Back to skills
SKILL.md
Skill Flag
DSecurityScan Clawdbot/OpenClaw skills for malicious patterns, backdoors, and security risks. **Created by:** DarkM00n (Bug Bounty Hunter & Security Researcher)
- 10 stars
- 0 votes
- 0 copies
- 1 view
- Added September 7, 2026
Works with
Security analysis
50/100- Accesses sensitive system or user directories
- Reads or references SSH private keys
- Exfiltrates credentials via HTTP โ exact pattern from Snyk ToxicSkills study
Pro scans all 10 files and shows the line behind each finding
npx -y skills add Demerzels-lab/elsamultiskillagent --skill skill-flag --agent claude-codeAre you the author of Skill Flag?
Add the live security badge to your README. It updates with every re-scan.
[](https://www.skillsdirectory.com/skills/demerzels-lab-skill-flag)# Skill Flag Skill ๐ก๏ธ
Scan Clawdbot/OpenClaw skills for malicious patterns, backdoors, and security risks.
**Created by:** DarkM00n (Bug Bounty Hunter & Security Researcher)
## Commands
### Scan All Installed Skills
```
scan skills
scan all skills
security scan
```
### Scan Specific Skill
```
scan skill <skill-name>
check skill <skill-name>
```
### Scan Before Installing (URL/Path)
```
scan skill url <clawdhub-url>
pre-scan <skill-name>
```
### Quick Risk Report
```
skill risk report
security report
```
## How To Use
Run the scanner:
```bash
python3 skills/skill-flag/scanner.py [--skill NAME] [--all] [--verbose]
```
Or ask the agent:
- "Scan all my installed skills for security issues"
- "Check if the crypto-tracker skill is safe"
- "Give me a security report"
## What It Detects
| Category | Risk Level | Examples |
|----------|------------|----------|
| ๐ด Data Exfiltration | CRITICAL | curl/wget to external domains, fetch(), requests.post() |
| ๐ด Backdoors | CRITICAL | Reverse shells, nc -e, bash -i, encoded payloads |
| ๐ด Credential Theft | CRITICAL | Access to ~/.ssh, ~/.aws, API keys, .env files |
| ๐ Prompt Injection | HIGH | "ignore previous", "system override", "new instructions" |
| ๐ Code Execution | HIGH | eval(), exec(), subprocess with shell=True |
| ๐ก Persistence | MEDIUM | Cron jobs, systemd units, startup scripts |
| ๐ก Obfuscation | MEDIUM | Base64 encoded commands, hex strings, rot13 |
| ๐ข Suspicious | LOW | Uncommon imports, network activity |
## Risk Score
Each skill gets a score from 0-100:
- **0-20**: โ
Clean - No issues found
- **21-40**: ๐ข Low Risk - Minor concerns
- **41-60**: ๐ก Medium Risk - Review recommended
- **61-80**: ๐ High Risk - Careful inspection needed
- **81-100**: ๐ด Critical - Do not use without audit
## Output
Reports saved to: `skills/skill-flag/reports/`
Example output:
```
๐ก๏ธ SECURITY SCAN REPORT
โโโโโโโโโโโโโโโโโโโโโโโ
Scanned: 12 skills
Clean: 9
Warnings: 2
Critical: 1
โ ๏ธ WARNINGS:
- crypto-tracker: External API calls (expected for price data)
- web-scraper: Uses requests library
๐ด CRITICAL:
- shady-skill:
- Line 45: curl to unknown domain
- Line 67: Base64 encoded payload
- Line 89: Reads ~/.ssh/id_rsa
RECOMMENDATION: Remove immediately
```
## Directories Scanned
1. `~/.clawdbot/skills/` - Global installed skills
2. `./skills/` - Workspace skills
3. `~/.npm-global/lib/node_modules/clawdbot/skills/` - Built-in skills
## False Positives
Some legitimate skills need network access or file operations. The scanner flags them for review but doesn't auto-block. Use judgment:
- Price trackers โ API calls expected โ
- Email skills โ Network access expected โ
- File managers โ File operations expected โ
## Pro Version (Coming Soon)
- Continuous monitoring
- ClawdHub pre-install scanning
- Custom whitelist/blacklist
- Scheduled reports
- Webhook alerts
Files in this skill
- README.md
- SKILL.md
- _meta.json
- patterns/backdoors.yaml
- patterns/exfiltration.yaml
- patterns/injection.yaml
- patterns/obfuscation.yaml
- reports/scan_20260130_2007.json
- reports/template.md
- scanner.py
Attribution
Comments
Loading commentsโฆ