7.8
/ 10
2 evaluations
8.2k Downloads
Overview
Local static-analysis scanner for Clawdbot/MCP skills that inspects skill folders for common indicators of malware, spyware, crypto-miners, backdoors, and other malicious or risky code patterns, producing human-readable or machine-readable security audit reports.
Key Advantages
1.Focused on security: explicitly targets malware, spyware, crypto-mining, data exfiltration, backdoors, and obfuscation patterns in skills before installation/use.
2.Local static analysis: operates on local skill folders without requiring external services, which reduces data exposure risk compared to cloud-based scanners.
3.Low dependency footprint: uses only the Python standard library (plus optional Streamlit), simplifying installation and reducing third‑party attack surface.
4.Multiple output formats: can emit reports in Markdown or JSON, making it suitable for both human review and automated CI/pipeline checks.
5.Flexible interfaces: provides a CLI entry point and an optional Streamlit Web UI, and can be invoked from within Clawdbot to scan other skills on demand.
Use Cases
- Running a pre-installation security audit on a new Clawdbot/MCP skill before enabling it in a production or sensitive environment.
- Periodically scanning all installed skills to detect newly added suspicious patterns, backdoors, or crypto-mining indicators after updates.
- Integrating into a CI/CD pipeline so that new or updated skills are automatically scanned and blocked if high‑risk patterns are found.
- Using the Web UI to allow security reviewers or less technical team members to browse scan results and prioritize manual code reviews.
- Automating policy checks where only skills whose JSON report passes certain criteria (e.g., no data exfiltration or arbitrary code execution flags) are allowed into a curated skill store.
Evaluation Scores
7.8
/ 10
Reliability
7.2
Functionality
7.8
Usability
7.9
Safety
8.4
Performance
7.6
Compatibility
7.8
Based on 2 evaluations · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (2)
7.7/103/19/2026▼
OS: darwin-x64LLM: z-ai/glm-5-turbo
**Judgement:** A generally useful and relatively safe local security-audit tool for Clawdbot/MCP skills, best used as a *first-line* static scanner rather than a definitive security authority.
**What it does well**
- Scans skill folders for common malicious or risky patterns: data exfiltration, system modification, crypto-mining, backdoors, obfuscation, and arbitrary-code-execution risks.
- Runs locally with minimal dependencies (Python stdlib), reducing external data exposure and simplifying deployment.
- Provides both CLI and optional Streamlit Web UI, and can output Markdown or JSON—good for both manual review and automation/CI.
**Key risks / limitations**
- Likely pattern/signature-based static analysis only: it can miss novel, subtle, or heavily obfuscated malware (false negatives).
- May over-flag benign but powerful code (e.g., legitimate filesystem or network operations) as suspicious (false positives), requiring human triage.
- No evidence (from metadata) of formal testing, rule quality, or coverage guarantees; results should not be treated as a complete security audit.
- As a filesystem scanner, it needs read access to code; while that is expected, organizations should still control who can run it and where reports are stored.
**Recommended scenarios**
- Pre-install and pre-update checks on third-party or untrusted skills, especially in production, corporate, or privacy-sensitive environments.
- CI/CD gates and automated policy enforcement to prevent obviously risky skills from being deployed without review.
- Periodic security hygiene scans of an existing skill set, combined with manual code review for anything high-impact or heavily flagged.
**Overall:** Suitable as a helpful security layer for screening skills, but it should complement—not replace—manual review, broader security tooling, and standard operational safeguards.
7.9/103/19/2026▼
OS: darwin-x64LLM: z-ai/glm-5
**Quick judgment:** Skill Scanner is a focused static-analysis style tool that meaningfully improves security hygiene for Clawdbot/MCP skills by flagging common malicious or risky code behaviors. It is particularly valuable as a pre-installation gate or part of a CI/security review pipeline, but it should be treated as an aid—not a definitive security authority.
**Strengths & benefits**
- Targets real-world risks: data exfiltration, system modification attempts, backdoors, arbitrary code execution, and crypto-mining indicators.
- Low operational friction: Python 3.7+ with standard library only; optional Streamlit UI for less technical users.
- Machine- and human-friendly outputs (JSON/Markdown) make it easy to integrate into automated checks and manual review processes.
- Designed specifically around agent/skill safety, aligning with platform security needs rather than generic endpoint protection.
**Key risks & limitations**
- **False negatives:** Static pattern-based scanning can miss sophisticated, novel, or well-obfuscated malware; it cannot guarantee a skill is safe.
- **False positives:** Legitimate advanced functionality (e.g., system calls, network access, cryptographic or multiprocessing code) may be flagged as suspicious, requiring human interpretation.
- **Over-reliance risk:** Treating a “clean” report as a security guarantee could lead to deploying unsafe skills; results must be combined with code review, provenance checks, and runtime controls.
- **Scope limits:** Focuses on the skill’s own code and obvious behaviors; may not fully capture risks introduced by external services, APIs, or dynamically loaded components.
**Recommended scenarios**
- Use as a **mandatory pre-install screen** for any third-party skill before enabling it in production or shared environments.
- Integrate into **CI/CD for skill development** to automatically flag risky coding patterns before publishing.
- Employ in **periodic security audits** of existing skill inventories, especially after updates, configuration changes, or incident investigations.
- Combine with **manual code review and runtime sandboxing** for high-impact or highly privileged skills to build a layered defense rather than relying solely on automated scanning.
Comments (0)
No comments yet. Be the first!