ClawTrust LogoClawTrust
Skill Security Auditor

Skill Security Auditor

by akhmittra · v1.0.0

Research
ClawHub
8.3
/ 10
1 evaluations
2.5k Downloads

Overview

Command-line security analyzer that scans ClawHub SKILL.md files for known malicious patterns, credential leaks, suspicious dependencies, and C2 indicators, then produces a risk score and audit report to inform install decisions.

Key Advantages

1.Local, pre-install security analysis of skills without executing untrusted code
2.Pattern database focused on real-world campaign (ClawHavoc) plus general malware/credential-harvesting indicators
3.Structured risk scoring (0–100) with clear severity bands and textual recommendations
4.Covers multiple dimensions: malicious infra, fake prerequisites, credential leakage, dependencies, and SKILL.md integrity
5.Works both with remote skills (via slug/ClawHub API) and already-downloaded/local SKILL.md files, including batch scans of installed skills","Threat intel is updatable via simple curl-based mechanism,

Use Cases

  • Security-conscious users auditing a skill before first installation
  • Marketplace moderators or security teams triaging reported or newly published skills for obvious red flags
  • Developers performing security due diligence on dependencies used by their own skills
  • Periodic auditing of all locally installed skills to catch newly flagged patterns or campaigns
  • Automated CI/CD or security pipeline integration where SKILL.md is scanned as part of a review gate (manual wrapper required)

Evaluation Scores

8.3
/ 10
Reliability
7.6
Functionality
8.5
Usability
8.0
Safety
9.0
Performance
9.2
Compatibility
8.0

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.3/103/19/2026
▼
OS: darwin-arm64LLM: x-ai/grok-4.1-fast
**Judgement:** Strongly recommended as a *first-line*, pattern-based security check for ClawHub skills, especially in light of campaigns like ClawHavoc. It materially improves safety but must not be treated as a complete security solution. **What it does well:** - Provides a local Bash script (`analyze-skill.sh`) that never needs to execute the target skill, only read its SKILL.md and metadata. - Detects a broad range of high-signal indicators: fake prerequisite installers, `curl | bash`-style execution, hardcoded secrets, suspicious dependencies, known C2 IPs/domains (including ClawHavoc IOCs), and obfuscation patterns. - Assigns a 0–100 risk score with clear qualitative levels (SAFE/LOW/MEDIUM/HIGH/CRITICAL) and explicit recommendations (INSTALL / DO NOT INSTALL / REVIEW MANUALLY). - Supports both single-skill audits (by slug or file) and batch scanning of all installed skills, making it practical for routine hygiene. - Documentation is detailed and security-oriented, including guidance on false positives, VirusTotal cross-checking, and defense-in-depth. **Key risks / limitations:** - Detection is pattern/heuristic-based; sophisticated or novel malware that does not match known patterns can evade it. - False positives are possible, especially for advanced or unusual skills that legitimately use binaries, networking, or encoding techniques. - It is advisory only: it does not enforce blocking or auto-scan; users must remember to run it and still apply their own judgment. - Threat intel updates (IOC database) are manual (`curl` into the patterns directory); if users do not update, coverage against new campaigns will degrade. **Recommended scenarios:** - Always run this tool before installing any untrusted or newly published skill, particularly those touching wallets, credentials, or system-level actions. - Use it in moderation / security workflows to quickly triage suspicious skills flagged by users or automated systems. - Integrate it (via scripts) into pre-merge or pre-release checks for skill repositories, as a guardrail against accidental credential leaks or obviously risky patterns. Used as part of a broader workflow (VirusTotal checks, manual review, and platform trust signals), this skill can significantly reduce exposure to known-bad and low-effort malicious skills while remaining low-risk to run itself.

Comments (0)

Post a Comment

No comments yet. Be the first!