8.4
/ 10
1 evaluations
1.8k Downloads
Overview
Deterministic, offline scanner that inspects installed OpenClaw skills for known malicious patterns (e.g., prompt injection, credential theft, data exfiltration, obfuscation, backdoors) using pattern matching rather than LLMs.
Key Advantages
1.Offline and deterministic: no network or API calls, fully reproducible results using only the Python 3 standard library.
2.Covers common skill-level threats: looks for prompt injection, credential access, exfiltration paths, obfuscated payloads, and backdoor-like patterns.
3.Single-skill and batch scanning: supports scanning one skill directory or all installed skills, with aggregate JSON reporting.
4.Machine- and human-readable output: can emit structured JSON (for automation/CI) or human-readable summaries (for interactive use).
5.Clear severity semantics: standardized verdicts (clean, suspicious, dangerous, error) with exit codes for automated gating or CI pipelines.
Built-in allowlist: reduces noise from known security/tool/“
Use Cases
- Pre-install and post-update checks for new or updated OpenClaw skills to gate them before first use.
- Periodic security audits over all installed skills using aggregate scanning and summarized reports.
- Integration into CI/CD or automated workflows to block deploying or enabling skills marked as dangerous or suspicious.
- Triage and investigation when the user suspects a specific skill may be malicious or compromised.
- Baseline security layer in environments that want deterministic, explainable pattern-based scanning without relying on external services.
Evaluation Scores
8.4
/ 10
Reliability
7.8
Functionality
9.0
Usability
7.9
Safety
8.6
Performance
9.1
Compatibility
8.7
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.4/103/19/2026▼
OS: linux-x64LLM: anthropic/claude-haiku-4.5
**Judgement:** Skill Defender is a strong, practical first-line security scanner for OpenClaw skills. It is well-suited as a deterministic, offline layer to catch many common malicious patterns, but it should be treated as a complementary control rather than a complete security solution.
**What it does well:**
- Scans individual or all installed skills for known malicious patterns (prompt injection, credential theft paths, exfiltration behavior, obfuscated/backdoor-like code).
- Provides both single-skill and aggregate JSON reports, plus clear exit codes and verdicts, making it easy to automate in CI/CD or pre-install checks.
- Runs quickly with no external dependencies, which is ideal for repeated or scheduled audits.
- Includes an allowlist for known noisy patterns (e.g., other security/credentials-related skills) to reduce false positives in batch scans.
**Key risks and limitations:**
- Pattern-based only: it will miss novel or subtle attacks that don’t match its documented patterns, and sophisticated adversaries can potentially evade detection.
- False positives remain possible, especially when scanning security-oriented or configuration-heavy skills without the appropriate allowlisting or `--exclude` usage.
- Verdicts (especially “suspicious”) still require human review; treating them as fully authoritative without inspection can either block safe skills or give a false sense of security.
- It will even flag itself without the allowlist, which is expected behavior but can confuse users who aren’t aware of that caveat.
**Recommended scenarios:**
- Always run on new skills before enabling them, and after any skill updates.
- Schedule periodic “scan all skills” audits in environments where skills can change over time or multiple people can install them.
- Integrate into automated pipelines (e.g., treat exit code 1 as a warning and exit code 2 as a hard block requiring explicit override).
- Use in combination with other defenses (code review, permission sandboxing, runtime monitoring) rather than as the sole security mechanism.
Comments (0)
No comments yet. Be the first!