Requirements
- Target platform
- OpenClaw
- Install method
- Manual import
- Extraction
- Extract archive
- Prerequisites
- OpenClaw
- Primary doc
- SKILL.md
AI-powered security scanner for OpenClaw skills. Scans skill files for credential theft, data exfiltration, reverse shells, obfuscation, and other threats be...
AI-powered security scanner for OpenClaw skills. Scans skill files for credential theft, data exfiltration, reverse shells, obfuscation, and other threats be...
This item's current download entry is known to bounce back to a listing or homepage instead of returning a package file.
Use the source page and any available docs to guide the install because the item currently does not return a direct package file.
I tried to install a skill package from Yavira, but the item currently does not return a direct package file. Inspect the source page and any extracted docs, then tell me what you can confirm and any manual steps still required. Then review README.md for any prerequisites, environment setup, or post-install checks.
I tried to upgrade a skill package from Yavira, but the item currently does not return a direct package file. Compare the source page and any extracted docs with my current installation, then summarize what changed and what manual follow-up I still need. Then review README.md for any prerequisites, environment setup, or post-install checks.
AI-powered security scanner for OpenClaw skills. Analyzes skill code for malicious behaviour before you install it.
skillguard install <skill-name> Downloads the skill to a temp directory, runs AI security analysis, shows verdict, then asks for confirmation before installing via clawhub. Example: skillguard install my-new-skill
skillguard audit Scans all skills in /usr/lib/node_modules/openclaw/skills/, ~/.openclaw/workspace/skills/, and ~/.openclaw/skills/. Prints a table summary with details on any flagged skills.
skillguard scan <path> Scan any local skill directory without installing. Useful for reviewing skills you've already downloaded or developed locally. Example: skillguard scan ./my-skill-folder skillguard scan /usr/lib/node_modules/openclaw/skills/some-skill
LevelMeaning✅ CLEANNo security issues detected🟡 LOWMinor concerns, generally safe⚠️ MEDIUMReview recommended before installing🚨 HIGHDangerous — do not install without careful manual review
Credential theft: Reads to ~/.ssh/, ~/.openclaw/, API keys, .env files Data exfiltration: curl/wget/fetch POSTing data to external servers Reverse shells: netcat, bash TCP redirects, socat to external IPs Privilege escalation: sudo abuse, setuid bits, writing to /etc/ Persistence: cron installs, systemd units, .bashrc modifications Obfuscation: base64-piped-to-bash, eval with dynamic content Package smuggling: undisclosed npm/pip installs Reconnaissance: network scanning, system info harvesting
When the user asks to install a skill, use skillguard first: python3 /root/.openclaw/workspace/skills/skillguard/skillguard.py install <skill-name> When the user asks to check their installed skills for security issues: python3 /root/.openclaw/workspace/skills/skillguard/skillguard.py audit When the user asks to check a specific local skill directory: python3 /root/.openclaw/workspace/skills/skillguard/skillguard.py scan /path/to/skill
Clean skill: ✅ SkillGuard: good-skill — Clean. Installing... Flagged skill: 🚨 SkillGuard: bad-skill — Risk: HIGH Reads /root/.openclaw/*.json and POSTs to external IP. [HIGH] Data Exfiltration: curl POST of ~/.openclaw/openclaw.json to 45.33.32.156 [scripts/init.sh:14-22] [MEDIUM] Credential Theft: Reads ~/.ssh/id_rsa without disclosure [scripts/setup.sh:8] Install bad-skill anyway? (type YES to confirm)
Python 3.6+ An Anthropic, OpenRouter, or DeepSeek API key configured in OpenClaw clawhub CLI (for install command only)
Binary files are automatically skipped Files larger than 100KB are truncated before analysis Analysis uses Claude Opus (or best available model) for maximum accuracy The scan itself is safe — skills are text files, not executed during scanning
Identity, auth, scanning, governance, audit, and operational guardrails.
Largest current source with strong distribution and engagement signals.