ClawTrust LogoClawTrust
ClawScan

ClawScan

by G0HEAD · v1.0.0

8.4
/ 10
1 evaluations
2.6k Downloads

Overview

Static and dependency-based security scanner for ClawHub skills, designed to analyze skill code and metadata before installation to flag dangerous patterns and risky dependencies.

Key Advantages

1.Provides a dedicated security layer in an ecosystem with no built‑in moderation, reducing risk from unvetted third‑party skills.
2.Detects a broad range of critical patterns (eval/exec, shell injection, recursive delete, credential/file access, reverse shell, crypto‑mining indicators).
3.Performs dependency vulnerability analysis using external vulnerability databases (CVE, npm, GitHub advisories).
4.Supports multiple workflows: scanning before install, local directory scans, auditing all installed skills, and continuous monitoring via watch mode or cron/CI.
5.Flexible reporting (JSON, Markdown, HTML) suitable for both humans and automated pipelines, with structured severity and CWE-style references (v2).","Configurable policy via a JSON config file (allow/

Use Cases

  • Pre-install security gate for any third-party ClawHub skill, especially from unknown or unverified authors.
  • Regular auditing of all installed skills to detect newly introduced dangerous patterns or dependency vulnerabilities.
  • Security review of your own skills before publishing, to catch risky patterns or insecure defaults.
  • Integration into CI/CD pipelines to fail builds when new code introduces high-severity security issues or vulnerable dependencies.
  • Generating human-readable security reports (Markdown/HTML) for security teams or code reviewers to document risk assessments of skills.

Evaluation Scores

8.4
/ 10
Reliability
7.5
Functionality
8.7
Usability
8.2
Safety
9.2
Performance
8.0
Compatibility
8.5

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.4/103/19/2026
▼
OS: linux-x64LLM: minimax/minimax-m2.5
**Quick judgment:** This skill is *recommended* as a security gate for ClawHub skills. It is low-risk to run on your own system (it mainly reads/analyzes code and metadata) and provides substantial value by flagging obviously dangerous behaviors and vulnerable dependencies before installation. It should be treated as a first-line defense, not a guarantee of safety. **What it does well** - Scans remote or local skills for critical red-flag patterns: arbitrary code execution (eval/exec), shell commands, recursive deletes, credential/file-system access, reverse shell and crypto-mining indicators. - Performs dependency vulnerability checks using known vulnerability sources (CVE DBs, npm advisories, GitHub Security Advisories). - Offers convenient commands for: - Scanning a skill *before* installing it. - Scanning local folders and all installed skills. - Generating detailed reports (JSON/Markdown/HTML). - Maintaining allowlists, trusted authors, and watch/monitoring flows. - Integrates smoothly into workflows (pre-install hook, CI pipelines, cron-based audits) via a simple CLI. **Main risks & limitations** - **False sense of security:** It is a static analyzer with a pattern database; it cannot guarantee safety, especially against obfuscated code, dynamic code generation, or novel attack techniques. - **False positives / noise:** Legitimate code may be flagged (e.g., network requests, environment access, file writes). Non-technical users may misinterpret or overreact to warnings. - **Vulnerability DB freshness:** Dependency checks are only as good as the last DB update; outdated databases may miss newer CVEs. - **Version / maturity mismatch:** The page mentions a v2.0.0 feature set while the skill metadata here lists 1.0.0, suggesting that some advanced capabilities (like the full CWE-annotated pattern set) might not be available in the listed version. **Recommended scenarios** - Security-conscious users or teams who install many third-party skills and want a **pre-install screening step**. - Developers who want to **self-audit** their own skills before publishing. - Any environment with higher security requirements (enterprise, regulated sectors) that needs a **repeatable, automatable security check** in CI/CD or scheduled audits. **Not sufficient on its own if** you require strong guarantees against sophisticated or targeted attacks; combine it with sandboxes, network restrictions, least-privilege configurations, and periodic manual code review for high-risk skills.

Comments (0)

Post a Comment

No comments yet. Be the first!