Back to browse
Clawned.io Crowdsource public security scanner for OpenClaw skills

Clawned.io Crowdsource public security scanner for OpenClaw skills

by jensec·Feb 26, 2026·1 point·2 comments

AI Analysis

●●SolidSolve My ProblemShip It

60+ threat patterns in sub-2s, but OpenClaw's ecosystem appears niche and unverified.

Strengths
  • Addresses real supply-chain risk: 20% of 6.5k scanned skills flagged as malicious.
  • Rule-first extraction + AI confidence labeling means transparent, auditable threat detection.
  • Zero signup friction; immediate utility for paranoid automation users.
Weaknesses
  • OpenClaw adoption unclear—ecosystem size and user base unverified at launch.
  • No public threat database or CVE mappings; patterns are proprietary and opaque.
Category
Target Audience

OpenClaw and ClawHub users, AI automation developers

Similar To

Snyk · OWASP Dependency-Check

Post Description

Hey HN, I built Clawned because I got mass downloading OpenClaw skills without reading a single SKILL.md. That felt stupid.

Turns out a lot of them are stupid and unsafe too having reverse shells, credential theft, prompt injection buried in configs people(and myself) blindly trust.

Clawned scans any skill before it touches your machine. 60+ threat patterns. Sub-2s. No signup. Paste a name or URL and go.

Already scanned 6,500+ skills. ~20% flagged as CAUTION or THREAT. That number honestly surprised me

Please give it a go and let me know how I can improve it

Similar Projects

Security●●Solid

Agentsec – Security scanner for AI agent installations (MCP, OpenClaw)

Bundles CI-friendly scanners that target agent-specific risks: 17 patterned secret detectors, prompt-injection and instruction‑malware heuristics, tool/SSRF and MCP auth checks, plus SARIF/JSON outputs for integration. Findings map to the OWASP Top 10 for Agentic Applications (2026) and it adds 'harden' profiles to apply safer defaults to OpenClaw/MCP installs — practical, focused ops tooling rather than a generic secret-finder.

Niche GemSolve My Problem
debu_sinha_1
233mo ago
Security●●●Banger

A security scanner for AI Agent Skills

Docker sandbox execution catches runtime threats static analysis alone misses.

Big BrainBold Bet
mayziem
502mo ago