2.5k Downloads
Overview
Command-line security analyzer that scans ClawHub SKILL.md files for known malicious patterns, credential leaks, suspicious dependencies, and C2 indicators, then produces a risk score and audit report to inform install decisions.
Key Advantages
1.Local, pre-install security analysis of skills without executing untrusted code
2.Pattern database focused on real-world campaign (ClawHavoc) plus general malware/credential-harvesting indicators
3.Structured risk scoring (0–100) with clear severity bands and textual recommendations
4.Covers multiple dimensions: malicious infra, fake prerequisites, credential leakage, dependencies, and SKILL.md integrity
5.Works both with remote skills (via slug/ClawHub API) and already-downloaded/local SKILL.md files, including batch scans of installed skills","Threat intel is updatable via simple curl-based mechanism,
Use Cases
- Security-conscious users auditing a skill before first installation
- Marketplace moderators or security teams triaging reported or newly published skills for obvious red flags
- Developers performing security due diligence on dependencies used by their own skills
- Periodic auditing of all locally installed skills to catch newly flagged patterns or campaigns
- Automated CI/CD or security pipeline integration where SKILL.md is scanned as part of a review gate (manual wrapper required)
Evaluation Scores
8.3
/ 10
Reliability
7.6
Functionality
8.5
Usability
8.0
Safety
9.0
Performance
9.2
Compatibility
8.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.3/103/19/2026▼
OS: darwin-arm64LLM: x-ai/grok-4.1-fast
**Judgement:** Strongly recommended as a *first-line*, pattern-based security check for ClawHub skills, especially in light of campaigns like ClawHavoc. It materially improves safety but must not be treated as a complete security solution.
**What it does well:**
- Provides a local Bash script (`analyze-skill.sh`) that never needs to execute the target skill, only read its SKILL.md and metadata.
- Detects a broad range of high-signal indicators: fake prerequisite installers, `curl | bash`-style execution, hardcoded secrets, suspicious dependencies, known C2 IPs/domains (including ClawHavoc IOCs), and obfuscation patterns.
- Assigns a 0–100 risk score with clear qualitative levels (SAFE/LOW/MEDIUM/HIGH/CRITICAL) and explicit recommendations (INSTALL / DO NOT INSTALL / REVIEW MANUALLY).
- Supports both single-skill audits (by slug or file) and batch scanning of all installed skills, making it practical for routine hygiene.
- Documentation is detailed and security-oriented, including guidance on false positives, VirusTotal cross-checking, and defense-in-depth.
**Key risks / limitations:**
- Detection is pattern/heuristic-based; sophisticated or novel malware that does not match known patterns can evade it.
- False positives are possible, especially for advanced or unusual skills that legitimately use binaries, networking, or encoding techniques.
- It is advisory only: it does not enforce blocking or auto-scan; users must remember to run it and still apply their own judgment.
- Threat intel updates (IOC database) are manual (`curl` into the patterns directory); if users do not update, coverage against new campaigns will degrade.
**Recommended scenarios:**
- Always run this tool before installing any untrusted or newly published skill, particularly those touching wallets, credentials, or system-level actions.
- Use it in moderation / security workflows to quickly triage suspicious skills flagged by users or automated systems.
- Integrate it (via scripts) into pre-merge or pre-release checks for skill repositories, as a guardrail against accidental credential leaks or obviously risky patterns.
Used as part of a broader workflow (VirusTotal checks, manual review, and platform trust signals), this skill can significantly reduce exposure to known-bad and low-effort malicious skills while remaining low-risk to run itself.
Comments (0)
No comments yet. Be the first!