2.6k Downloads
Overview
Static and dependency-based security scanner for ClawHub skills, designed to analyze skill code and metadata before installation to flag dangerous patterns and risky dependencies.
Key Advantages
1.Provides a dedicated security layer in an ecosystem with no built‑in moderation, reducing risk from unvetted third‑party skills.
2.Detects a broad range of critical patterns (eval/exec, shell injection, recursive delete, credential/file access, reverse shell, crypto‑mining indicators).
3.Performs dependency vulnerability analysis using external vulnerability databases (CVE, npm, GitHub advisories).
4.Supports multiple workflows: scanning before install, local directory scans, auditing all installed skills, and continuous monitoring via watch mode or cron/CI.
5.Flexible reporting (JSON, Markdown, HTML) suitable for both humans and automated pipelines, with structured severity and CWE-style references (v2).","Configurable policy via a JSON config file (allow/
Use Cases
- Pre-install security gate for any third-party ClawHub skill, especially from unknown or unverified authors.
- Regular auditing of all installed skills to detect newly introduced dangerous patterns or dependency vulnerabilities.
- Security review of your own skills before publishing, to catch risky patterns or insecure defaults.
- Integration into CI/CD pipelines to fail builds when new code introduces high-severity security issues or vulnerable dependencies.
- Generating human-readable security reports (Markdown/HTML) for security teams or code reviewers to document risk assessments of skills.
Evaluation Scores
8.4
/ 10
Reliability
7.5
Functionality
8.7
Usability
8.2
Safety
9.2
Performance
8.0
Compatibility
8.5
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.4/103/19/2026▼
OS: linux-x64LLM: minimax/minimax-m2.5
**Quick judgment:** This skill is *recommended* as a security gate for ClawHub skills. It is low-risk to run on your own system (it mainly reads/analyzes code and metadata) and provides substantial value by flagging obviously dangerous behaviors and vulnerable dependencies before installation. It should be treated as a first-line defense, not a guarantee of safety.
**What it does well**
- Scans remote or local skills for critical red-flag patterns: arbitrary code execution (eval/exec), shell commands, recursive deletes, credential/file-system access, reverse shell and crypto-mining indicators.
- Performs dependency vulnerability checks using known vulnerability sources (CVE DBs, npm advisories, GitHub Security Advisories).
- Offers convenient commands for:
- Scanning a skill *before* installing it.
- Scanning local folders and all installed skills.
- Generating detailed reports (JSON/Markdown/HTML).
- Maintaining allowlists, trusted authors, and watch/monitoring flows.
- Integrates smoothly into workflows (pre-install hook, CI pipelines, cron-based audits) via a simple CLI.
**Main risks & limitations**
- **False sense of security:** It is a static analyzer with a pattern database; it cannot guarantee safety, especially against obfuscated code, dynamic code generation, or novel attack techniques.
- **False positives / noise:** Legitimate code may be flagged (e.g., network requests, environment access, file writes). Non-technical users may misinterpret or overreact to warnings.
- **Vulnerability DB freshness:** Dependency checks are only as good as the last DB update; outdated databases may miss newer CVEs.
- **Version / maturity mismatch:** The page mentions a v2.0.0 feature set while the skill metadata here lists 1.0.0, suggesting that some advanced capabilities (like the full CWE-annotated pattern set) might not be available in the listed version.
**Recommended scenarios**
- Security-conscious users or teams who install many third-party skills and want a **pre-install screening step**.
- Developers who want to **self-audit** their own skills before publishing.
- Any environment with higher security requirements (enterprise, regulated sectors) that needs a **repeatable, automatable security check** in CI/CD or scheduled audits.
**Not sufficient on its own if** you require strong guarantees against sophisticated or targeted attacks; combine it with sandboxes, network restrictions, least-privilege configurations, and periodic manual code review for high-risk skills.
Comments (0)
No comments yet. Be the first!