Skip to content
Back to skills

Guardskills

ASecurity

Security gate for skill installs. Scans skill content for malicious patterns (credential exfiltration, remote code execution, destructive ops, privilege escalation) before installation. Always run guardskills before installing any skill from ClawHub, GitHub, or local sources.

  • 14 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
toolsbashnodegitsecurity

Security analysis

A100/100

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill guardskills --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Guardskills?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Guardskills
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-guardskills/badge)](https://www.skillsdirectory.com/skills/modbender-guardskills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: guardskills
description: Security gate for skill installs. Scans skill content for malicious patterns (credential exfiltration, remote code execution, destructive ops, privilege escalation) before installation. Always run guardskills before installing any skill from ClawHub, GitHub, or local sources.
homepage: https://github.com/felixondesk/guardskills
metadata:
  {
    "openclaw":
      {
        "emoji": "πŸ›‘οΈ",
        "requires": { "bins": ["guardskills"] },
        "install":
          [
            {
              "id": "node",
              "kind": "node",
              "package": "guardskills",
              "bins": ["guardskills"],
              "label": "Install guardskills (npm)",
            },
          ],
      },
  }
---

# GuardSkills β€” Security Scanner for Skills

Static analysis security gate. Scans skill files for malicious patterns and produces a risk decision before allowing installation.

## Rule β€” ALWAYS scan before installing

Before installing any skill (ClawHub, GitHub, local, or skills.sh), you MUST run a guardskills scan first. Never run `clawhub install`, `skills add`, or copy skill files without scanning.

## Scan by source

### 1. ClawHub skills

When the user asks to install a ClawHub skill, scan it first:

```bash
guardskills scan-clawhub <owner/skill-slug>
```

Also accepts full URLs:

```bash
guardskills scan-clawhub https://clawhub.ai/owner/skill-slug
```

### 2. Local skills

When loading or reviewing a skill folder on disk:

```bash
guardskills scan-local <path-to-skill-folder>
```

If the path contains multiple skills:

```bash
guardskills scan-local <path-to-skills-root> --skill <skill-folder-name>
```

### 3. GitHub skills

When installing from a GitHub repository:

```bash
guardskills add owner/repo --skill <skill-name> --dry-run
```

Also accepts full URLs:

```bash
guardskills add https://github.com/owner/repo --skill <skill-name> --dry-run
```

### 4. skills.sh skills

Use the same GitHub flow:

```bash
guardskills add owner/repo --skill <skill-name> --dry-run
```

If scan passes:

```bash
guardskills add owner/repo --skill <skill-name>
```

## How to interpret results

| Decision       | Action                                                       |
| -------------- | ------------------------------------------------------------ |
| `SAFE`         | Proceed with installation.                                   |
| `WARNING`      | Ask the user for confirmation before proceeding.             |
| `UNSAFE`       | Block. Tell the user the skill is unsafe and do not install.  |
| `CRITICAL`     | Block. Do not install under any circumstances.               |
| `UNVERIFIABLE` | Block. Inform the user the skill could not be verified.      |

## Useful flags

- `--json` β€” machine-readable JSON output
- `--dry-run` β€” scan only, do not install
- `--ci` β€” deterministic gate mode (no prompts, no install)
- `--strict` β€” use stricter risk thresholds
- `--yes` β€” auto-accept WARNING level (only if user explicitly requests)
- `--force` β€” override UNSAFE block (only if user explicitly requests)
- `--allow-unverifiable` β€” override UNVERIFIABLE block (only if user explicitly requests)

## Exit codes

- `0` β€” allowed / safe
- `10` β€” warning not confirmed
- `20` β€” blocked (UNSAFE, CRITICAL, or UNVERIFIABLE)
- `30` β€” runtime / internal error

## Recommended workflow

1. User asks to install a skill.
2. Determine the source (ClawHub, GitHub, local, skills.sh).
3. Run the appropriate `guardskills` scan command.
4. Read the decision from the output.
5. If `SAFE`, proceed with `clawhub install` or equivalent.
6. If `WARNING`, inform the user and ask for confirmation.
7. If `UNSAFE`, `CRITICAL`, or `UNVERIFIABLE`, block and explain why.
8. Never skip the scan step.

## Notes

- guardskills is an additional security layer, not a replacement for manual review.
- A `SAFE` result means no known high-risk patterns were detected, not a guarantee of safety.
- The scanner checks for: credential exfiltration, remote code execution chains, destructive filesystem operations, privilege escalation, obfuscated payloads, and suspicious network activity.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…