Skulk Skill Scanner for Openclaw

A security-focused static analysis tool that scans Openclaw Skills for potential vulnerabilities, malicious patterns, and data exfiltration risks.

adainthelab
v1.0.1
Feb 20, 2026
0
1.7k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install skulk-skill-scanner

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install skulk-skill-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Skulk Skill Scanner?

Skulk Skill Scanner is a critical security utility designed for developers and users of AI agent extensions. It provides a robust layer of defense by performing static analysis on skill folders to identify red flags such as credential theft, destructive commands, and obfuscated code. Whether you are downloading a new skill from ClawHub or preparing your own for publication, this tool ensures that Openclaw Skills adhere to safety standards.

By auditing the codebase and metadata, the scanner assigns a security score that helps users make informed decisions about the trustworthiness of a specific skill. It acts as an automated auditor, catching common attack vectors before they can compromise your workspace or data.

Skulk Skill Scanner Use Cases

  • Auditing a downloaded skill from ClawHub before enabling it in your local environment.
  • Performing a final security check on your own Openclaw Skills prior to public distribution.
  • Integrating automated security scoring into a CI/CD pipeline for agent development.
  • Reviewing the safety of SKILL.md files and associated scripts for hidden prompt injections or malicious instructions.

How Skulk Skill Scanner Works

  1. The scanner receives a directory path pointing to the specific Openclaw Skills folder.
  2. It performs static pattern matching against a library of security rules categorized by severity.
  3. The tool evaluates the presence of sensitive API calls, network requests, and file system operations.
  4. A scoring algorithm deducts points from a base of 100 based on detected critical, high, or medium risks.
  5. The scanner outputs a pass, warn, or fail status along with a detailed report or a concise summary.

Skulk Skill Scanner Setup

To begin using the scanner, ensure you have Node.js installed and access to the skill scripts directory. Run the following command to scan a target directory:

node scripts/scanner.js <path-to-skill> [--verbose] [--json]

For basic auditing of local Openclaw Skills, you can use the summary flag for a quick status check:

node scripts/scanner.js ./skills/my-skill --summary

Skulk Skill Scanner Data Schema & Taxonomy

The scanner organizes its findings based on a severity-weighted scoring system. It evaluates Openclaw Skills using the following data taxonomy:

Severity Identified Risk Factors
Critical Data exfiltration, credential access, safety overrides
High Obfuscation, unknown network access, privilege escalation
Medium Writes outside workspace, unexpected package installs
Info API key references, broad tool access requests

Results can be exported in JSON format for further processing in automated security dashboards.

Skulk Skill Scanner Advanced Features

  • Automated scoring system with CI-friendly exit codes for build pipelines.
  • Customizable Safe Domain Allowlist via the SAFE_DOMAINS array in the configuration script.
  • Multiple output modes including verbose for detailed audits and JSON for machine readability.
  • Self-scan inclusion mode to audit the scanner's own internals when necessary.
  • Static analysis rules specifically tuned for the unique architecture of Openclaw Skills.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*