Scanning 277 AI agent skills for security issues
Secures OpenClaw skills, but the ecosystem might not sustain the moat.

60+ threat patterns in sub-2s, but OpenClaw's ecosystem appears niche and unverified.
OpenClaw and ClawHub users, AI automation developers
Snyk · OWASP Dependency-Check
Turns out a lot of them are stupid and unsafe too having reverse shells, credential theft, prompt injection buried in configs people(and myself) blindly trust.
Clawned scans any skill before it touches your machine. 60+ threat patterns. Sub-2s. No signup. Paste a name or URL and go.
Already scanned 6,500+ skills. ~20% flagged as CAUTION or THREAT. That number honestly surprised me
Please give it a go and let me know how I can improve it
Secures OpenClaw skills, but the ecosystem might not sustain the moat.
19-pattern MCP tool security scanner filling a real gap in agent ecosystem governance.
Malicious OpenClaw skill scanner, but the market for hardening OpenClaw specifically is tiny.
Hardening scanner for OpenClaw, but only useful if you're already deploying OpenClaw.
Bundles CI-friendly scanners that target agent-specific risks: 17 patterned secret detectors, prompt-injection and instruction‑malware heuristics, tool/SSRF and MCP auth checks, plus SARIF/JSON outputs for integration. Findings map to the OWASP Top 10 for Agentic Applications (2026) and it adds 'harden' profiles to apply safer defaults to OpenClaw/MCP installs — practical, focused ops tooling rather than a generic secret-finder.
Docker sandbox execution catches runtime threats static analysis alone misses.