Requirements
- Target platform
- OpenClaw
- Install method
- Manual import
- Extraction
- Extract archive
- Prerequisites
- OpenClaw
- Primary doc
- SKILL.md
Scans ClawHub skills for malicious patterns like payloads, reverse shells, data leaks, and crypto miners before and after installation.
Scans ClawHub skills for malicious patterns like payloads, reverse shells, data leaks, and crypto miners before and after installation.
Hand the extracted package to your coding agent with a concrete install brief instead of figuring it out manually.
I downloaded a skill package from Yavira. Read SKILL.md from the extracted folder and install it by following the included instructions. Tell me what you changed and call out any manual steps you could not complete.
I downloaded an updated skill package from Yavira. Read SKILL.md from the extracted folder, compare it with my current installation, and upgrade it while preserving any custom configuration unless the package docs explicitly say otherwise. Summarize what changed and any follow-up checks I should run.
Name: skill-scanner Version: 1.0.0 Author: vrtlly.us Category: Security
Scans ClawHub skills for malicious patterns before and after installation. Detects base64 payloads, reverse shells, data exfiltration, crypto miners, obfuscated URLs, and more.
python3 scanner.py
python3 scanner.py --skill <skill-name>
python3 scanner.py --file <path-to-file>
python3 scanner.py --pre-install <clawhub-slug>
python3 scanner.py --json python3 scanner.py --skill <name> --json
bash install-hook.sh <clawhub-slug> bash install-hook.sh <clawhub-slug> --force
CategoryWhat it catchesBase64 payloadsLong base64 strings near exec/bash/evalPipe to shellcurl ... | bash, wget ... | shRaw IP connectionshttp://1.2.3.4 style URLsDangerous functionseval(), exec(), os.system(), subprocess(shell=True)Hidden filesDotfile creation in unexpected placesEnv exfiltrationReading .env, API keys sent outboundObfuscated URLsrentry.co, pastebin, hastebin redirectorsFake dependenciesReferences to non-existent packagesData exfil endpointswebhook.site, requestbin, etc.Crypto miningxmrig, stratum, mining pool referencesPassword archivesPassword-protected zip/tar downloads
0-29 (Green): Clean โ no suspicious patterns found 30-69 (Yellow): Suspicious โ review warnings before use 70-100 (Red): Dangerous โ likely malicious, do not install
scanner.py โ Main scanner engine install-hook.sh โ Safe installation wrapper whitelist.json โ Known-good and known-bad skill lists report-template.md โ Markdown report template
Identity, auth, scanning, governance, audit, and operational guardrails.
Largest current source with strong distribution and engagement signals.