clawned for Openclaw

A security-focused agent that inventories installed skills and performs threat analysis to ensure your AI ecosystem remains secure.

uttamnest
v1.0.1
Feb 24, 2026
0
1.3k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install skill-sec

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install skill-sec using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is clawned?

Clawned is a specialized security agent designed to provide transparency and protection for your local development environment. It functions by scanning and inventorying all installed Openclaw Skills, ensuring that every tool in your workspace is identified and audited. By syncing this data to a centralized dashboard, developers gain a holistic view of their security posture.

Beyond simple inventorying, Clawned offers deep analysis capabilities for Openclaw Skills by inspecting source code for vulnerabilities while strictly adhering to privacy standards. It is an essential utility for developers who need to balance the power of autonomous AI agents with the security requirements of professional software environments.

clawned Use Cases

  • Periodic auditing of Openclaw Skills to maintain a clean and authorized workspace.
  • Deep scanning specific skill directories for security vulnerabilities before deployment.
  • Automated security reporting to a centralized dashboard for team-wide visibility.
  • Verifying the integrity of newly installed agents through local inventory checks.

How clawned Works

  1. The agent reads the local Openclaw configuration to locate all active skill directories.
  2. It performs an inventory scan to collect metadata such as the skill name, version, and owner.
  3. Collected metadata is synchronized with the Clawned dashboard for real-time monitoring.
  4. When a manual scan is triggered, the agent performs a source code analysis of the specific skill path.
  5. Security results are processed and uploaded to the server, allowing for centralized threat management.

clawned Setup

To set up the security agent, you must configure your API key in the openclaw.json file to allow the agent to communicate with your dashboard.

{
  "skills": {
    "entries": {
      "clawned": {
        "enabled": true,
        "env": {
          "CLAWNED_API_KEY": "cg_your_api_key_here",
          "CLAWNED_SERVER": "https://api.clawned.io"
        }
      }
    }
  }
}

Verify the agent is running correctly with the status command:

python3 {baseDir}/scripts/agent.py status

clawned Data Schema & Taxonomy

The agent prioritizes security and privacy by only accessing necessary metadata during standard operations. Below is the data handling schema for Openclaw Skills:

Data Category Field Details Privacy Level
Skill Metadata Name, Owner, Slug, Version Syncs to Dashboard
Source Code .py, .js, .md file contents Only via explicit scan --path
Exclusions .env files and system secrets Never read or transmitted
Configuration Skill directory paths Read locally only

clawned Advanced Features

  • Support for OpenClaw cron jobs to enable automated security syncing every 6 hours.
  • Explicit path scanning for deep source code analysis of individual Openclaw Skills.
  • Customizable server endpoints via the CLAWNED_SERVER environment variable.
  • Privacy-preserving metadata-only sync mode that excludes all file contents by default.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*