Skill Scanner for Openclaw

A specialized security auditing tool designed to detect malware, spyware, and malicious code patterns within AI agent skills.

bvinci1-design
v0.1.2
Jan 29, 2026
24
18.5k
168

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install skill-scanner

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install skill-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Skill Scanner?

Skill Scanner is a robust security audit tool specifically engineered for the Openclaw Skills ecosystem. It provides developers and users with a critical safety layer by scanning skill folders for malicious patterns including data exfiltration, system modification attempts, and crypto-mining indicators. By analyzing code before installation, this tool ensures that your AI coding environment remains secure and free from unauthorized backdoors or obfuscated threats.

This utility serves as a first line of defense when integrating new capabilities into your agent workflow. It focuses on identifying high-risk behaviors such as arbitrary code execution and hidden exfiltration routes, making Openclaw Skills safer for both personal and enterprise use cases.

Skill Scanner Use Cases

  • Pre-installation security audits for new Openclaw Skills.
  • Identifying hidden crypto-mining scripts or spyware in downloaded MCP skills.
  • Detecting potential data exfiltration routes within third-party integrations.
  • Generating security compliance reports in Markdown or JSON for development teams.
  • Performing high-level vulnerability assessments using the Streamlit Web UI.

How Skill Scanner Works

  1. Point the scanner to the target directory containing the Openclaw Skills you wish to audit.
  2. The engine performs a static analysis of the source code, searching for known malicious patterns and risky system calls.
  3. It evaluates the code for obfuscation techniques that might hide backdoors or unauthorized system modifications.
  4. The tool generates a detailed report highlighting potential threats and risk levels.
  5. Results are delivered via the command line, a structured JSON file, or an interactive Streamlit dashboard.

Skill Scanner Setup

To get started with Skill Scanner for your Openclaw Skills, ensure you have Python 3.7+ installed. No additional dependencies are required for the core CLI tool.

# Run a scan on a specific skill folder via CLI
python skill_scanner.py /path/to/skill-folder

# Optional: Launch the Web UI
pip install streamlit
streamlit run streamlit_ui.py

Skill Scanner Data Schema & Taxonomy

The tool processes Openclaw Skills source files and outputs structured security data as shown below:

Attribute Description
Threat Level Categorization of risk (e.g., Critical, High, Warning, Info) based on detected patterns.
Pattern Match The specific code snippet or signature that triggered the security flag.
File Path The relative location of the detected risk within the skill directory.
Output Formats Generates reports in Markdown for readability or JSON for integration into CI/CD pipelines.

Skill Scanner Advanced Features

  • Seamless integration with Clawdbot natural language commands for on-the-fly audits of Openclaw Skills.
  • Comprehensive detection of arbitrary code execution risks and unauthorized system modification attempts.
  • Support for identifying complex obfuscation techniques used to hide malicious logic.
  • Flexible reporting options suitable for both individual developers and enterprise security pipelines.
  • Standalone execution with zero external dependencies for the core scanning engine to ensure the scanner itself is secure.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*