8.3
/ 10
1 evaluations
3.1k Downloads
Overview
Pre-install security gate for ClawHub skills that stages downloads in a temporary area, scans them with mcp-scan for AI-specific and traditional security issues, and only then installs or quarantines them.
Key Advantages
1.Blocks risky skills before they ever reach the live skills directory by using a /tmp staging area and quarantine flow.
2.Uses mcp-scan (Invariant Labs/Snyk) to analyze actual skill content, including prompts and config, not just binaries or metadata.
3.Specifically targets AI-oriented threats such as prompt injections, hidden instructions, data exfiltration URLs, and toxic chained flows.
4.Complements existing checks like VirusTotal and skillscanner by covering new or unreviewed skills and non-binary payloads.
5.Clear, scriptable exit codes (0/1/2) that integrate well with automation, CI, and policy-enforced install flows.
Provides a straightforward CLI workflow via ./scripts/safe-install.sh, with options for
Use Cases
- Default installation path for any new or untrusted ClawHub skills in security-conscious environments.
- CI/CD or automated agent setup pipelines that must enforce a security scan before adding or updating skills.
- Teams or organizations with sensitive data (source code, documents, secrets) that want to reduce risk from third-party skills.
- Security review workflows where practitioners need to stage, scan, and manually inspect suspicious skills before deployment.
- Developers experimenting with new or low-download skills and wanting protection against prompt injection and exfiltration patterns.
Evaluation Scores
8.3
/ 10
Reliability
7.5
Functionality
8.5
Usability
8.5
Safety
9.0
Performance
8.0
Compatibility
8.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.3/103/19/2026▼
OS: darwin-arm64LLM: google/gemini-2.5-flash-lite
**Judgment:** A strong, security-focused pre-install gate for ClawHub skills that substantially improves safety over direct installs, especially for unvetted or newly updated skills. Recommended for any setup that handles sensitive data or runs third-party skills at scale.
**What it does well**
- Stages skills in `/tmp` and only moves them into the real skills folder if they pass security checks.
- Uses mcp-scan (Invariant/Snyk) to analyze the actual skill content, catching AI-specific issues (prompt injections, hidden instructions, data exfil URLs, toxic flows) that VirusTotal and simple review tools typically miss.
- Can block installation automatically when threats are detected and quarantines the skill for manual review.
- Provides clear CLI usage (`./scripts/safe-install.sh <skill-slug> [--version] [--force]`) and structured exit codes for automation.
**Risks / Limitations**
- Not a guarantee of safety: advanced or novel attacks may evade static scanning, and users could develop a false sense of security.
- Depends on external tooling (mcp-scan, clawhub CLI, uv, and network access); outages or tool changes may cause failures or reduced protection.
- May introduce install latency due to staging and scanning, which could be noticeable in bulk or CI environments.
**Recommended scenarios**
- Installing any new, low-trust, or frequently updated ClawHub skills, especially on machines with secrets or sensitive files.
- Organizational or team environments where security policies require a pre-install scan step.
- Automated agent setups and CI pipelines that need a programmatic gate (via exit codes) before promoting skills into production.
Comments (0)
No comments yet. Be the first!