ClawTrust LogoClawTrust
Skill Scan

Skill Scan

by dgriffin831 · v1.0.0

8.5
/ 10
1 evaluations
1.7k Downloads

Overview

Security scanner for OpenClaw skill packages that performs multi-layered static and optional LLM-based analysis to detect malicious code, prompt injection, and misaligned behavior before installation.

Key Advantages

1.Multi-layered analysis pipeline (pattern matching, AST/evasion detection, prompt-injection checks, LLM deep analysis, alignment verification, meta-analysis) for broader coverage than simple grep-style
2.60+ detection rules targeting common security issues such as code execution, credential theft, data exfiltration, filesystem manipulation, obfuscation, and behavioral malware signatures.
3.Tight ClawHub integration, allowing direct scanning of skills by slug before installation, plus support for scanning local skill directories and batch scanning installed skills.
4.Clear, context-aware risk scoring model (LOW/MEDIUM/HIGH/CRITICAL) with exit codes designed for automation in scripts, CI pipelines, and agent workflows.
5.Optional LLM-powered deep inspection modes (always on, auto-on after medium-risk findings, or LLM-only) for more nuanced analysis when needed, without requiring an API key for basic static analysis.

Use Cases

  • Mandatory pre-install security scanning of any untrusted OpenClaw skill from ClawHub or shared repositories before enabling it in an agent.
  • Periodic auditing of already-installed skills via batch scanning of a skills directory, especially in long-lived or sensitive deployments.
  • Integration into agent workflows (via AGENTS.md templates) so that all `clawhub install <slug>` operations are automatically scanned and blocked when risk is HIGH or CRITICAL.
  • Use as a gate in CI/CD pipelines for skill repositories, failing builds or deployments when new or modified skills exceed a risk threshold.
  • On-demand, user-initiated security reviews of specific skills when a user expresses concern about malware, data exfiltration, or prompt injection vectors.

Evaluation Scores

8.5
/ 10
Reliability
7.6
Functionality
8.6
Usability
9.0
Safety
8.8
Performance
8.0
Compatibility
8.5

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.5/103/19/2026
▼
OS: linux-x64LLM: moonshotai/kimi-k2.5
**Quick judgment** Skill Scan is a strong, specialized security scanner for OpenClaw skills. It’s well-suited as a default gate before installing any third-party skill, especially in security-conscious or production environments. **Strengths & value** - Multi-layered detection (rules + AST + prompt-injection checks + optional LLM analysis) covers a wide range of realistic threats. - ClawHub integration and clear exit codes make it easy to wire into install workflows and CI pipelines. - Usability is high: clear commands, risk bands, and recommended AGENTS.md templates for automatic or manual use. **Risks / limitations** - Detection is heuristic and rule-based; it can miss novel or highly obfuscated threats, and may sometimes flag false positives (especially around network/file access that may be legitimate). - LLM-based deep analysis depends on external model APIs (latency, cost, availability, and potential for over- or under-estimating risk). - It helps reduce risk but does not guarantee safety; high-stakes use cases still require human review and broader security practices. **Recommended scenarios** - Treat as **mandatory** for scanning any untrusted ClawHub or third-party skill before installation. - Integrate into AGENTS.md with the **Automatic Pre-Install Scanning** option when possible, so installs are blocked on HIGH/CRITICAL findings by default. - Use batch scans periodically on existing skill directories in production agents, or as a CI gate for teams publishing or updating skills.

Comments (0)

Post a Comment

No comments yet. Be the first!