Skip to main content

Security Dashboard

Monitor security scores and issues across all skills in the directory.

How we make skill installs safer

The ClawHavoc incident in the OpenClaw ecosystem showed a real risk: a SKILL.md file can look normal while hiding malicious instructions. That can lead to command execution, data exfiltration, or credential theft.

Direct installs from random GitHub repositories put the full security review burden on each user. Most teams do not have time to manually audit every skill file before installing it.

agentskill.sh uses a two-layer model: centralized scanning on the platform plus local verification in /learn at install time. This gives both broad coverage and a final check before files are written.

Exactly what we do to improve security

  1. We run server-side static analysis on every skill across 12 threat categories.
  2. We assign a normalized 0-100 security score with issue severity and category details.
  3. We show the score and metadata in /learn before installation starts.
  4. We warn on low scores (<50) and require explicit confirmation for very low scores (<30).
  5. We continuously rescan skills and ingest new reports to refresh risk signals.
  6. We self-check /learn updates with content SHA verification to avoid stale security logic.
For safer installs, use /learn and review this dashboard instead of blindly cloning unknown skill files. For incident context, see CrowdStrike's OpenClaw analysis .

Score Distribution

Excellent (90-100)88,383
Good (70-89)10,468
Medium (50-69)4,084
Low (25-49)1,900
Critical (0-24)2,373

Issues by Severity

Critical
1,430
High
12,106
Medium
99,366
Low
222,081

Top Issue Categories

External Calls172,590
Sensitive File Access56,812
Command Injection53,738
Data Exfiltration47,961
Credential Harvesting2,054
Obfuscation1,676
Prompt Injection136
Persistence9
Staged Malware4
Social Engineering2
ClickFix Attack1

Low Security Skills

(score below 70)
sickn33sickn33/frontend-mobile-development-component-scaffold
0
sickn33sickn33/cloud-penetration-testing
3 high 0
openclawopenclaw/kosmi-dj
6 high 0
sickn33sickn33/bash-pro
13 high 0
agenticnotetakingagenticnotetaking/reseed
18 high 0
openclawopenclaw/osint-investigator
0
githubgithub/project-workflow-analysis-blueprint-generator
1 high 0
openclawopenclaw/wp-to-static
3 critical 4 high 0
openclawopenclaw/canary
7 critical 1 high 0
openclawopenclaw/dns-networking
0
openclawopenclaw/dm-bot
0
openclawopenclaw/openkrill
1 high 0
agenticnotetakingagenticnotetaking/add-domain
14 high 0
openclawopenclaw/opengraph-io
0
openclawopenclaw/stock-evaluator-v3
0
sickn33sickn33/file-path-traversal
5 critical 31 high 0
sickn33sickn33/iterate-pr
6 high 0
danielmiesslerdanielmiessler/Documents
0
openclawopenclaw/kryptogo-meme-trader
0
openclawopenclaw/planning-with-files
3 critical 2 high 0
openclawopenclaw/kirk-content-pipeline
1 critical 0
openclawopenclaw/nutrient-document-processing
0
openclawopenclaw/fomo-research
0
sickn33sickn33/github-workflow-automation
6 critical 15 high 0
agenticnotetakingagenticnotetaking/setup
36 high 0
sickn33sickn33/convex
2 high 0
openclawopenclaw/credential-manager
0
openclawopenclaw/skill-security-scanner
2 critical 3 high 0
sickn33sickn33/cal-com-automation
0
openclawopenclaw/emergency-rescue
6 high 0
agenticnotetakingagenticnotetaking/ask
13 high 0
openclawopenclaw/skillguard
3 critical 1 high 0
sickn33sickn33/incident-runbook-templates
7 high 0
openclawopenclaw/security-scanner
7 critical 3 high 0
githubgithub/write-coding-standards-from-file
38 high 0
openclawopenclaw/skillvet
7 critical 3 high 0
sickn33sickn33/linux-privilege-escalation
10 high 0
openclawopenclaw/security-sentinel
3 critical 3 high 0
openclawopenclaw/ssh-tunnel
2 critical 23 high 0
openclawopenclaw/imap-idle
14 high 0
openclawopenclaw/clawtime
1 critical 2 high 0
openclawopenclaw/permission-creep-scanner
6 critical 1 high 0
openclawopenclaw/better-auth
1 high 0
openclawopenclaw/security-check
6 critical 1 high 0
openclawopenclaw/veryfi-documents-ai
0
openclawopenclaw/protocol-doc-auditor
5 critical 2 high 0
openclawopenclaw/vigil
3 critical 1 high 0
openclawopenclaw/vault0
4 high 0
openclawopenclaw/keychain-bridge
42 high 0
trailofbitstrailofbits/semgrep-rule-creator
1 critical 5 high 0