ClawVet looks like a legitimate security scanner, but its bundled API/dashboard has persistent auth, scan history, cloud analysis, telemetry, and webhook behavior that needs review before deployment.
Install/use the CLI only if you are comfortable with an npm-based scanner that can read the skill files you point it at, audit local OpenClaw skill directories when asked, and optionally use telemetry, remote fetching, and cloud LLM analysis. Do not deploy the bundled API/dashboard for shared or public use without tightening auth, JWT configuration, scan ownership checks, webhook URL restrictions, and provider/telemetry disclosure.