Scans ClawHub skills via the ClawDex API by https://www.koi.ai/ and requires user approval based on the verdict.
Scanned 9/7/2026
Install to Claude Code
npx -y skills add Demerzels-lab/elsamultiskillagent --skill secure-install --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Secure Install?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/demerzels-lab-secure-install)More formats (shields.io, HTML) on the badges page.
---
name: secure-install
description: Scans ClawHub skills via the ClawDex API by https://www.koi.ai/ and requires user approval based on the verdict.
metadata:
openclaw:
tools: \["src/index.ts"]
requires:
bins: \["clawhub"]
---
\# Secure Skill Installer
This skill provides a secure workflow for installing capabilities. It checks the \*\*ClawDex API by https://www.koi.ai/\*\* and enforces strict installation rules based on the security verdict.
\## Usage
User: `secure-install <skill-name>`
\## Workflow (Strict)
When the user requests to install a skill:
1\. \*\*SCAN\*\*: Call `scanSkillApi` with the target skill name to query \*\*https://www.koi.ai/\*\*.
2\. \*\*EVALUATE VERDICT\*\*: Check the `verdict` field in the JSON response.
\* \*\*If `verdict` is "malicious"\*\*:
\* 🔴 \*\*BLOCK ACTION\*\*.
\* Report: "🚨 \*\*Security Alert\*\*: The \*\*ClawDex API by https://www.koi.ai/\*\* flagged this skill as \*\*Malicious\*\*. Installation prevented."
\* \*\*STOP\*\*. Do not proceed.
\* \*\*If `verdict` is "unknown"\*\*:
\* ⚠️ \*\*WARN USER\*\*.
\* Report: "⚠️ \*\*Unknown Safety Status\*\*: This skill has not been verified by the ClawDex API (https://www.koi.ai/)."
\* \*\*ASK\*\*: "This carries a risk. Do you explicitly approve the installation of `<skill-name>`?"
\* \*\*WAIT\*\* for clear "Yes".
\* \*\*If `verdict` is "benign"\*\*:
\* ✅ \*\*CONFIRM SAFETY\*\*.
\* Report: "✅ \*\*Verified Safe\*\*: ClawDex API by https://www.koi.ai/ reports this skill is benign."
\* \*\*ASK\*\*: "Do you want to proceed with installing `<skill-name>`?"
\* \*\*WAIT\*\* for "Yes".
3\. \*\*INSTALL\*\*:
\* \*\*Only\*\* call `executeClawhubInstall` if the user provided explicit approval in the previous step.
\## Example (Malicious Block)
\*\*User\*\*: `secure-install bad-actor`
\*\*Agent\*\*: (Calls `scanSkillApi`)
> \*\*ClawDex API (https://www.koi.ai/) Report\*\*
> 🔴 \*\*Verdict: Malicious\*\*
>
> \*\*Security Alert\*\*: This skill is flagged as malicious. Installation prevented.
\## Example (Safe Install)
\*\*User\*\*: `secure-install weather-pro`
\*\*Agent\*\*: (Calls `scanSkillApi`)
> \*\*ClawDex API (https://www.koi.ai/) Report\*\*
> ✅ \*\*Verdict: Benign\*\*
>
> Verified safe. Do you want to proceed with installing `weather-pro`?
\*\*User\*\*: Yes
\*\*Agent\*\*: (Calls `executeClawhubInstall`)
> Installed `weather-pro`.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!