8.6
/ 10
1 evaluations
5.1k Downloads
Overview
Security auditing and trust scoring tool for OpenClaw/ClawHub skills, providing automated multi-check scans and 5‑dimension trust scores to identify malicious or risky behavior before and after installation.
Key Advantages
1.Comprehensive security coverage with 18 targeted checks (credential harvest, exfiltration, obfuscated payloads, privilege escalation, prompt injection, download-and-execute, etc.).
2.Purpose-built for OpenClaw/ClawHub skills with workflows for pre-install inspection, post-install audits, diff-based update review, and corpus-wide benchmarking.
3.5-dimension trust scoring (Security, Quality, Structure, Transparency, Behavioral) with clear 0–100 scores and letter grades for policy-driven decisions.
4.CI/CD friendly via JSON output, exit codes (0/1/2/3), and batch tooling (audit-all, benchmark, report generation).
5.Trend tracking and comparative analysis to monitor skill security posture over time and compare alternatives side by side.
Robust test suite with malicious and clean fixtures to validate detection and
Use Cases
- Pre-install security validation of new ClawHub skills using inspect.sh to reduce the risk of introducing malicious or low-trust skills into an environment.
- Periodic security audits of all installed skills via audit-all.sh to maintain an up-to-date view of the skill fleet’s risk posture.
- Gatekeeping in CI/CD pipelines for skill repositories using trust_score.py with JSON output and exit codes to enforce minimum trust/grade thresholds.
- Security review of skill updates using diff-audit.sh to catch regressions or newly introduced risky patterns before deployment.
- Comparative evaluation of multiple candidate skills for a use case via trust_score.py --compare to choose higher-trust, better-structured options. Longitudinal tracking of a skill’s security and
Evaluation Scores
8.6
/ 10
Reliability
8.0
Functionality
9.0
Usability
8.5
Safety
9.5
Performance
7.5
Compatibility
8.0
Based on 1 evaluation · Latest: 3/19/2026
Download Trend
Loading...
Evaluation History (1)
8.6/103/19/2026▼
OS: darwin-arm64LLM: deepseek/deepseek-v3.2
## Quick judgment
**Yoder Skill Auditor** is a **specialized, high-utility security scanner for OpenClaw/ClawHub skills**. Based on the description, it appears well-designed for technical teams that need structured, repeatable security checks and trust scoring around skills. It is best suited as a **security gate and ongoing audit tool**, not as a sole source of truth for security.
**Overall stance:** Recommended for security-conscious users and teams working heavily with OpenClaw skills, especially in automated or policy-driven environments.
---
## Key strengths
- **Deep, domain-specific coverage**: 18 tailored checks that match common real-world threats (credential harvesting, exfil, obfuscated payloads, download-and-execute, privilege escalation, prompt injection, etc.).
- **Prompt-injection detection**: Explicit coverage of agent manipulation in documentation ("ignore instructions", role hijacking, hidden HTML), which is often overlooked.
- **Trust scoring framework**: 5 dimensions (Security, Quality, Structure, Transparency, Behavioral) with numeric score + letter grade, making it easy to set organizational policies (e.g., block <60 or <40).
- **Rich workflows**: Pre-install inspection, single-skill audit, diff audits, trend tracking, benchmarking, and batch scans across all installed skills.
- **Automation-ready**: CLI tooling, JSON output, and clear exit codes (0=PASS, 1=REVIEW, 2=FAIL, 3=Error) integrate well into CI/CD and fleet management.
- **Validation effort**: 12 test fixtures (8 malicious, 4 clean) and 28 automated assertions give some evidence of reliability and attention to false positives.
---
## Risks and limitations
- **Potential overreliance / false sense of security**: Marketing claims such as "zero false positives" and "best-in-class detection" should be treated cautiously; manual review is still needed for high-risk deployments.
- **Coverage is pattern-based**: The checks are mainly heuristics (e.g., patterns for curl|bash, base64, eval/exec, sensitive paths). Novel or well-obfuscated attacks may evade detection.
- **Ecosystem-specific**: Highly tailored to OpenClaw/ClawHub skills; it is not a general-purpose code security scanner and may miss non-skill-related issues in broader projects.
- **Operational fit required**: Designed for users comfortable with shell and Python CLIs; less suitable for non-technical operators without tooling or automation around it.
---
## Recommended scenarios
Use **Yoder Skill Auditor** when:
- You are **installing or updating skills from ClawHub**, especially from untrusted or third-party authors.
- You want a **policy gate in CI/CD** that enforces minimum trust scores and fails on CRITICAL findings.
- You manage **many skills across environments** and need batch audits, benchmarking, and trend tracking.
- You need to **compare multiple skills** for the same purpose and want security/quality structure to influence the selection.
It is less appropriate as a standalone solution for organizations that need **comprehensive, language-level or infrastructure-level security scanning** beyond OpenClaw skills; in those environments it should be combined with broader application security tools.
Comments (0)
No comments yet. Be the first!