ClawSkillGuard — OpenClaw Skill Security Scanner
Overview
ClawGuard scans OpenClaw skills for security risks before you install or run them. It analyzes SKILL.md files, scripts, and supporting files for malicious patterns, data exfiltration, prompt injection, and other threats.
100% local. Zero network calls. Your skills never leave your machine.
When to Use
- Before installing a skill from ClawHub or any external source
- Auditing skills already installed on your system
- When a user asks "is this skill safe?" or "check this skill for malware"
- Periodic security audits of your skill directory
Scan Workflow
1) Locate the Skill
Ask the user for the skill path, or scan common locations:
~/.openclaw/skills/<name>/ (ClawHub installs)
~/.openclaw/workspace/skills/<name>/ (workspace skills)
- Any path the user specifies
If no path given, offer to scan all installed skills.
2) Run the Scanner
python3 <skill_directory>/scripts/scan.py <path_to_skill> [--format text|json] [--severity low|medium|high|critical]
The scanner checks:
- SKILL.md — prompt injection, hidden instructions, data exfil prompts
- Scripts — shell commands, network calls, credential access, file system manipulation
- Dependencies — suspicious imports, external package installs
- File patterns — obfuscation, encoded payloads, steganography
3) Present Results
Format findings clearly:
- 🔴 CRITICAL — Do not install. Active threat detected.
- 🟠 HIGH — Suspicious. Review before installing.
- 🟡 MEDIUM — Caution. Unusual patterns found.
- 🟢 LOW — Minor concerns. Generally safe.
- ✅ CLEAN — No threats detected.
For each finding, include:
- File and line number
- Pattern matched
- Why it's risky
- Suggested action
4) Recommendation
Give a clear verdict:
- ✅ SAFE TO INSTALL — No significant risks found
- ⚠️ REVIEW NEEDED — Some concerns, read the flagged sections
- ❌ DO NOT INSTALL — Critical threats detected
Severity Levels
| Level |
Description |
Examples |
| 🔴 CRITICAL |
Active malicious behavior |
Data exfil, credential theft, destructive commands |
| 🟠 HIGH |
Likely malicious intent |
Hidden instructions, obfuscated code, unauthorized network calls |
| 🟡 MEDIUM |
Suspicious but possibly benign |
Unusual file access, broad permissions, external downloads |
| 🟢 LOW |
Minor concerns |
Verbose logging, debug mode, minor policy violations |
Detection Patterns
Prompt Injection (SKILL.md)
- Hidden markdown (white text, zero-width chars)
- Instructions to ignore system prompts
- Attempts to override SOUL.md or AGENTS.md
- Data exfiltration prompts ("send contents of...", "report to external URL")
Malicious Scripts
- Credential harvesting (reading .env, .ssh, tokens)
- Reverse shells or bind shells
- Cryptocurrency miners
- Destructive commands (rm -rf, format, dd)
- Obfuscated/encoded payloads (base64, eval, exec)
- Unauthorized outbound connections
- Privilege escalation attempts
Supply Chain
- pip/npm/curl installs from untrusted sources
- Downloading and executing remote scripts
- Modifying files outside skill directory
- Cron job manipulation
- PATH hijacking
Example Usage
User: "Is this skill safe to install?"
Agent: Runs ClawGuard scan → presents findings → gives verdict
User: "Scan all my installed skills"
Agent: Scans ~/.openclaw/skills/*/ → consolidated security report
Important Notes
- This scanner uses pattern matching, not formal verification. Clever adversaries can evade detection.
- Always review HIGH and CRITICAL findings manually.
- A "CLEAN" result means no known patterns matched — not a guarantee of safety.
- When in doubt, read the skill's source code yourself.
