Skip to content
Back to skills

Skill Auditor

ASecurity

Security scanner for OpenClaw skills. Detects malicious code, obfuscated payloads, prompt injection, social engineering, typosquatting, and data exfiltration before installation. Features 0-100 numeric risk scoring, MITRE ATT&CK mappings, base64/hex deobfuscation, IoC database, whitelist system, and SHA256 file inventory. Use before installing any third-party skill. Triggers: audit skill, check security, scan skill, is this skill safe, security review, quarantine.

  • 33 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 5, 2026
securitypythongoshellbashgitdatabasesecuritydocumentation

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add dvcrn/openclaw-skills-marketplace --skill skill-auditor --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Skill Auditor?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Skill Auditor
[![Security: A โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/dvcrn-skill-auditor-openclaw-skills-marketplace/badge)](https://www.skillsdirectory.com/skills/dvcrn-skill-auditor-openclaw-skills-marketplace)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: skill-auditor
description: "Security scanner for OpenClaw skills. Detects malicious code, obfuscated payloads, prompt injection, social engineering, typosquatting, and data exfiltration before installation. Features 0-100 numeric risk scoring, MITRE ATT&CK mappings, base64/hex deobfuscation, IoC database, whitelist system, and SHA256 file inventory. Use before installing any third-party skill. Triggers: audit skill, check security, scan skill, is this skill safe, security review, quarantine."
---

# Skill Auditor v2.0 ๐Ÿ”๐Ÿ›ก๏ธ

Comprehensive security scanner for OpenClaw/ClawHub skills. Merges static analysis, deobfuscation, and threat intelligence into a single Python tool.

## When to Use

- Before installing **any** third-party skill from ClawHub
- When reviewing skill updates for security regressions
- To audit your own skills before publishing
- When someone asks: "is this skill safe?", "audit this", "check security"

## Quick Start

### Audit a local skill directory
```bash
python3 {baseDir}/scripts/audit_skill.py /path/to/skill --human
```

### Audit a ClawHub skill by slug
```bash
python3 {baseDir}/scripts/audit_skill.py --slug skill-name --human
```

### Quarantine workflow (audit + prompt to install)
```bash
bash {baseDir}/scripts/quarantine.sh /path/to/skill
bash {baseDir}/scripts/quarantine.sh --slug skill-name
```

### JSON output for programmatic use
```bash
python3 {baseDir}/scripts/audit_skill.py /path/to/skill --json
```

## Scoring System

| Score | Level | Action |
|-------|-------|--------|
| 0โ€“20 | โœ… SAFE | Auto-install OK |
| 21โ€“40 | ๐ŸŸข LOW RISK | Proceed with caution |
| 41โ€“60 | ๐ŸŸก MEDIUM RISK | Manual review required |
| 61โ€“80 | ๐ŸŸ  HIGH RISK | Expert review needed |
| 81โ€“100 | ๐Ÿ”ด CRITICAL | Do NOT install |

Exit codes: `0` = safe (โ‰ค20), `1` = review (21โ€“60), `2` = dangerous (>60)

## Detection Layers

### Layer 1: Static Pattern Analysis
- 10+ scan categories with regex patterns
- Shell execution, network calls, env access, filesystem escape
- Prompt injection, data exfiltration, crypto wallet access
- Dynamic imports, browser credential theft, fake prerequisites

### Layer 2: Deobfuscation
- Base64 string extraction and decode โ†’ re-scan decoded content
- Hex escape sequence decode โ†’ re-scan
- Detects hidden commands, C2 IPs in encoded payloads

### Layer 3: Threat Intelligence
- IoC database: known malicious IPs, domains
- Social engineering detection: urgency, false authority, fear tactics
- MITRE ATT&CK ID mapping on every finding
- Whitelist system reduces score for safe binaries/domains

### Additional Checks
- SHA256 file inventory for integrity verification
- Typosquat detection (Levenshtein distance on package names)
- Zero-width character detection in SKILL.md
- Comment-context severity reduction (findings in comments scored lower)
- Permission scope analysis (what tools does the skill request?)

## IoC Database

Structured threat data in `references/ioc-database.json`. Update when new threats emerge. The scanner auto-loads this file at runtime.

## References

- `references/ioc-database.json` โ€” Structured IoC data (IPs, domains, patterns)
- `references/known-patterns.md` โ€” Human-readable threat documentation
- `references/prompt-injection-patterns.md` โ€” Prompt injection pattern reference

## Credits

Built by [M. Abidi](https://www.linkedin.com/in/mohammad-ali-abidi) | [agxntsix.ai](https://www.agxntsix.ai)
[YouTube](https://youtube.com/@aiwithabidi) | [GitHub](https://github.com/aiwithabidi)
Part of the **AgxntSix Skill Suite** for OpenClaw agents.

๐Ÿ“… **Need help setting up OpenClaw for your business?** [Book a free consultation](https://cal.com/agxntsix/abidi-openclaw)

Fork of [skill-auditor-pro](https://clawhub.ai/skills/skill-auditor-pro) by sypsyp97, merged with [skill-security-auditor](https://clawhub.ai/skills/skill-security-auditor) by akm626.

Files in this skill

  • SKILL.md3.8 KB
  • references/ioc-database.json3.9 KB
  • references/known-patterns.md2.8 KB
  • references/prompt-injection-patterns.md2.3 KB
  • scripts/audit_skill.py35.3 KB
  • scripts/quarantine.sh3.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading commentsโ€ฆ