Skip to content
Back to skills

Openclaw Skill Scanner

FSecurity

Scans ClawHub skills for malicious patterns before and after

  • 14 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
documentationpythongoshellbashapisecurity

Works with

  • api

Security analysis

F0/100
  • criticalPipes output to a shell interpreter
  • criticalExfiltrates credentials via HTTP — exact pattern from Snyk ToxicSkills study
  • criticalExfiltrates credentials via HTTP — exact pattern from Snyk ToxicSkills study
  • criticalDownloads and executes remote scripts — classic supply chain attack
  • criticalDownloads and executes remote scripts — classic supply chain attack

Pro scans all 5 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill openclaw-skill-scanner --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Openclaw Skill Scanner?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Openclaw Skill Scanner
[![Security: F — Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-openclaw-skill-scanner/badge)](https://www.skillsdirectory.com/skills/modbender-openclaw-skill-scanner)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Skill Scanner
description: Scans ClawHub skills for malicious patterns before and after
  installation. Detects base64 payloads, reverse shells, data exfiltration,
  crypto miners, obfuscated URLs, and more.
---

# Skill Scanner

**Name:** skill-scanner
**Version:** 1.0.0
**Author:** vrtlly.us
**Category:** Security

## Description

Scans ClawHub skills for malicious patterns before and after installation. Detects base64 payloads, reverse shells, data exfiltration, crypto miners, obfuscated URLs, and more.

## Usage

### Scan all installed skills
```bash
python3 scanner.py
```

### Scan a specific skill
```bash
python3 scanner.py --skill <skill-name>
```

### Scan a specific file
```bash
python3 scanner.py --file <path-to-file>
```

### Pre-install scan (download → scan → report → cleanup)
```bash
python3 scanner.py --pre-install <clawhub-slug>
```

### JSON output
```bash
python3 scanner.py --json
python3 scanner.py --skill <name> --json
```

### Safe install hook
```bash
bash install-hook.sh <clawhub-slug>
bash install-hook.sh <clawhub-slug> --force
```

## Detection Patterns

| Category | What it catches |
|---|---|
| Base64 payloads | Long base64 strings near exec/bash/eval |
| Pipe to shell | `curl ... \| bash`, `wget ... \| sh` |
| Raw IP connections | `http://1.2.3.4` style URLs |
| Dangerous functions | `eval()`, `exec()`, `os.system()`, `subprocess(shell=True)` |
| Hidden files | Dotfile creation in unexpected places |
| Env exfiltration | Reading `.env`, API keys sent outbound |
| Obfuscated URLs | rentry.co, pastebin, hastebin redirectors |
| Fake dependencies | References to non-existent packages |
| Data exfil endpoints | webhook.site, requestbin, etc. |
| Crypto mining | xmrig, stratum, mining pool references |
| Password archives | Password-protected zip/tar downloads |

## Risk Scores

- **0-29 (Green):** Clean — no suspicious patterns found
- **30-69 (Yellow):** Suspicious — review warnings before use
- **70-100 (Red):** Dangerous — likely malicious, do not install

## Files

- `scanner.py` — Main scanner engine
- `install-hook.sh` — Safe installation wrapper
- `whitelist.json` — Known-good and known-bad skill lists
- `report-template.md` — Markdown report template

Files in this skill

  • SKILL.md2.3 KB
  • install-hook.sh10.8 KB
  • report-template.md1023 B
  • scanner.py33.4 KB
  • whitelist.json1.1 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…