OpenClaw Skill Analyzer: Static Security Scanner for AI Agent Skills

An OpenClaw developer has released a security scanner that analyzes skills for malicious code before installation. The tool was created in response to the discovery of 341 malicious skills on ClawHub earlier this year.
How It Works
The analyzer performs static analysis on skill folders and provides a clear risk rating: SAFE, LOW, MEDIUM, HIGH, or CRITICAL. You point it at a skill folder and it runs the checks automatically.
Detection Capabilities
The scanner includes 40+ detection rules across 12 categories. Specific detection types mentioned in the source include:
- Prompt injection
- Data exfiltration
- Credential theft
- Backdoors
- Obfuscation
The tool is available on GitHub at https://github.com/papichulomami/openclaw-skill-analyzer.
This type of security tool is particularly useful for developers working with AI coding agents, where third-party skills can introduce significant security risks if not properly vetted.
📖 Read the full source: r/openclaw
👀 See Also
ZCode, Z.ai's GLM Coding Agent, Silently Uploads Your Entire Git History
A reverse-engineering walkthrough of Z.ai's ZCode desktop app shows it packages your entire workspace — .git objects, LFS cache, reflogs — and uploads an encrypted archive to Aliyun OSS. Only Z.ai holds the decryption key.

ClawSecure: Security Platform for OpenClaw Ecosystem with 3-Layer Audit and Real-Time Monitoring
ClawSecure is a dedicated security platform for OpenClaw that performs 3-layer security audits, real-time monitoring with SHA-256 hash tracking every 12 hours, and provides full OWASP ASI coverage. It has audited 3,000+ popular skills and is free to use with no signup required.

Why Internal RAG and Doc-Chat Tools Fail Security Audits
Community discusses real-world security and compliance blockers that prevent RAG tools from reaching production.

Anthropic's Computer-Use Feature Triggers Governance Lockdown in Real Test
Anthropic shipped computer-use capabilities, and during implementation of governance controls, a risk threshold triggered a LOCKDOWN posture that blocked all mutating operations including the operator's own governance work.