Skip to content
Back to skills

Openclaw Signet

ASecurity

Cryptographic verification for installed skills. Sign skills at

  • 14 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
ai-agentspythonrustbash

Works with

  • claude code
  • cursor

Security analysis

A92/100
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro scans all 3 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill openclaw-signet --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Openclaw Signet?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Openclaw Signet
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-openclaw-signet/badge)](https://www.skillsdirectory.com/skills/modbender-openclaw-signet)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: openclaw-signet
description: Cryptographic verification for installed skills. Sign skills at
  install time, verify they haven't been tampered with later.
---


# OpenClaw Signet

Cryptographic verification for installed skills. Sign skills at install time, verify they haven't been tampered with later.

## The Problem

You install a skill and it works. Days later, a compromised process modifies files inside the skill directory — injecting code, altering behavior, adding exfiltration. All current defenses are heuristic (regex pattern matching). Nothing mathematically verifies that installed code is unchanged.


## Commands

### Sign Skills

Generate SHA-256 content hashes for all installed skills and store in trust manifest.

```bash
python3 {baseDir}/scripts/signet.py sign --workspace /path/to/workspace
```

### Sign Single Skill

```bash
python3 {baseDir}/scripts/signet.py sign openclaw-warden --workspace /path/to/workspace
```

### Verify Skills

Compare current skill state against trusted signatures.

```bash
python3 {baseDir}/scripts/signet.py verify --workspace /path/to/workspace
```

### List Signed Skills

```bash
python3 {baseDir}/scripts/signet.py list --workspace /path/to/workspace
```

### Quick Status

```bash
python3 {baseDir}/scripts/signet.py status --workspace /path/to/workspace
```

## How It Works

1. `sign` computes SHA-256 hashes of every file in each skill directory
2. A composite hash represents the entire skill state
3. `verify` recomputes hashes and compares against the manifest
4. If any file is modified, added, or removed — the composite hash changes
5. Reports exactly which files changed within each tampered skill

## Exit Codes

- `0` — All skills verified
- `1` — Unsigned skills detected
- `2` — Tampered skills detected

## No External Dependencies

Python standard library only. No pip install. No network calls. Everything runs locally.

## Cross-Platform

Works with OpenClaw, Claude Code, Cursor, and any tool using the Agent Skills specification.

Files in this skill

  • README.md1.6 KB
  • SKILL.md2 KB
  • scripts/signet.py24.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…