Skill-Scan: Security Auditor for Agent Skills for Openclaw

A multi-layered security scanner designed to audit Openclaw Skills for malicious code, prompt injection, and behavioral threats before they are enabled.

dgriffin831
v1.0.0
Feb 3, 2026
3
2.4k
7

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install skill-scan

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install skill-scan using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Skill-Scan: Security Auditor for Agent Skills?

Skill-Scan serves as a critical security gateway for developers and teams using AI agents. It performs deep static and dynamic analysis on skill packages to identify execution threats, credential theft, and data exfiltration attempts. By providing a comprehensive audit of code before execution, it ensures that your Openclaw Skills environment remains secure and compliant with organizational safety standards.

The tool utilizes six distinct analysis layers, ranging from pattern matching and AST evasion detection to LLM-powered deep inspection. This multi-faceted approach allows it to identify not just simple malware, but also sophisticated prompt injection techniques and misaligned behaviors that could compromise an agent's integrity.

Skill-Scan: Security Auditor for Agent Skills Use Cases

  • Automatically auditing third-party Openclaw Skills from ClawHub before local installation.
  • Performing periodic security reviews of already-installed agent tools to detect updated threats.
  • Integrating security gates into CI/CD pipelines for custom skill development.
  • Scanning shared or public repositories to ensure skill safety before team-wide deployment.
  • Detecting hidden prompt injection and jailbreak attempts within skill metadata.

How Skill-Scan: Security Auditor for Agent Skills Works

  1. The scanner initializes a multi-layered analysis starting with pattern matching and AST inspection to identify obfuscated code.
  2. It evaluates the skill against over 60 detection rules covering network calls, filesystem manipulation, and credential access.
  3. The tool performs a context-aware risk assessment to reduce false positives for legitimate API-heavy skills.
  4. Optional LLM-powered deep inspection (via OpenAI or Anthropic) analyzes the semantic intent and alignment of the skill logic.
  5. A final risk score (0-100) is generated, accompanied by a detailed findings report and a binary exit code to allow or block the installation workflow.

Skill-Scan: Security Auditor for Agent Skills Setup

Skill-Scan requires Python 3.10 or higher. For LLM-powered deep analysis, ensure an API key is available in your environment.

# Standard scan of a remote skill by slug
skill-scan scan-hub <skill-slug>

# Scan a local skill directory before enabling it
skill-scan scan /path/to/skill

# Audit all installed Openclaw Skills in a directory
skill-scan batch /path/to/skills-directory

# Run with automatic LLM escalation for suspicious patterns
skill-scan scan-hub <slug> --llm-auto

Skill-Scan: Security Auditor for Agent Skills Data Schema & Taxonomy

The scanner categorizes threats and provides structured feedback for Openclaw Skills auditing:

Category Description
Execution Use of eval(), exec(), or unauthorized child processes
Credentials Attempts to access .env files, API keys, or private tokens
Exfiltration Unauthorized use of fetch, axios, or socket connections
Injection Detection of jailbreaks, homoglyphs, or roleplay framing

Results can be exported via --json for programmatic integration or --compact for CLI summaries.

Skill-Scan: Security Auditor for Agent Skills Advanced Features

  • Context-aware scoring that differentiates between malicious exfiltration and legitimate API communication.
  • Direct ClawHub integration for scanning remote Openclaw Skills without downloading them manually.
  • Multiple LLM provider support (GPT-4o-mini, Claude 3.5 Sonnet) for semantic alignment verification.
  • Automated workflow integration through exit codes (0 for safe, 1 for risky) suitable for shell scripting.
  • Batch scanning capabilities for high-volume security audits of entire skill libraries.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*