Install
openclaw skills install @vnbochkarev-netizen/skill-injection-scannerScan agent skill files for hidden instructions and prompt-injection patterns (EN/RU) before a poisoned skill rewrites your agent. 19 rules, zero dependencies. Use ONLY with the user's explicit consent: tell the user which skills folder will be scanned — findings are printed to stdout locally.
openclaw skills install @vnbochkarev-netizen/skill-injection-scannerLocal-first. No telemetry, no cloud sync — the files you scan never leave your machine.
# from this package (or the git repo: github.com/vnbochkarev-netizen/skill-injection-scanner)
python3 scanner.py --skills ~/.openclaw/skills
python3 scanner.py --skills ~/.claude/skills --format json
python3 scanner.py --skills /path/to/skills --exclude .bak --include-code-spans
<|system|> / ```system markerscurl | bash, git clone … && run), instruction extraction from attachments/imagesContext-aware scoring: security docs that describe injections, «show, don't tell» writing advice,
code-span examples and trusted hosts (github.com, docs.python.org, …) are not flagged; unknown
hosts stay HIGH with a «verify the source» note. --self-test exits 1 if fixtures/ are missing
— it can never report a fake green. Note: the packaged copy has no fixtures/ (marketplace policy);
run --self-test from the git repo, which ships them.
| What | Where | How to delete |
|---|---|---|
| Read file contents of the folder you point at | in memory only | nothing is written; findings go to stdout |
| Findings (file:line, rule, snippet) | stdout / --format json | close the terminal / redirect to a file and delete it |
Get explicit consent before scanning a folder: tell the user what will be read. The tool writes nothing, phones nothing and keeps no logs.
MIT © 2026 Viacheslav Bochkarev. Free to use, modify and redistribute.