Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Devin Floyd

v1.0.0

Security scanner for OpenClaw/Clawdbot skills - detect malicious patterns before installation

0· 550· 1 versions· 0 current· 0 all-time· Updated 7h ago· MIT-0
byDevin Floyd@devinfloyd1

Install

openclaw skills install clawguarddevin

ClawGuard

Security Scanner for OpenClaw/Clawdbot Skills

Protect yourself from malicious skill installations. ClawGuard scans skills for dangerous patterns before you install them - including patterns from the ClawHavoc campaign (341 malicious skills discovered by Koi Security).

Quick Start

# Scan a skill by name
python scan.py --skill <skill-name>

# Scan a skill by path  
python scan.py --path /path/to/skill

# Scan all installed skills
python scan.py --all

What It Detects

CategoryExamplesSeverity
🔴 Reverse Shellssocket.connect(), pty.spawn(), /dev/tcpCritical
🔴 Data Exfiltrationrequests.post() to suspicious TLDsCritical
🔴 Credential HarvestReading ~/.ssh/id_rsa, AWS credentialsCritical
🔴 Obfuscationbase64.b64decode(exec), chr() chainsCritical
🔴 ClawHavoc IOCsglot.io scripts, fake Apple URLs, known C2 IPsCritical
🟠 Code Executionexec(), eval(), subprocessHigh
🟡 Suspicious NetworkURL shorteners, weird portsMedium

Output Formats

# Console (default) - colored terminal output
python scan.py --skill github

# JSON - machine-readable for CI/CD
python scan.py --skill github --format json

# Markdown - for sharing reports
python scan.py --skill github --format markdown

Risk Scoring

ScoreLevelAction
0-10🟢 SafeInstall freely
11-25🟢 LowQuick review
26-50🟡 MediumReview findings
51-75🔴 HighReview carefully
76-100🔴 CriticalDo not install

IOC Database

70+ indicators of compromise including:

  • Remote access (reverse shells, C2)
  • Data exfiltration
  • Credential harvesting
  • Code obfuscation
  • Real ClawHavoc campaign IOCs (from Koi Security research)
  • Known malicious IPs, hashes, and skill names

Requirements

  • Python 3.8+
  • No external dependencies (stdlib only)

Credits

IOCs enriched with research from Koi Security - ClawHavoc campaign analysis by Oren Yomtov and Alex.

Links


Built for the Clawdbot community 🐾

Version tags

latestvk970fjvh5fe9a5xck5bwcdj98s81ctz4

Runtime requirements

🛡️ Clawdis
OSmacOS · Linux · Windows