Skill-Scanner-Pro for Openclaw

A robust security auditing tool designed to identify malware, spyware, and vulnerabilities within AI agent skills and MCP tools.

gravitypoet
v0.1.4
Feb 28, 2026
0
421
2

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install skill-scanner-pro

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install skill-scanner-pro using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Skill-Scanner-Pro?

Skill-Scanner-Pro is a specialized security audit tool designed to safeguard users of Openclaw Skills and MCP-compatible agents. It functions as a preventative layer, scanning code directories for malicious patterns including data exfiltration, backdoors, and crypto-mining indicators.

By leveraging heuristic analysis, the tool identifies potential threats in scripts and documentation before they can compromise your system. This pro edition is optimized to provide high-fidelity results with minimal false positives, ensuring that your Openclaw Skills remain secure and reliable.

Skill-Scanner-Pro Use Cases

  • Perform a security audit on newly downloaded Openclaw Skills before adding them to your agent environment.
  • Detect hidden crypto-mining scripts or unauthorized data exfiltration attempts in third-party repositories.
  • Generate compliance-ready security reports in JSON or Markdown for organizational safety records.
  • Use the integrated Web UI to visually inspect the security posture of multiple agent tools simultaneously.

How Skill-Scanner-Pro Works

  1. The user provides a path to a skill folder via the command line or the Streamlit Web UI.
  2. The scanner initializes a heuristic engine to analyze code patterns across all supported file types.
  3. Documentation files are filtered to only scan fenced code blocks, significantly reducing false positive triggers.
  4. The tool identifies specific risks such as arbitrary code execution, system modification attempts, and obfuscated backdoors.
  5. A comprehensive report is generated, highlighting detected threats and providing a safety summary.

Skill-Scanner-Pro Setup

Skill-Scanner-Pro requires Python 3.7 or higher. No additional core dependencies are required for the CLI, but Streamlit is needed for the Web UI.

# Navigate to the tool directory
cd skill-scanner-pro

# Optional: Install dependencies for the Web UI
pip install streamlit

# Run a scan via CLI
python skill_scanner.py /path/to/your-skill-folder

# Launch the Web UI
streamlit run streamlit_ui.py

Skill-Scanner-Pro Data Schema & Taxonomy

The tool organizes its findings into structured reports for easy ingestion by other security workflows.

  • Scan Results: Detailed logs of detected patterns and their file locations.
  • Report Formats: Supports both human-readable Markdown and machine-parseable JSON.
  • Target Scope: Automatically skips binary files and noisy directories (e.g., .git) to focus on actionable source code.
  • Metadata Taxonomy: Categorizes threats into Malware, Spyware, Crypto-mining, and Obfuscation classes.

Skill-Scanner-Pro Advanced Features

  • Enhanced detection logic specifically tuned for Openclaw Skills to minimize noise in README and documentation files.
  • Multi-format output support allowing for seamless integration into automated DevSecOps pipelines.
  • Native Streamlit integration providing a user-friendly dashboard for non-technical users to verify skill safety.
  • Support for identifying complex system modification attempts and unauthorized network requests.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*