A security-focused static analysis tool that scans Openclaw Skills for potential vulnerabilities, malicious patterns, and data exfiltration risks.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install skulk-skill-scanner
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install skulk-skill-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Skulk Skill Scanner is a critical security utility designed for developers and users of AI agent extensions. It provides a robust layer of defense by performing static analysis on skill folders to identify red flags such as credential theft, destructive commands, and obfuscated code. Whether you are downloading a new skill from ClawHub or preparing your own for publication, this tool ensures that Openclaw Skills adhere to safety standards.
By auditing the codebase and metadata, the scanner assigns a security score that helps users make informed decisions about the trustworthiness of a specific skill. It acts as an automated auditor, catching common attack vectors before they can compromise your workspace or data.
To begin using the scanner, ensure you have Node.js installed and access to the skill scripts directory. Run the following command to scan a target directory:
node scripts/scanner.js <path-to-skill> [--verbose] [--json]
For basic auditing of local Openclaw Skills, you can use the summary flag for a quick status check:
node scripts/scanner.js ./skills/my-skill --summary
The scanner organizes its findings based on a severity-weighted scoring system. It evaluates Openclaw Skills using the following data taxonomy:
| Severity | Identified Risk Factors |
|---|---|
| Critical | Data exfiltration, credential access, safety overrides |
| High | Obfuscation, unknown network access, privilege escalation |
| Medium | Writes outside workspace, unexpected package installs |
| Info | API key references, broad tool access requests |
Results can be exported in JSON format for further processing in automated security dashboards.
Loading
A deterministic framework for standardizing API credential handling and startup authentication checks to prevent session regressions.

A professional open-source market making framework for AI agents supporting multi-exchange grid trading and real-time market data.

An automated grid trading engine for OpenMM that executes buy and sell orders around a center price to capture market volatility.

An interactive configuration guide for setting up secure API credentials and environment variables for the OpenMM trading framework.

A real-time momentum scoring and market intelligence engine for over 6,500 stocks and crypto assets.

A specialized AI agent skill that transforms chaotic X bookmarks into organized, searchable intelligence with automated summaries and channel delivery.








































