Top ClawHub Skills
PassAudited by VirusTotal on May 12, 2026.
Overview
Type: OpenClaw Skill Name: topclawhubskills Version: 1.1.0 The skill bundle defines an agent skill to query an external API (`https://topclawhubskills.com/api`) for information about ClawHub skills (downloads, stars, new, certified, deleted, search, stats, health). The `SKILL.md` instructions are clear, well-defined, and solely focus on fetching and formatting this public data. There is no evidence of prompt injection, data exfiltration, malicious execution, persistence mechanisms, or obfuscation. The external API call is a standard and expected function for such a skill, and the instructions do not encourage any harmful interaction with it beyond retrieving data.
Findings (0)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
Users may install recommended skills with less caution because the agent frames certification as a guarantee of safety.
This directs the agent to make an unqualified safety assurance about installable skills. Automated screening may be useful, but presenting it as ensuring safety can cause users to over-trust recommendations.
All certified skills on ClawHub have been verified through automated security screening ... to ensure skills are safe to install.
Present certification as a reported screening status, not a guarantee; encourage users to review permissions, source, and current scan results before installing any skill.
Recommendations, popularity rankings, and certification labels depend on the availability and correctness of the external API.
The skill depends on a remote service for rankings and certification data. This is disclosed and purpose-aligned, but users should understand the results are supplied by that external API rather than independently verified by the skill.
API Base URL ``` https://topclawhubskills.com/api ```
Treat API results as informational and verify important security or installation decisions through ClawHub’s official skill pages or other trusted review sources.
