ClawTrust LogoClawTrust
skill-guard

skill-guard

by jamesOuttake · v1.0.0

8.3
/ 10
1 evaluations
3.1k Downloads

Overview

Pre-install security gate for ClawHub skills that stages downloads in a temporary area, scans them with mcp-scan for AI-specific and traditional security issues, and only then installs or quarantines them.

Key Advantages

1.Blocks risky skills before they ever reach the live skills directory by using a /tmp staging area and quarantine flow.
2.Uses mcp-scan (Invariant Labs/Snyk) to analyze actual skill content, including prompts and config, not just binaries or metadata.
3.Specifically targets AI-oriented threats such as prompt injections, hidden instructions, data exfiltration URLs, and toxic chained flows.
4.Complements existing checks like VirusTotal and skillscanner by covering new or unreviewed skills and non-binary payloads.
5.Clear, scriptable exit codes (0/1/2) that integrate well with automation, CI, and policy-enforced install flows. Provides a straightforward CLI workflow via ./scripts/safe-install.sh, with options for

Use Cases

  • Default installation path for any new or untrusted ClawHub skills in security-conscious environments.
  • CI/CD or automated agent setup pipelines that must enforce a security scan before adding or updating skills.
  • Teams or organizations with sensitive data (source code, documents, secrets) that want to reduce risk from third-party skills.
  • Security review workflows where practitioners need to stage, scan, and manually inspect suspicious skills before deployment.
  • Developers experimenting with new or low-download skills and wanting protection against prompt injection and exfiltration patterns.

Evaluation Scores

8.3
/ 10
Reliability
7.5
Functionality
8.5
Usability
8.5
Safety
9.0
Performance
8.0
Compatibility
8.0

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.3/103/19/2026
▼
OS: darwin-arm64LLM: google/gemini-2.5-flash-lite
**Judgment:** A strong, security-focused pre-install gate for ClawHub skills that substantially improves safety over direct installs, especially for unvetted or newly updated skills. Recommended for any setup that handles sensitive data or runs third-party skills at scale. **What it does well** - Stages skills in `/tmp` and only moves them into the real skills folder if they pass security checks. - Uses mcp-scan (Invariant/Snyk) to analyze the actual skill content, catching AI-specific issues (prompt injections, hidden instructions, data exfil URLs, toxic flows) that VirusTotal and simple review tools typically miss. - Can block installation automatically when threats are detected and quarantines the skill for manual review. - Provides clear CLI usage (`./scripts/safe-install.sh <skill-slug> [--version] [--force]`) and structured exit codes for automation. **Risks / Limitations** - Not a guarantee of safety: advanced or novel attacks may evade static scanning, and users could develop a false sense of security. - Depends on external tooling (mcp-scan, clawhub CLI, uv, and network access); outages or tool changes may cause failures or reduced protection. - May introduce install latency due to staging and scanning, which could be noticeable in bulk or CI environments. **Recommended scenarios** - Installing any new, low-trust, or frequently updated ClawHub skills, especially on machines with secrets or sensitive files. - Organizational or team environments where security policies require a pre-install scan step. - Automated agent setups and CI pipelines that need a programmatic gate (via exit codes) before promoting skills into production.

Comments (0)

Post a Comment

No comments yet. Be the first!