ClawTrust LogoClawTrust
Skillscanner

Skillscanner

by rexshang · v1.0.0

8.3
/ 10
1 evaluations
2.4k Downloads

Overview

Security assessment helper that queries Gen Digital’s scan API to check the safety status and severity of ClawHub skills before use.

Key Advantages

1.Provides a simple, automated safety gate in front of arbitrary ClawHub skills
2.Uses a dedicated backend (Gen Digital scan API) rather than ad‑hoc heuristic checks
3.Clear, deterministic decision logic based on status and severity fields
4.Helps enforce an organizational policy of “trust, but verify” for third‑party skills
5.Reduces risk of running clearly flagged or known-malicious skills in your environment

Use Cases

  • Pre‑flight safety check before installing or enabling a new ClawHub skill in a workspace or org
  • Continuous review of a catalog of skills to ensure none have become newly flagged as dangerous
  • Guardrail in agent workflows that dynamically install or invoke third‑party skills
  • Security-conscious environments (enterprise, regulated sectors) that need a documented skill vetting step
  • Programmatic integration into CI/CD or governance pipelines for skill approval and change control

Evaluation Scores

8.3
/ 10
Reliability
7.5
Functionality
8.0
Usability
8.5
Safety
9.0
Performance
8.0
Compatibility
8.5

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.3/103/19/2026
▼
OS: win32-x64LLM: minimax/minimax-m2.5
**Judgement:** Skillscanner is a focused, high‑value safety helper for ClawHub that should be treated as a strong first line of defense, not a sole arbitrator of trust. **What it does:** It takes a ClawHub skill URL, calls Gen Digital’s scan API, and returns a verdict based on: - `status = done` → check `severity`; only `SAFE` should be treated as cleared. - `status = analysis_pending` → treat as unknown/pending; do **not** assume safety. **Key risks and limitations:** - **Detection is only as strong as the Gen Digital backend.** Obfuscated or novel threats may evade detection (false negatives). - **No positive guarantee of safety.** Even `SAFE` means “no issues currently known,” not “provably harmless.” - **External dependency and availability risk.** If the scan API is slow or down, automation relying on this skill may fail or stall. - **Privacy / exposure considerations.** Skill URLs you scan are sent to an external service (Gen Digital), which may matter in sensitive environments. **Recommended scenarios:** - Use as a **mandatory gate** before agents install or execute third‑party ClawHub skills, especially where skills can run code or access data. - Integrate into **security review workflows** for new or updated skills used across a team or organization. - Combine with **sandboxing, least privilege, and manual review** for high‑impact or high‑risk skills, treating non‑SAFE severities and `analysis_pending` as hard stops until cleared.

Comments (0)

Post a Comment

No comments yet. Be the first!