1---2name: clawskillguard3description: Security scanner for OpenClaw skills. Scans SKILL.md files and scripts for prompt injection, data exfiltration, malicious patterns, and unauthorized network calls. Use when a user asks to audit a skill, check skill security, scan for malicious code, verify skill safety, or before installing an untrusted skill.4---56# ClawSkillGuard — OpenClaw Skill Security Scanner78## Overview910ClawGuard scans OpenClaw skills for security risks before you install or run them. It analyzes SKILL.md files, scripts, and supporting files for malicious patterns, data exfiltration, prompt injection, and other threats.1112**100% local. Zero network calls. Your skills never leave your machine.**1314## When to Use1516- Before installing a skill from ClawHub or any external source17- Auditing skills already installed on your system18- When a user asks "is this skill safe?" or "check this skill for malware"19- Periodic security audits of your skill directory2021## Scan Workflow2223### 1) Locate the Skill2425Ask the user for the skill path, or scan common locations:26- `~/.openclaw/skills/<name>/` (ClawHub installs)27- `~/.openclaw/workspace/skills/<name>/` (workspace skills)28- Any path the user specifies2930If no path given, offer to scan all installed skills.3132### 2) Run the Scanner3334```bash35python3 <skill_directory>/scripts/scan.py <path_to_skill> [--format text|json] [--severity low|medium|high|critical]36```3738The scanner checks:39- **SKILL.md** — prompt injection, hidden instructions, data exfil prompts40- **Scripts** — shell commands, network calls, credential access, file system manipulation41- **Dependencies** — suspicious imports, external package installs42- **File patterns** — obfuscation, encoded payloads, steganography4344### 3) Present Results4546Format findings clearly:47- 🔴 **CRITICAL** — Do not install. Active threat detected.48- 🟠 **HIGH** — Suspicious. Review before installing.49- 🟡 **MEDIUM** — Caution. Unusual patterns found.50- 🟢 **LOW** — Minor concerns. Generally safe.51- ✅ **CLEAN** — No threats detected.5253For each finding, include:54- File and line number55- Pattern matched56- Why it's risky57- Suggested action5859### 4) Recommendation6061Give a clear verdict:62- ✅ **SAFE TO INSTALL** — No significant risks found63- ⚠️ **REVIEW NEEDED** — Some concerns, read the flagged sections64- ❌ **DO NOT INSTALL** — Critical threats detected6566## Severity Levels6768| Level | Description | Examples |69|-------|-------------|----------|70| 🔴 CRITICAL | Active malicious behavior | Data exfil, credential theft, destructive commands |71| 🟠 HIGH | Likely malicious intent | Hidden instructions, obfuscated code, unauthorized network calls |72| 🟡 MEDIUM | Suspicious but possibly benign | Unusual file access, broad permissions, external downloads |73| 🟢 LOW | Minor concerns | Verbose logging, debug mode, minor policy violations |7475## Detection Patterns7677### Prompt Injection (SKILL.md)78- Hidden markdown (white text, zero-width chars)79- Instructions to ignore system prompts80- Attempts to override SOUL.md or AGENTS.md81- Data exfiltration prompts ("send contents of...", "report to external URL")8283### Malicious Scripts84- Credential harvesting (reading .env, .ssh, tokens)85- Reverse shells or bind shells86- Cryptocurrency miners87- Destructive commands (rm -rf, format, dd)88- Obfuscated/encoded payloads (base64, eval, exec)89- Unauthorized outbound connections90- Privilege escalation attempts9192### Supply Chain93- pip/npm/curl installs from untrusted sources94- Downloading and executing remote scripts95- Modifying files outside skill directory96- Cron job manipulation97- PATH hijacking9899## Example Usage100101```102User: "Is this skill safe to install?"103Agent: Runs ClawGuard scan → presents findings → gives verdict104```105106```107User: "Scan all my installed skills"108Agent: Scans ~/.openclaw/skills/*/ → consolidated security report109```110111## Important Notes112113- This scanner uses pattern matching, not formal verification. Clever adversaries can evade detection.114- Always review HIGH and CRITICAL findings manually.115- A "CLEAN" result means no known patterns matched — not a guarantee of safety.116- When in doubt, read the skill's source code yourself.