2.3k Downloads
Overview
Statically scan OpenBot/Clawdbot skills (local folders) for security vulnerabilities, malicious or suspicious patterns, and potential prompt-injection issues before installation.
Key Advantages
1.Provides an automated pre-installation security check for skills, improving overall security hygiene.
2.Detects a range of red flags (credential exfiltration, suspicious network calls, obfuscated code, prompt injection patterns).
3.Simple CLI usage with options for verbose and JSON output, suitable for both manual and automated workflows.
4.Severity-based scoring (CLEAN/INFO/REVIEW/SUSPICIOUS/DANGEROUS) with clear exit codes enables integration into CI/CD or approval pipelines.
5.Relies on an explicit ruleset (references/rules.md), making detection logic auditable and tunable.
Use Cases
- Security audit of a ClawHub skill before installing it into an OpenClaw/OpenBot environment.
- Automated security gate in CI/CD pipelines for internal or third-party skills.
- Scanning unknown or low-trust skills for credential exfiltration or suspicious network activity patterns.
- Detecting likely prompt injection or prompt-manipulation patterns in skill code or templates.
- Periodic re-scan of existing skills when updating rules to catch newly identified patterns or domains.
Evaluation Scores
8.1
/ 10
Reliability
7.5
Functionality
8.5
Usability
8.0
Safety
8.5
Performance
8.0
Compatibility
8.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.1/103/19/2026▼
OS: linux-x64LLM: anthropic/claude-haiku-4.5
**Quick judgment:** A useful and generally safe security utility that improves the safety of installing OpenBot/Clawdbot skills, as long as users treat it as a *screening tool* rather than a guarantee of safety.
**What it does well**
- Statically scans skill folders for:
- Credential exfiltration patterns (e.g., sending secrets out, suspicious logging).
- Suspicious network calls (e.g., unknown or non-whitelisted domains, unusual HTTP usage).
- Obfuscated or encoded code fragments that may hide malicious behavior.
- Possible prompt-injection or prompt-manipulation content.
- Provides clear severity levels (CLEAN, INFO, REVIEW, SUSPICIOUS, DANGEROUS) and exit codes suitable for automation.
- Offers verbose and JSON modes, making it practical both for human review and scripted pipelines.
**Risks & limitations**
- **Pattern-based only**: Can miss well-crafted or novel obfuscation, and cannot see runtime behavior.
- **False positives**: Legitimate tools that access files, network, or do encoding/decoding may be flagged as REVIEW/SUSPICIOUS.
- **False sense of security**: Passing the scan does **not** prove a skill is safe; manual review is still required for higher-severity or complex skills.
**Recommended use scenarios**
- As a **mandatory pre-install scan** for any third-party or untrusted skill from ClawHub or other sources.
- As a **CI/CD or approval gate**: fail or require security review when exit code indicates REVIEW/SUSPICIOUS/DANGEROUS.
- As a **triage tool** to prioritize which skills need deeper manual security review.
Overall: Strongly recommended as one layer in a defense-in-depth workflow for managing skill security, but it should always be combined with human review and broader security practices.
Comments (0)
No comments yet. Be the first!