← All skills
Tencent SkillHub · Security & Compliance

CrawSecure

Offline security scanner that detects unsafe code patterns in ClawHub skills before installation to help users assess potential risks locally.

skill openclawclawhub Free
0 Downloads
0 Stars
0 Installs
0 Score
High Signal

Offline security scanner that detects unsafe code patterns in ClawHub skills before installation to help users assess potential risks locally.

⬇ 0 downloads ★ 0 stars Unverified but indexed

Install for OpenClaw

Quick setup
  1. Download the package from Yavira.
  2. Extract the archive and review SKILL.md first.
  3. Import or place the package into your OpenClaw setup.

Requirements

Target platform
OpenClaw
Install method
Manual import
Extraction
Extract archive
Prerequisites
OpenClaw
Primary doc
SKILL.md

Package facts

Download mode
Yavira redirect
Package format
ZIP package
Source platform
Tencent SkillHub
What's included
SKILL.md, DESCRIPTION.txt

Validation

  • Use the Yavira download entry.
  • Review SKILL.md after the package is downloaded.
  • Confirm the extracted package contains the expected setup assets.

Install with your agent

Agent handoff

Hand the extracted package to your coding agent with a concrete install brief instead of figuring it out manually.

  1. Download the package from Yavira.
  2. Extract it into a folder your agent can access.
  3. Paste one of the prompts below and point your agent at the extracted folder.
New install

I downloaded a skill package from Yavira. Read SKILL.md from the extracted folder and install it by following the included instructions. Tell me what you changed and call out any manual steps you could not complete.

Upgrade existing

I downloaded an updated skill package from Yavira. Read SKILL.md from the extracted folder, compare it with my current installation, and upgrade it while preserving any custom configuration unless the package docs explicitly say otherwise. Summarize what changed and any follow-up checks I should run.

Trust & source

Release facts

Source
Tencent SkillHub
Verification
Indexed source record
Version
2.0.1

Documentation

ClawHub primary doc Primary doc: SKILL.md 8 sections Open source page

CrawSecure

CrawSecure is a documentation-first security skill for the ClawHub / OpenClaw ecosystem. This skill does not include executable code or binaries. Its purpose is to clearly document, explain, and guide the safe usage of the CrawSecure CLI, which is distributed and installed separately by the user. The goal of this skill is to promote security awareness, transparency, and best practices when working with third‑party skills.

🔍 What this skill provides

Clear documentation of what CrawSecure analyzes Explanation of risk signals and classifications Guidance on how to use the CrawSecure CLI safely Security philosophy and trust boundaries ℹ️ This skill itself performs no scans and executes no code.

🧰 About the CrawSecure CLI

The CrawSecure CLI is an external, optional tool that users may install independently. It performs local, offline static analysis of ClawHub / OpenClaw skills before installation or trust.

CLI distribution (external)

Source & releases: https://github.com/diogopaesdev/crawsecure Official website: https://crawsecure.com The CLI is not bundled with this skill.

🚨 Risk signals analyzed by the CLI

When used, the CrawSecure CLI may detect: Dangerous command patterns (e.g. destructive or execution‑related behavior) References to sensitive files or credentials (e.g. .env, .ssh, private keys) Indicators of unsafe or misleading practices Risk levels are classified as: SAFE MEDIUM HIGH

🔒 Security & trust boundaries

This skill: Does not execute code Does not install software Does not access the network Does not modify files Requests read‑only permissions only Any actual scanning happens only if the user installs and runs the CrawSecure CLI from a trusted source.

✅ When to use this skill

To understand what CrawSecure checks and why Before deciding to install or run the CrawSecure CLI As a reference for safer skill development practices To promote transparency inside the ClawHub ecosystem

📦 Version

v2.0.1 – Documentation‑only clarification release This version clarifies scope and removes any ambiguity about bundled execution.

Category context

Identity, auth, scanning, governance, audit, and operational guardrails.

Source: Tencent SkillHub

Largest current source with strong distribution and engagement signals.

Package contents

Included in package
1 Docs1 Files
  • SKILL.md Primary doc
  • DESCRIPTION.txt Files