A specialized security auditing tool designed to detect malware, spyware, and malicious code patterns within AI agent skills.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install skill-scanner
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install skill-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Skill Scanner is a robust security audit tool specifically engineered for the Openclaw Skills ecosystem. It provides developers and users with a critical safety layer by scanning skill folders for malicious patterns including data exfiltration, system modification attempts, and crypto-mining indicators. By analyzing code before installation, this tool ensures that your AI coding environment remains secure and free from unauthorized backdoors or obfuscated threats.
This utility serves as a first line of defense when integrating new capabilities into your agent workflow. It focuses on identifying high-risk behaviors such as arbitrary code execution and hidden exfiltration routes, making Openclaw Skills safer for both personal and enterprise use cases.
To get started with Skill Scanner for your Openclaw Skills, ensure you have Python 3.7+ installed. No additional dependencies are required for the core CLI tool.
# Run a scan on a specific skill folder via CLI
python skill_scanner.py /path/to/skill-folder
# Optional: Launch the Web UI
pip install streamlit
streamlit run streamlit_ui.py
The tool processes Openclaw Skills source files and outputs structured security data as shown below:
| Attribute | Description |
|---|---|
| Threat Level | Categorization of risk (e.g., Critical, High, Warning, Info) based on detected patterns. |
| Pattern Match | The specific code snippet or signature that triggered the security flag. |
| File Path | The relative location of the detected risk within the skill directory. |
| Output Formats | Generates reports in Markdown for readability or JSON for integration into CI/CD pipelines. |
Loading
ClawDNA is a specialized utility that synthesizes historical AI agent interactions into structured, privacy-safe public personas and wiki-style profiles.

A professional-grade AI investment assistant providing deep multi-market stock analysis and real-time sentiment tracking.

Control Chrome tabs, interact with web elements, and automate complex browser workflows using an AI-powered MCP bridge and extension.

TorrentClaw is a powerful AI agent skill for searching, filtering, and downloading high-quality movie and TV torrents with automated local client integration.

A powerful AI skill that aggregates, deduplicates, and summarizes real-time video game news from leading global outlets.

A framework for implementing persistent, hierarchical memory in AI agents using structured Markdown and automated Bash workflows.








































