Skip to content
Back to skills

Pincer

DSecurity

Security-first wrapper for installing agent skills. Scans for malware, prompt injection, and suspicious patterns before installation. Use instead of `clawhub install` for safer skill management.

  • 14 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 7, 2026
securityrustgoshellbashawsgitsecuritydocumentation

Works with

  • mcp

Security analysis

D50/100
  • criticalPipes output to a shell interpreter
  • criticalDownloads and executes remote scripts โ€” classic supply chain attack

Pro scans all 3 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add modbender/skill-library-mcp --skill pincer --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Pincer?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Pincer
[![Security: D โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/modbender-pincer/badge)](https://www.skillsdirectory.com/skills/modbender-pincer)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: pincer
description: Security-first wrapper for installing agent skills. Scans for malware, prompt injection, and suspicious patterns before installation. Use instead of `clawhub install` for safer skill management.
homepage: https://github.com/panzacoder/pincer
metadata:
  openclaw:
    emoji: "๐Ÿฆž"
    requires:
      bins: ["pincer"]
    install:
      - id: symlink
        kind: script
        label: "Install pincer to PATH"
        script: |
          chmod +x "${SKILL_DIR}/scripts/pincer.sh"
          mkdir -p ~/.local/bin
          ln -sf "${SKILL_DIR}/scripts/pincer.sh" ~/.local/bin/pincer
          echo ""
          echo "โœ… pincer installed!"
          echo ""
          echo "Make sure ~/.local/bin is in your PATH:"
          echo '  export PATH="$HOME/.local/bin:$PATH"'
          echo ""
          echo "Usage:"
          echo "  pincer install <skill>  # Safe install with scanning"
          echo "  pincer scan <skill>     # Scan without installing"
          echo "  pincer audit            # Scan all installed skills"
          echo ""
---

# pincer ๐Ÿ›ก๏ธ

Security-first wrapper for `clawhub install`. Scans skills for malware, prompt injection, and suspicious patterns before installation.

## Why?

Agent skills are powerful โ€” they're basically executable documentation. The ClawHub ecosystem has already seen [malware campaigns](https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/) distributing infostealers via innocent-looking skills. pincer adds a security layer before you install anything.

## Install

```bash
# From ClawHub
clawhub install pincer

# Or manually
chmod +x ./scripts/pincer.sh
ln -sf "$(pwd)/scripts/pincer.sh" ~/.local/bin/pincer
```

**Dependencies:**
- `clawhub` โ€” for fetching skills
- `uvx` โ€” for mcp-scan (`brew install uv`)
- `jq` โ€” for JSON parsing

## Usage

### Safe Install

```bash
# Instead of: clawhub install some-skill
pincer install some-skill

# With specific version
pincer install some-skill@1.2.0
```

### Scan Without Installing

```bash
# Scan a ClawHub skill
pincer scan some-skill

# Scan a local directory
pincer scan ./path/to/skill

# JSON output for automation
pincer scan some-skill --json
```

### Audit Installed Skills

```bash
# Quick-scan all installed skills
pincer audit

# JSON output
pincer audit --json
```

### Manage Trust

```bash
# Add trusted publisher (auto-approve clean skills)
pincer trust add steipete

# Remove from trusted
pincer trust remove old-publisher

# Block a publisher or skill
pincer trust block suspicious-dev
pincer trust block malware-skill

# Unblock
pincer trust unblock redeemed-dev

# List all trust settings
pincer trust list
```

### View History

```bash
# See what you've installed
pincer history

# JSON output
pincer history --json
```

### Configuration

```bash
# Show current config
pincer config show

# Edit in $EDITOR
pincer config edit

# Reset to defaults
pincer config reset
```

## What It Checks

### Via mcp-scan (Invariant Labs)
- Prompt injection attacks
- Malware payloads in natural language
- Tool poisoning
- Sensitive data exposure
- Hard-coded secrets

### Additional Pattern Detection
| Pattern | Risk | Description |
|---------|------|-------------|
| Base64 commands | ๐Ÿšจ High | Encoded shell commands |
| Hex payloads | ๐Ÿšจ High | Obfuscated binary data |
| `xattr -d quarantine` | ๐Ÿšจ High | macOS Gatekeeper bypass |
| `curl \| sh` | ๐Ÿšจ High | Pipe to shell execution |
| Password archives | ๐Ÿšจ High | Hidden malicious payloads |
| Download + execute | โš ๏ธ Medium | `chmod +x && ./` patterns |
| `eval $var` | โš ๏ธ Medium | Dynamic code execution |
| Hidden files | โš ๏ธ Medium | Dot-file creation |
| Persistence | โš ๏ธ Medium | cron/launchd entries |

