Skip to content
Back to skills

Clawguarddevin

DSecurity

Security scanner for OpenClaw/Clawdbot skills - detect malicious patterns before installation

  • 14 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 7, 2026
securitypythongoshellbashawsgitdatabaseci/cdsecurity

Works with

  • terminal

Security analysis

D50/100
  • criticalAccesses sensitive system or user directories
  • criticalReads or references SSH private keys

Pro scans all 7 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill clawguarddevin --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Clawguarddevin?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Clawguarddevin
[![Security: D โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-clawguarddevin/badge)](https://www.skillsdirectory.com/skills/modbender-clawguarddevin)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: clawguard
description: Security scanner for OpenClaw/Clawdbot skills - detect malicious patterns before installation
author: devinfloyd1
version: 0.1.0
metadata: {"clawdbot":{"emoji":"๐Ÿ›ก๏ธ","os":["darwin","linux","win32"]}}
---

# ClawGuard

**Security Scanner for OpenClaw/Clawdbot Skills**

Protect yourself from malicious skill installations. ClawGuard scans skills for dangerous patterns before you install them - including patterns from the **ClawHavoc campaign** (341 malicious skills discovered by Koi Security).

## Quick Start

```bash
# Scan a skill by name
python scan.py --skill <skill-name>

# Scan a skill by path  
python scan.py --path /path/to/skill

# Scan all installed skills
python scan.py --all
```

## What It Detects

| Category | Examples | Severity |
|----------|----------|----------|
| ๐Ÿ”ด **Reverse Shells** | socket.connect(), pty.spawn(), /dev/tcp | Critical |
| ๐Ÿ”ด **Data Exfiltration** | requests.post() to suspicious TLDs | Critical |
| ๐Ÿ”ด **Credential Harvest** | Reading ~/.ssh/id_rsa, AWS credentials | Critical |
| ๐Ÿ”ด **Obfuscation** | base64.b64decode(exec), chr() chains | Critical |
| ๐Ÿ”ด **ClawHavoc IOCs** | glot.io scripts, fake Apple URLs, known C2 IPs | Critical |
| ๐ŸŸ  **Code Execution** | exec(), eval(), subprocess | High |
| ๐ŸŸก **Suspicious Network** | URL shorteners, weird ports | Medium |

## Output Formats

```bash
# Console (default) - colored terminal output
python scan.py --skill github

# JSON - machine-readable for CI/CD
python scan.py --skill github --format json

# Markdown - for sharing reports
python scan.py --skill github --format markdown
```

## Risk Scoring

| Score | Level | Action |
|-------|-------|--------|
| 0-10 | ๐ŸŸข Safe | Install freely |
| 11-25 | ๐ŸŸข Low | Quick review |
| 26-50 | ๐ŸŸก Medium | Review findings |
| 51-75 | ๐Ÿ”ด High | Review carefully |
| 76-100 | ๐Ÿ”ด Critical | **Do not install** |

## IOC Database

70+ indicators of compromise including:
- Remote access (reverse shells, C2)
- Data exfiltration
- Credential harvesting  
- Code obfuscation
- **Real ClawHavoc campaign IOCs** (from Koi Security research)
- Known malicious IPs, hashes, and skill names

## Requirements

- Python 3.8+
- No external dependencies (stdlib only)

## Credits

IOCs enriched with research from [Koi Security](https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting) - ClawHavoc campaign analysis by Oren Yomtov and Alex.

## Links

- [GitHub Repository](https://github.com/devinfloyd1/clawguard)
- [ClawHavoc Research](https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting)

---

**Built for the Clawdbot community** ๐Ÿพ

Files in this skill

  • SKILL.md2.8 KB
  • tests/fixtures/clean_skill/SKILL.md252 B
  • tests/fixtures/edge_case_skill/SKILL.md362 B
  • tests/fixtures/malicious_skill_credential/SKILL.md132 B
  • tests/fixtures/malicious_skill_exfil/SKILL.md164 B
  • tests/fixtures/malicious_skill_obfuscated/SKILL.md116 B
  • tests/fixtures/malicious_skill_revshell/SKILL.md114 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading commentsโ€ฆ