Security scanner for OpenClaw skill packages. Scans skills for malicious code, evasion techniques, prompt injection, and misaligned behavior BEFORE installation. Use to audit any skill from ClawHub or local directories.
Initial release of skill-scan – a multi-layered security scanner for OpenClaw skills. - Scans skills (local or from ClawHub) for malicious code, evasion, prompt injection, and misaligned behavior before installation. - Features 6 analysis layers, 60+ detection rules, and context-aware scoring to reduce false positives. - Supports static and optional LLM-powered deep inspection. - Provides detailed risk scores with actionable exit codes for automation. - Integrates with agent workflows via AGENTS.md templates (automatic or manual scanning). - Flexible output (text, JSON, compact, quiet) and supports batch audits.