A comprehensive static analysis tool designed to detect malicious backdoors and security vulnerabilities within Openclaw Skills.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install skill-security-scanner-clean
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install skill-security-scanner-clean using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Skill Security Scanner is an essential utility for developers and users who want to maintain a secure environment while extending their AI agents. It performs deep static analysis on skill source code—including Python, JavaScript, and Shell scripts—to identify dangerous patterns such as unauthorized code execution, data exfiltration, and system compromises. By providing a clear safety verdict, it ensures that every one of your Openclaw Skills is audited for integrity before it ever touches your local system.
This scanner acts as a gatekeeper for the ecosystem, protecting users from common threats like credential theft, cryptojacking, and hidden spyware. Whether you are a developer building new tools or a power user installing community contributions, this scanner provides the technical transparency needed to trust your Openclaw Skills.
To begin securing your Openclaw Skills, use the following commands from your terminal:
# Run a basic security scan on a skill folder
python scripts/security_scanner.py /path/to/skill
# Use strict mode to catch more subtle suspicious patterns
python scripts/security_scanner.py /path/to/skill --strict
# Generate a detailed Markdown report for manual auditing
python scripts/security_scanner.py /path/to/skill --format markdown -o report.md
The scanner generates structured data to help categorize risks within Openclaw Skills. The following schema outlines the reporting structure:
| Component | Description |
|---|---|
| Verdict | The final safety level: PASS (Safe), REVIEW (Check), WARNING (High-risk), or REJECT (Dangerous) |
| Security Score | A 0-100 rating where higher scores indicate lower risk levels |
| Rule IDs | Specific identifiers for threats (e.g., EXEC001 for code execution, NET002 for raw sockets) |
| Exit Codes | Standardized codes (0, 1, 2) for integration into automated installation scripts |
Loading
A powerful domain-specific language for orchestrating multi-model AI workflows with specialized engines for strategy, science, and culinary arts.

NOUS is a visible thinking engine that transforms AI from a black-box assistant into a transparent cognitive process you can steer in real time.

A technical mentor skill that validates commands, identifies learning gaps, and ensures project safety through mandatory backups.

MasterSwarm is a high-performance AI orchestration skill that leverages 15 specialized engines to provide deep, multi-perspective analysis of documents and complex queries.

A shared 256x256 pixel environment where agents study emergent social dynamics through scarce, high-impact actions.

Manage Canva designs, assets, and folders programmatically via the Connect API integration.








































