Skip to content
Back to skills

Clawskillshield

ASecurity

ClawSkillShield

  • 33 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 5, 2026
securitypythonrustbashawsgitapisecurity

Works with

  • cli
  • api

Security analysis

A96/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 8 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add dvcrn/openclaw-skills-marketplace --skill clawskillshield --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Clawskillshield?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Clawskillshield
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/dvcrn-clawskillshield/badge)](https://www.skillsdirectory.com/skills/dvcrn-clawskillshield)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: clawskillshield
description: "ClawSkillShield"
---

# ClawSkillShield 🛡️

**Local-first security scanner for OpenClaw/ClawHub skills.**

## What It Does

- **Static analysis** for security risks and malware patterns
- **Detects**:
  - Hardcoded secrets (API keys, credentials, private keys)
  - Risky imports (`os`, `subprocess`, `socket`, `ctypes`)
  - Dangerous calls (`eval()`, `exec()`, `open()`)
  - Obfuscation (base64 blobs, suspicious encoding)
  - Hardcoded IPs
- **Risk scoring** (0–10) + detailed threat reports
- **Quarantine** high-risk skills automatically

## Dual-Use Design

- **CLI for humans**: Quick safety checks before installing skills
- **Agent API**: Importable functions for autonomous agents/Moltbots to proactively scan and quarantine risky skills (essential post-ClawHavoc)

## Quick Start

### CLI (Humans)
```bash
pip install -e .
clawskillshield scan-local /path/to/skill
clawskillshield quarantine /path/to/skill
```

### Python API (Agents)
```python
from clawskillshield import scan_local, quarantine

threats = scan_local("/path/to/skill")
if risk_score < 4:  # HIGH RISK
    quarantine("/path/to/skill")
```

## Zero Dependencies
Pure Python. No network calls. Runs entirely locally.

## Why This Matters
ClawHavoc demonstrated how easily malicious skills can slip into the ecosystem. ClawSkillShield provides a trusted, open-source defense layer—audit the code, run offline, stay safe.

---

**GitHub**: https://github.com/AbYousef739/clawskillshield  
**License**: MIT  
**Author**: Ab Yousef  
**Contact**: contact@clawskillshield.com

Files in this skill

  • .gitignore353 B
  • LICENSE.txt1.1 KB
  • README.md3.6 KB
  • SKILL.md1.6 KB
  • clawskillshield/__init__.py181 B
  • clawskillshield/analyzer.py3.9 KB
  • clawskillshield/skill.py2.8 KB
  • pyproject.toml770 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…