MoltCops — Skill Security Scanner
Scan any skill for security threats before you install it. Detects prompt injection, data exfiltration, sleeper triggers, drain patterns, and 16 more threat categories.
Local-first. Your code never leaves your machine. No API calls. No uploads. No accounts.
When to Use
- Before installing any skill from ClawHub, GitHub, or other sources
- Before running skills shared by other agents
- When evaluating unknown code from any source
- After ClawHavoc: 341 malicious skills were found on ClawHub this week. Scan first.
How to Run
python3 scripts/scan.py <path-to-skill-folder>
Example:
# Scan a skill before installing
python3 scripts/scan.py ~/.openclaw/skills/suspicious-skill
# Scan a freshly downloaded skill
python3 scripts/scan.py ./my-new-skill
No dependencies required — uses only Python 3 standard library.
Reading Results
The scanner returns three verdicts:
| Verdict |
Exit Code |
Meaning |
| PASS |
0 |
No critical or high-risk threats detected. Safe to install. |
| WARN |
1 |
High-risk patterns found. Review findings before installing. |
| BLOCK |
2 |
Critical threats detected. Do NOT install this skill. |
What It Detects
20 detection rules across these threat categories:
| Category |
Rules |
Examples |
| Prompt Injection |
MC-001, MC-002, MC-003 |
System prompt override, jailbreak payloads, tool-use steering |
| Code Injection |
MC-004, MC-005, MC-006, MC-019 |
Shell injection, eval/exec, base64-to-exec, child_process |
| Data Exfiltration |
MC-007, MC-008, MC-009, MC-010, MC-020 |
Webhook URLs, env var harvesting, SSH key access, credential files |
| Hardcoded Secrets |
MC-011, MC-012 |
API keys in source, private key material |
| Financial |
MC-013 |
Drain patterns, unlimited withdrawals |
| Lateral Movement |
MC-014 |
Git credential access, repo manipulation |
| Persistence |
MC-015, MC-016 |
SOUL.md writes, cron job creation |
| Autonomy Abuse |
MC-017 |
Destructive force flags (rm -rf, git push --force) |
| Infrastructure |
MC-018 |
Permission escalation (sudo, chmod 777) |
False Positive Handling
The scanner includes context-aware filtering to reduce false positives:
- Env var access (MC-008): Only flags when variable names contain KEY, SECRET, PASSWORD, TOKEN, or CREDENTIAL
- Git operations (MC-014): Skips standard remotes (github.com, gitlab.com, bitbucket.org)
- Force flags (MC-017): Only flags on destructive operations, not install scripts
Example Output
MoltCops Security Scanner
========================================
Scanning: ./suspicious-skill
Files: 5
Rules: 20
FINDINGS
----------------------------------------
[CRITICAL] MC-007: Exfiltration URL (main.py:14)
[CRITICAL] MC-004: Shell Injection (helper.sh:8)
[HIGH] MC-005: Dynamic Code Execution (main.py:22)
SUMMARY
========================================
Files scanned: 5
Total findings: 3
Critical: 2
High: 1
Medium: 0
VERDICT: BLOCK
Critical threats detected. Do NOT install this skill.
Web Scanner
For a browser-based version with the same engine, visit: https://scan.moltcops.com
About MoltCops
MoltCops protects the AI agent ecosystem from malicious skills. While VirusTotal catches known malware signatures, MoltCops catches behavioral patterns — drain logic, sleeper triggers, prompt injection, and data exfiltration that signature-based scanning misses.
1---2name: moltcops3description: Pre-install security scanner for AI agent skills. Detects malicious patterns before you trust code. Local-first — code never leaves your machine.4---5
6# MoltCops — Skill Security Scanner
7
8Scan any skill for security threats **before** you install it. Detects prompt injection, data exfiltration, sleeper triggers, drain patterns, and 16 more threat categories.
9
10**Local-first.** Your code never leaves your machine. No API calls. No uploads. No accounts.
11
12## When to Use
13
14- **Before installing any skill** from ClawHub, GitHub, or other sources
15- **Before running** skills shared by other agents
16- **When evaluating** unknown code from any source
17- **After ClawHavoc**: 341 malicious skills were found on ClawHub this week. Scan first.
18
19## How to Run
20
21```bash
22python3 scripts/scan.py <path-to-skill-folder>
23```
24
25Example:
26```bash
27# Scan a skill before installing
28python3 scripts/scan.py ~/.openclaw/skills/suspicious-skill
29
30# Scan a freshly downloaded skill
31python3 scripts/scan.py ./my-new-skill
32```
33
34**No dependencies required** — uses only Python 3 standard library.
35
36## Reading Results
37
38The scanner returns three verdicts:
39
40| Verdict | Exit Code | Meaning |
41|---------|-----------|---------|
42| **PASS** | 0 | No critical or high-risk threats detected. Safe to install. |
43| **WARN** | 1 | High-risk patterns found. Review findings before installing. |
44| **BLOCK** | 2 | Critical threats detected. Do NOT install this skill. |
45
46## What It Detects
47
4820 detection rules across these threat categories:
49
50| Category | Rules | Examples |
51|----------|-------|---------|
52| **Prompt Injection** | MC-001, MC-002, MC-003 | System prompt override, jailbreak payloads, tool-use steering |
53| **Code Injection** | MC-004, MC-005, MC-006, MC-019 | Shell injection, eval/exec, base64-to-exec, child_process |
54| **Data Exfiltration** | MC-007, MC-008, MC-009, MC-010, MC-020 | Webhook URLs, env var harvesting, SSH key access, credential files |
55| **Hardcoded Secrets** | MC-011, MC-012 | API keys in source, private key material |
56| **Financial** | MC-013 | Drain patterns, unlimited withdrawals |
57| **Lateral Movement** | MC-014 | Git credential access, repo manipulation |
58| **Persistence** | MC-015, MC-016 | SOUL.md writes, cron job creation |
59| **Autonomy Abuse** | MC-017 | Destructive force flags (rm -rf, git push --force) |
60| **Infrastructure** | MC-018 | Permission escalation (sudo, chmod 777) |
61
62## False Positive Handling
63
64The scanner includes context-aware filtering to reduce false positives:
65
66- **Env var access** (MC-008): Only flags when variable names contain KEY, SECRET, PASSWORD, TOKEN, or CREDENTIAL
67- **Git operations** (MC-014): Skips standard remotes (github.com, gitlab.com, bitbucket.org)
68- **Force flags** (MC-017): Only flags on destructive operations, not install scripts
69
70## Example Output
71
72```
73MoltCops Security Scanner
74========================================
75Scanning: ./suspicious-skill
76Files: 5
77Rules: 20
78
79FINDINGS
80----------------------------------------
81[CRITICAL] MC-007: Exfiltration URL (main.py:14)
82[CRITICAL] MC-004: Shell Injection (helper.sh:8)
83[HIGH] MC-005: Dynamic Code Execution (main.py:22)
84
85SUMMARY
86========================================
87Files scanned: 5
88Total findings: 3
89 Critical: 2
90 High: 1
91 Medium: 0
92
93VERDICT: BLOCK
94Critical threats detected. Do NOT install this skill.
95```
96
97## Web Scanner
98
99For a browser-based version with the same engine, visit: **https://scan.moltcops.com**
100
101## About MoltCops
102
103MoltCops protects the AI agent ecosystem from malicious skills. While VirusTotal catches known malware signatures, MoltCops catches **behavioral patterns** — drain logic, sleeper triggers, prompt injection, and data exfiltration that signature-based scanning misses.
104
105- Web: https://moltcops.com
106- Moltbook: https://moltbook.com/u/MoltCops