Browse 22951+ OpenClaw skills with independent security analysis. Every skill scanned. No AI. No black boxes.
22951
Skills Scanned
0
Flagged Risky
11
Security Signals
Deterministic. No AI. No black boxes. Every skill is scored using 11 weighted signals that detect supply chain risks, suspicious code, and packaging anomalies.
| Signal | Weight | Severity | Description |
|---|---|---|---|
| clawhub_flagged | +3.0 | critical | Flagged by ClawHub moderation system |
| suspicious_handler | +2.0 | high | Contains executable handler code |
| executable_content | +2.0 | high | Files with executable MIME types |
| hidden_dotfile | +1.5 | high | Hidden dotfiles (.env, .ssh, etc.) |
| binary_file | +1.5 | high | Binary files in skill package |
| new_publisher_many_files | +1.5 | medium | New publisher with complex package |
| suspicious_filename | +1.5 | medium | Filenames containing backdoor/exploit/payload |
| missing_skill_md | +1.0 | low | No skill.md documentation when files exist |
| large_file | +1.0 | low | Files larger than 100KB (anomalous for skills) |
| rapid_version_churn | +1.0 | medium | Rapid version publishing pattern |
| excessive_files | +0.5 | info | Unusually high file count for a skill |
Clean
0 – 1.0
Low
1.1 – 3.0
Medium
3.1 – 5.0
High
5.1 – 7.0
Critical
7.1 – 10.0
Risk score = sum of all triggered signal weights. Capped at 10.0.
Every skill in the ClawHub registry is rescanned every 6 hours. Verdicts update automatically.
Last scan: Jun 30, 2026, 12:00 AM
Protected by Clawkeeper
Free to scan. Pro to deploy. Start protecting your AI agents today.