abyousef739/clawskillshield/SKILL.md
# ClawSkillShield 🛡️ **Local-first security scanner for OpenClaw/ClawHub skills.** ## What It Does - **Static analysis** for security risks and malware patterns - **Detects**: - Hardcoded secrets (API keys, credentials, private keys) - Risky imports (`os`, `subprocess`, `socket`, `ctypes`) - Dangerous calls (`eval()`, `exec()`, `open()`) - Obfuscation (base64 blobs, suspicious encoding) - Hardcoded IPs - **Risk scoring** (0–10) + detailed threat reports - **Quarantine
npx skillsauth add openclaw/skills abyousef739/clawskillshieldInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Local-first security scanner for OpenClaw/ClawHub skills.
os, subprocess, socket, ctypes)eval(), exec(), open())pip install -e .
clawskillshield scan-local /path/to/skill
clawskillshield quarantine /path/to/skill
from clawskillshield import scan_local, quarantine
threats = scan_local("/path/to/skill")
if risk_score < 4: # HIGH RISK
quarantine("/path/to/skill")
Pure Python. No network calls. Runs entirely locally.
ClawHavoc demonstrated how easily malicious skills can slip into the ecosystem. ClawSkillShield provides a trusted, open-source defense layer—audit the code, run offline, stay safe.
GitHub: https://github.com/AbYousef739/clawskillshield
License: MIT
Author: Ab Yousef
Contact: [email protected]
tools
Use when the user wants to connect to, test, or use the McDonalds service at mcp.mcd.cn, including checking authentication, probing MCP endpoints, listing tools, or calling McDonalds MCP tools through a reusable local CLI.
development
Web scraping platform — Twitter/X data, Vinted marketplace, and general web scraping API
development
SlowMist AI Agent Security Review — comprehensive security framework for skills, repositories, URLs, on-chain addresses, and products (Claude Code version)
data-ai
去除中文文本中的 AI 写作痕迹,使其读起来自然。基于维基百科 AI 写作特征指南,检测 24 种 AI 模式。触发词:humanizer-cn、去除 AI 痕迹、去除 AI 写作痕迹、中文文本人性化。