5.6k Downloads
Overview
Clawdex is a security-vetting skill that queries Koi’s Clawdex API to determine whether another ClawHub skill is benign, malicious, or unknown before (or after) installation.
Key Advantages
1.Centralized security oracle for ClawHub skills, powered by a dedicated risk engine (Koi Wings).
2.Very simple, well-defined JSON verdict API (`benign` | `malicious` | `unknown`) that’s easy to integrate into automated workflows.
3.Explicit guidance on how to handle each verdict, including escalation when a skill is `unknown`.
4.Supports both pre-install checks and bulk auditing of already-installed skills.
5.Helps non-security experts make safer install decisions without needing to manually inspect skill code.
Use Cases
- Pre-installation security checks for any ClawHub skill before running `clawhub install`.
- Periodic or initial bulk audits of all already-installed skills to find previously unnoticed malicious extensions.
- Guardrail in enterprise or team environments where only skills with a `benign` verdict may be installed.
- Interactive assistant workflows where the AI must ask for explicit user approval if the verdict is `unknown`.
- Security-conscious users or organizations wanting an additional independent check beyond manual code review.
Evaluation Scores
8.4
/ 10
Reliability
7.5
Functionality
8.0
Usability
8.8
Safety
9.2
Performance
8.5
Compatibility
8.5
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.4/103/19/2026▼
OS: darwin-x64LLM: google/gemini-3-flash-preview
**Quick judgement:** Clawdex is a focused, high-value safety layer for ClawHub that checks skills against Koi’s security verdict API. It’s well-suited as a default pre-installation gate and for periodic audits of existing skills.
**Key strengths & benefits**
- Provides a **simple, binary/ternary security verdict** (`benign`, `malicious`, `unknown`) for ClawHub skills.
- **Clear operational guidance** on what to do for each verdict (install, block, or escalate for user review).
- Enables **bulk scanning of already-installed skills**, catching legacy risks from before security checks were common.
- Backed by a specialized **AI risk engine (Koi Wings)**, which can add meaningful protection beyond manual inspection for many users.
**Risks & limitations**
- **Single external dependency**: effectiveness and uptime depend on the availability and integrity of `https://clawdex.koi.security`. If it’s down or compromised, verdicts could be delayed, missing, or misleading.
- **False negatives/positives are possible**: a `benign` verdict is not a formal proof of safety, and a `malicious` verdict depends on Clawdex’s detection quality and threat models.
- The `unknown` result still **requires user or operator judgement**; it doesn’t remove the need for code review or policy decisions.
- Primarily tailored to **ClawHub skill names**; it’s not a general-purpose scanner for arbitrary code or tools.
**Recommended scenarios**
- Use as a **default mandatory check** before installing any new ClawHub skill, especially on shared or production systems.
- Integrate into **automated CI/security pipelines** that validate skill sets used by teams or internal assistants.
- Run regular **post-install audits** to identify and remove newly flagged malicious skills.
- Combine with **manual review and organizational policies** for skills returning `unknown` or when operating in high-security environments.
Comments (0)
No comments yet. Be the first!