### Publisher & Provenance
- Publisher reputation (trusted list)
- Download count threshold
- Skill age threshold
- Blocklist checking

### Binary Detection
- Scans for bundled executables
- Flags Mach-O, ELF, PE32 binaries

## Risk Levels

| Level | Meaning | Action |
|-------|---------|--------|
| โœ… **CLEAN** | No issues | Auto-approve if trusted publisher |
| โš ๏ธ **CAUTION** | Warnings present | Prompt for approval |
| ๐Ÿšจ **DANGER** | Suspicious patterns | Block (override with `--force`) |
| โ˜ ๏ธ **MALWARE** | Known malicious | Block (cannot override) |
| โ›” **BLOCKED** | On blocklist | Block (cannot override) |

## Configuration

Config: `~/.config/pincer/config.json`

```json
{
  "trustedPublishers": ["openclaw", "steipete", "invariantlabs-ai"],
  "blockedPublishers": [],
  "blockedSkills": [],
  "autoApprove": "clean",
  "logInstalls": true,
  "minDownloads": 0,
  "minAgeDays": 0
}
```

| Key | Description |
|-----|-------------|
| `trustedPublishers` | Publishers whose clean skills auto-approve |
| `blockedPublishers` | Always block these publishers |
| `blockedSkills` | Always block these specific skills |
| `autoApprove` | `"clean"` = auto-approve clean+trusted, `"never"` = always prompt |
| `logInstalls` | Log installations to history file |
| `minDownloads` | Warn if skill has fewer downloads |
| `minAgeDays` | Warn if skill is newer than N days |

## Examples

### Clean Install
```
$ pincer install bird
๐Ÿ›ก๏ธ pincer v1.0.0

  โ†’ Fetching bird from ClawHub...
  Publisher: steipete (trusted)
  Stats: 7363 downloads ยท 27 โ˜… ยท created 1 month ago

๐Ÿ›ก๏ธ pincer Scanning bird...

  โ†’ Running mcp-scan...
  โœ… mcp-scan: passed
  โ†’ Checking for suspicious patterns...
  โœ… Pattern check: passed
  โ†’ Checking external URLs...
  โœ… URL check: passed
  โ†’ Checking for bundled binaries...
  โœ… Binary check: passed

Risk Assessment:
  โœ… CLEAN โ€” No issues detected

  โ†’ Auto-approved (clean + trusted config).
  โ†’ Installing bird...
  โœ… Installed successfully!
```

### Dangerous Skill Blocked
```
$ pincer install sketchy-tool
๐Ÿ›ก๏ธ pincer v1.0.0

  โ†’ Fetching sketchy-tool from ClawHub...
  Publisher: newaccount (unknown)
  Stats: 12 downloads ยท 0 โ˜… ยท created 2 days ago

๐Ÿ›ก๏ธ pincer Scanning sketchy-tool...

  โ†’ Running mcp-scan...
  ๐Ÿšจ mcp-scan: high-risk warnings
  โ†’ Checking for suspicious patterns...
  ๐Ÿšจ Pattern check: suspicious patterns found
    โ€ข curl/wget piped to shell
    โ€ข macOS quarantine removal (xattr)
  โ†’ Checking external URLs...
  โš ๏ธ URL check: external URLs found
    โ€ข http://sketchy-domain.xyz/install
  โ†’ Checking for bundled binaries...
  โœ… Binary check: passed

Risk Assessment:
  ๐Ÿšจ DANGER โ€” Suspicious patterns detected
    โ€ข mcp-scan: high-risk patterns detected
    โ€ข curl/wget piped to shell
    โ€ข macOS quarantine removal (xattr)

  โ˜ ๏ธ Install blocked. Use --force to override (not recommended).
```

## Credits

- [mcp-scan](https://github.com/invariantlabs-ai/mcp-scan) by Invariant Labs โ€” core security scanning
- [1Password Security Research](https://1password.com/blog/from-magic-to-malware-how-openclaws-agent-skills-become-an-attack-surface) โ€” threat analysis that inspired this tool
- [Snyk ToxicSkills Report](https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/) โ€” ecosystem threat research

## License

MIT

---

**Stay safe out there.** ๐Ÿ›ก๏ธ

Files in this skill

  • README.md1.7 KB
  • SKILL.md7.3 KB
  • scripts/pincer.sh30.9 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading commentsโ€ฆ