Skill Security Scanner
Security audit tool for AI agent skills. Run before installing any new skill.
Quick Audit
# Audit a skill directory
./skill-security/audit.sh /path/to/skill
# Audit all installed skills
./skill-security/audit-all.sh
What It Checks
| Check |
Risk Level |
Pattern |
| Network Exfiltration |
🚨 HIGH |
requests., urllib, http.client, socket., fetch(, axios |
| Credential Harvesting |
🚨 HIGH |
.ssh/, .aws/, pass , keyring, credential, secret, token file reads |
| Code Injection |
🚨 CRITICAL |
exec(, eval(, compile(, Function(, __import__ |
| Obfuscation |
⚠️ MEDIUM |
base64.decode, atob, encoded payloads |
| Env Dumping |
⚠️ MEDIUM |
os.environ, process.env, getenv bulk access |
| Subprocess Abuse |
⚠️ MEDIUM |
subprocess.run, os.system, child_process with credentials |
Severity Levels
- CRITICAL (🚨): Block installation, report to owner
- HIGH (🔴): Requires manual review before use
- MEDIUM (🟡): Note but allow if from trusted source
- LOW (🟢): Informational only
Safe Skill Checklist
Before using any skill:
- ✅ Is it from a trusted source? (official OpenClaw, known publisher)
- ✅ Is the code readable (not obfuscated)?
- ✅ Does it document why it needs network/credential access?
- ✅ Does it scope file access to its own directory?
- ✅ Has it been audited by the community?
Integration with AGENTS.md
Add this to your workflow:
## Skill Installation Protocol
Before loading any new skill:
1. Run `./skill-security/audit.sh <skill-path>`
2. If CRITICAL/HIGH findings → STOP, alert the user
3. If MEDIUM findings → Review manually, proceed if justified
4. If CLEAN → Safe to use
Automatic Protection
The scanner creates a blocklist at ./blocklist.txt.
Skills with CRITICAL findings are automatically added.
Manual Override
If a skill is flagged but you've verified it's safe:
echo "skill-name:verified:YYYY-MM-DD:reason" >> allowlist.txt
Premium Skills
Like this? Check out our premium skills at skillpacks.dev:
- 🛡️ Security Suite — Full PII scanning, secrets detection, prompt injection defense — $9.90
- 🧠 Structured Memory — Three-tier memory replacing flat MEMORY.md — $9.90
- 📋 Planning & Execution — Systematic task plans with batch execution — $9.90
- 💎 Bundle — all 3 for $24.90
1---2name: skill-security3description: Security audit tool for AI agent skills. Scans for credential harvesting, code injection, network exfiltration, obfuscation. ALWAYS run before installing any new skill from external sources. Triggers on: new skill installation, skill audit, security scan, skill review, before loading external skill.4---56# Skill Security Scanner78Security audit tool for AI agent skills. **Run before installing any new skill.**910## Quick Audit1112```bash13# Audit a skill directory14./skill-security/audit.sh /path/to/skill1516# Audit all installed skills17./skill-security/audit-all.sh18```1920## What It Checks2122| Check | Risk Level | Pattern |23|-------|------------|---------|24| **Network Exfiltration** | 🚨 HIGH | `requests.`, `urllib`, `http.client`, `socket.`, `fetch(`, `axios` |25| **Credential Harvesting** | 🚨 HIGH | `.ssh/`, `.aws/`, `pass `, `keyring`, `credential`, `secret`, `token` file reads |26| **Code Injection** | 🚨 CRITICAL | `exec(`, `eval(`, `compile(`, `Function(`, `__import__` |27| **Obfuscation** | ⚠️ MEDIUM | `base64.decode`, `atob`, encoded payloads |28| **Env Dumping** | ⚠️ MEDIUM | `os.environ`, `process.env`, `getenv` bulk access |29| **Subprocess Abuse** | ⚠️ MEDIUM | `subprocess.run`, `os.system`, `child_process` with credentials |3031## Severity Levels3233- **CRITICAL** (🚨): Block installation, report to owner34- **HIGH** (🔴): Requires manual review before use35- **MEDIUM** (🟡): Note but allow if from trusted source36- **LOW** (🟢): Informational only3738## Safe Skill Checklist3940Before using any skill:41421. ✅ Is it from a trusted source? (official OpenClaw, known publisher)432. ✅ Is the code readable (not obfuscated)?443. ✅ Does it document why it needs network/credential access?454. ✅ Does it scope file access to its own directory?465. ✅ Has it been audited by the community?4748## Integration with AGENTS.md4950Add this to your workflow:5152```markdown53## Skill Installation Protocol5455Before loading any new skill:561. Run `./skill-security/audit.sh <skill-path>`572. If CRITICAL/HIGH findings → STOP, alert the user583. If MEDIUM findings → Review manually, proceed if justified594. If CLEAN → Safe to use60```6162## Automatic Protection6364The scanner creates a blocklist at `./blocklist.txt`.65Skills with CRITICAL findings are automatically added.6667## Manual Override6869If a skill is flagged but you've verified it's safe:7071```bash72echo "skill-name:verified:YYYY-MM-DD:reason" >> allowlist.txt73```7475---7677## Premium Skills7879Like this? Check out our premium skills at **[skillpacks.dev](https://skillpacks.dev)**:8081- 🛡️ **Security Suite** — Full PII scanning, secrets detection, prompt injection defense — [$9.90](https://polycatai.gumroad.com/l/bsrugo)82- 🧠 **Structured Memory** — Three-tier memory replacing flat MEMORY.md — [$9.90](https://polycatai.gumroad.com/l/goawrg)83- 📋 **Planning & Execution** — Systematic task plans with batch execution — [$9.90](https://polycatai.gumroad.com/l/uydfto)84- 💎 **[Bundle — all 3 for $24.90](https://polycatai.gumroad.com/l/atsrl)**