2.2k Downloads
Overview
Performs multi-layer, fail-closed security audits of OpenClaw/ClawHub skills and general codebases, focusing on whether a repository can compromise or “betray” the host system rather than whether it functions correctly.
Key Advantages
1.Fail-closed design: any failed check (secrets, SAST, hostile signals, supply-chain hygiene) yields an overall FAIL, suitable for zero-trust and quarantine workflows.
2.Multi-layer security coverage: integrates trufflehog for secret/credential leakage, semgrep for static analysis (SAST), and a custom hostile-audit layer for prompt-injection, persistence mechanisms, &
3.dependency hygiene.
4.Configurable strictness levels (standard, strict, paranoid) allow teams to tune aggressiveness, from pragmatic defaults to highly conservative, paranoid gating.
5.Machine-readable intent/permissions manifest (openclaw-skill.json) requirement enables policy-driven install workflows and clearer, auditable skill permissions modeling.
JSON-only output via scripts,
Use Cases
- Pre-install security gate for OpenClaw/ClawHub skills before enabling them in production or sensitive environments.
- Continuous integration (CI) or pre-merge pipelines to block introduction of skills/repos with leaked secrets, malicious hooks, or suspicious dependencies.
- Marketplace or catalog curation for organizations hosting internal skill hubs, ensuring a baseline of security hygiene before publishing a skill to others.
- Periodic re-audits of existing skills and codebases after dependency updates or refactors to catch newly introduced hostile patterns or leaked credentials.
- Zero-trust or high-assurance workflows where missing manifests, ambiguous intent, or best-effort hashing failures must be treated as hard failures (e.g., regulated environments).
Evaluation Scores
8.5
/ 10
Reliability
8.0
Functionality
9.0
Usability
8.0
Safety
9.5
Performance
7.5
Compatibility
8.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.5/103/19/2026▼
OS: linux-x64LLM: x-ai/grok-4.1-fast
### Quick judgement
This skill is a strong choice for **security-first, zero-trust workflows** around OpenClaw/ClawHub skills and general repos. It is explicitly **hostile-by-design and fail-closed**, prioritizing prevention of compromise over developer convenience. Expect more false positives and friction, but significantly higher assurance that untrusted skills can’t quietly install persistence, exfiltrate data, or bypass policy.
### What it does
- Runs a **multi-layer security audit**:
- **Secrets/credential leakage** via `trufflehog`.
- **Static analysis (SAST)** via `semgrep` auto rules.
- **Hostile repo audit** via custom logic: prompt-injection signals, persistence mechanisms (e.g., install hooks), suspicious artifacts, and dependency hygiene.
- Produces **JSON-only output** from `scripts/run_audit_json.sh` / `scripts/security_audit.sh`, suitable for automation.
- Supports configurable strictness levels via `OPENCLAW_AUDIT_LEVEL`:
- `standard`: pragmatic but strict defaults (lockfiles required; install hooks, persistence, and prompt-injection signals cause FAIL).
- `strict`: more patterns become hard FAIL (e.g., minified/obfuscated artifacts).
- `paranoid`: minimal tolerance for ambiguity; no “best-effort” hashing failures; more fail-closed behavior.
- Can **enforce a manifest requirement**: `openclaw-skill.json` at repo root, with schema in `docs/OPENCLAW_SKILL_MANIFEST_SCHEMA.md`. Missing manifest is treated as FAIL in strict/quarantine flows.
### Key risks and limitations
- **High false-positive rate by design**: Legitimate but unusual patterns (minified bundles, complex hooks, unconventional dependencies) are likely to trigger FAIL under `strict`/`paranoid` levels.
- **Operational dependencies**: Relies on external tools (`trufflehog`, `semgrep`, and system `bash`) and their rule sets; misconfiguration or version drift may affect results or performance.
- **Performance impact on large repos**: Full SAST and secrets scanning can be slow on large mono-repos or history-rich projects, especially at higher strictness levels.
- **Developer friction**: Requiring `openclaw-skill.json` and strict hygiene can slow onboarding of new skills and require education and process changes.
### Recommended scenarios
Use this skill when:
- You need a **hard security gate** before installing or enabling any third-party or untrusted skill.
- You run a **shared skills marketplace** (internal or external) and must enforce minimum security hygiene before publishing.
- Your environment is **regulatory or high-stakes** (finance, healthcare, critical infra) and you prefer blocking safe-but-ambiguous repos over permitting anything suspicious.
- You want **repeatable, JSON-based security checks** in CI/CD, with clear PASS/FAIL semantics and minimal room for silent policy bypasses.
Avoid relying on it as the sole check for **functional correctness**; it is focused on "can this skill betray the system?", not "does this skill work as intended?".
Comments (0)
No comments yet. Be the first!