Skill Security Scanner for Openclaw

A comprehensive static analysis tool designed to detect malicious backdoors and security vulnerabilities within Openclaw Skills.

cookiemikeliu
v1.0.0
Feb 27, 2026
0
1k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install skill-security-scanner-clean

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install skill-security-scanner-clean using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Skill Security Scanner?

The Skill Security Scanner is an essential utility for developers and users who want to maintain a secure environment while extending their AI agents. It performs deep static analysis on skill source code—including Python, JavaScript, and Shell scripts—to identify dangerous patterns such as unauthorized code execution, data exfiltration, and system compromises. By providing a clear safety verdict, it ensures that every one of your Openclaw Skills is audited for integrity before it ever touches your local system.

This scanner acts as a gatekeeper for the ecosystem, protecting users from common threats like credential theft, cryptojacking, and hidden spyware. Whether you are a developer building new tools or a power user installing community contributions, this scanner provides the technical transparency needed to trust your Openclaw Skills.

Skill Security Scanner Use Cases

  • Auditing third-party Openclaw Skills for malicious backdoors prior to installation.
  • Scanning skill updates to ensure no new security risks or suspicious network requests were introduced.
  • Automating security checks in CI/CD pipelines to validate the safety of developed Openclaw Skills.
  • Identifying accidental inclusion of sensitive environment variable access or unsafe deserialization in code.

How Skill Security Scanner Works

  1. The scanner targets a specific directory containing the source code for Openclaw Skills.
  2. It executes a series of detection rules that look for critical, high, medium, and low-risk signatures.
  3. The tool analyzes system calls, network request patterns, and obfuscated blocks to determine intent.
  4. A security score is generated alongside a verdict (PASS, REVIEW, WARNING, or REJECT).
  5. The user reviews the generated JSON or Markdown report to make an informed installation decision.

Skill Security Scanner Setup

To begin securing your Openclaw Skills, use the following commands from your terminal:

# Run a basic security scan on a skill folder
python scripts/security_scanner.py /path/to/skill

# Use strict mode to catch more subtle suspicious patterns
python scripts/security_scanner.py /path/to/skill --strict

# Generate a detailed Markdown report for manual auditing
python scripts/security_scanner.py /path/to/skill --format markdown -o report.md

Skill Security Scanner Data Schema & Taxonomy

The scanner generates structured data to help categorize risks within Openclaw Skills. The following schema outlines the reporting structure:

Component Description
Verdict The final safety level: PASS (Safe), REVIEW (Check), WARNING (High-risk), or REJECT (Dangerous)
Security Score A 0-100 rating where higher scores indicate lower risk levels
Rule IDs Specific identifiers for threats (e.g., EXEC001 for code execution, NET002 for raw sockets)
Exit Codes Standardized codes (0, 1, 2) for integration into automated installation scripts

Skill Security Scanner Advanced Features

  • Strict Mode Analysis: Increases sensitivity to catch obfuscated code and rare suspicious patterns.
  • Automated Installation Blocking: Integration-ready Python snippets to stop the setup of Openclaw Skills if a REJECT verdict is found.
  • Custom Export Formats: Support for both JSON and Markdown outputs to fit into various developer workflows.
  • Comprehensive Rule Taxonomy: Pre-defined rules covering everything from keyloggers to cryptocurrency miners.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*