Analysis: Uses Levenshtein distance to detect package names that impersonate popular Openclaw Skills.
  • Comment-Context Awareness: Reduces the risk score if a suspicious pattern is found within a comment rather than executable code.
  • Whitelist System: Supports a custom whitelist to reduce false positives for known-safe binaries or internal domains.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*