Requirements
- Target platform
- OpenClaw
- Install method
- Manual import
- Extraction
- Extract archive
- Prerequisites
- OpenClaw
- Primary doc
- SKILL.md
Scans ClawHub skills for malicious patterns like payloads, reverse shells, data leaks, and crypto miners before and after installation.
Scans ClawHub skills for malicious patterns like payloads, reverse shells, data leaks, and crypto miners before and after installation.
This item's current download entry is known to bounce back to a listing or homepage instead of returning a package file.
Use the source page and any available docs to guide the install because the item currently does not return a direct package file.
I tried to install a skill package from Yavira, but the item currently does not return a direct package file. Inspect the source page and any extracted docs, then tell me what you can confirm and any manual steps still required.
I tried to upgrade a skill package from Yavira, but the item currently does not return a direct package file. Compare the source page and any extracted docs with my current installation, then summarize what changed and what manual follow-up I still need.
Name: skill-scanner Version: 1.0.0 Author: vrtlly.us Category: Security
Scans ClawHub skills for malicious patterns before and after installation. Detects base64 payloads, reverse shells, data exfiltration, crypto miners, obfuscated URLs, and more.
python3 scanner.py
python3 scanner.py --skill <skill-name>
python3 scanner.py --file <path-to-file>
python3 scanner.py --pre-install <clawhub-slug>
python3 scanner.py --json python3 scanner.py --skill <name> --json
bash install-hook.sh <clawhub-slug> bash install-hook.sh <clawhub-slug> --force
CategoryWhat it catchesBase64 payloadsLong base64 strings near exec/bash/evalPipe to shellcurl ... | bash, wget ... | shRaw IP connectionshttp://1.2.3.4 style URLsDangerous functionseval(), exec(), os.system(), subprocess(shell=True)Hidden filesDotfile creation in unexpected placesEnv exfiltrationReading .env, API keys sent outboundObfuscated URLsrentry.co, pastebin, hastebin redirectorsFake dependenciesReferences to non-existent packagesData exfil endpointswebhook.site, requestbin, etc.Crypto miningxmrig, stratum, mining pool referencesPassword archivesPassword-protected zip/tar downloads
0-29 (Green): Clean โ no suspicious patterns found 30-69 (Yellow): Suspicious โ review warnings before use 70-100 (Red): Dangerous โ likely malicious, do not install
scanner.py โ Main scanner engine install-hook.sh โ Safe installation wrapper whitelist.json โ Known-good and known-bad skill lists report-template.md โ Markdown report template
Identity, auth, scanning, governance, audit, and operational guardrails.
Largest current source with strong distribution and engagement signals.