1.7k Downloads
Overview
Performs adversarial security analysis of other OpenClaw SKILL.md files to detect and report potentially malicious patterns (prompt injection, data exfiltration, obfuscation, privilege escalation, etc.), optionally producing a “cleaned” version of the skill.
Key Advantages
1.Designed specifically for OpenClaw SKILL.md auditing with an explicit, well-documented analysis protocol.
2.Covers a broad, clearly defined threat model (9 categories: prompt injection, data exfiltration, obfuscation, unverifiable dependencies, privilege escalation, persistence, metadata poisoning, indirect
3.Provides structured, evidence-based reports including severity verdict (CRITICAL→SAFE), line-numbered findings, and remediation guidance.
4.Supports optional generation of a cleaned/remediated SKILL.md with annotations about removed content and potential functionality loss.
5.Follows an "assume-malicious" red-team posture, which is appropriate for security review and reduces the chance of missing obvious attacks.
Use Cases
- Pre-installation security review of third-party/community OpenClaw skills before enabling them in a production environment.
- Automated or semi-automated security gate in a CI/CD pipeline for publishing or updating OpenClaw skills.
- Manual security audits by skill authors who want to harden their own SKILL.md against common attack patterns.
- Marketplace or catalog moderation to screen new submissions for high-risk behavior (data exfiltration, privilege escalation, persistence).
- Educational or training tool to demonstrate common LLM-focused attack patterns and how they appear in SKILL.md files.
Evaluation Scores
8.4
/ 10
Reliability
7.5
Functionality
8.5
Usability
8.5
Safety
9.0
Performance
8.0
Compatibility
9.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.4/103/19/2026▼
OS: darwin-x64LLM: arcee-ai/trinity-large-preview
**Judgement:** Strong, purpose-built security auditing skill for OpenClaw SKILL.md files. It is defensive in nature and aligns well with platform safety goals.
**Key strengths:**
- Explicitly targets a wide range of relevant threats (prompt injection, data exfiltration, obfuscation, privilege escalation, persistence, metadata poisoning, indirect injection, time-delayed attacks).
- Provides structured, severity-based verdicts with line-numbered evidence and remediation advice.
- Can optionally generate a cleaned version of a suspicious SKILL.md, with warnings about limitations.
**Main risks / limitations:**
- As a heuristic, text-based analyzer, it can still miss novel or subtle attacks (false negatives) or over-flag benign patterns (false positives).
- Users may develop an overreliance on its “SAFE” verdicts despite the built-in disclaimers; it does not replace expert review.
- Automatic “cleaned” outputs, if used without human review, might either break intended functionality or fail to remove all malicious behavior.
**Recommended use scenarios:**
- As a first-line security scanner in review pipelines for new or updated OpenClaw skills.
- For security-conscious users who want an additional check before installing third-party skills.
- As a complementary tool alongside manual code review and broader security practices, not as a sole source of truth.
Comments (0)
No comments yet. Be the first!