Skip to main content

Security Dashboard

Monitor security scores and issues across all skills in the directory.

How we make skill installs safer

The ClawHavoc incident in the OpenClaw ecosystem showed a real risk: a SKILL.md file can look normal while hiding malicious instructions. That can lead to command execution, data exfiltration, or credential theft.

Direct installs from random GitHub repositories put the full security review burden on each user. Most teams do not have time to manually audit every skill file before installing it.

agentskill.sh uses a two-layer model: centralized scanning on the platform plus local verification in /learn at install time. This gives both broad coverage and a final check before files are written.

Exactly what we do to improve security

  1. We run server-side static analysis on every skill across 12 threat categories.
  2. We assign a normalized 0-100 security score with issue severity and category details.
  3. We show the score and metadata in /learn before installation starts.
  4. We warn on low scores (<50) and require explicit confirmation for very low scores (<30).
  5. We continuously rescan skills and ingest new reports to refresh risk signals.
  6. We self-check /learn updates with content SHA verification to avoid stale security logic.
For safer installs, use /learn and review this dashboard instead of blindly cloning unknown skill files. For incident context, see CrowdStrike's OpenClaw analysis .

Score Distribution

Excellent (90-100)88,387
Good (70-89)10,469
Medium (50-69)4,084
Low (25-49)1,900
Critical (0-24)2,373

Issues by Severity

Critical
1,430
High
12,106
Medium
99,368
Low
222,104

Top Issue Categories

External Calls172,607
Sensitive File Access56,817
Command Injection53,741
Data Exfiltration47,961
Credential Harvesting2,054
Obfuscation1,676
Prompt Injection136
Persistence9
Staged Malware4
Social Engineering2
ClickFix Attack1

Low Security Skills

(score below 70)
sickn33sickn33/frontend-mobile-development-component-scaffold
0
openclawopenclaw/clawtime
1 critical 2 high 0
openclawopenclaw/security-scanner
7 critical 3 high 0
sickn33sickn33/bash-pro
13 high 0
agenticnotetakingagenticnotetaking/reseed
18 high 0
openclawopenclaw/skill-security-scanner
2 critical 3 high 0
githubgithub/project-workflow-analysis-blueprint-generator
1 high 0
openclawopenclaw/better-auth
1 high 0
openclawopenclaw/canary
7 critical 1 high 0
openclawopenclaw/emergency-rescue
6 high 0
openclawopenclaw/skillguard
3 critical 1 high 0
trailofbitstrailofbits/semgrep-rule-creator
1 critical 5 high 0
agenticnotetakingagenticnotetaking/add-domain
14 high 0
openclawopenclaw/openkrill
1 high 0
agenticnotetakingagenticnotetaking/setup
36 high 0
sickn33sickn33/file-path-traversal
5 critical 31 high 0
sickn33sickn33/iterate-pr
6 high 0
danielmiesslerdanielmiessler/Documents
0
openclawopenclaw/vigil
3 critical 1 high 0
openclawopenclaw/ssh-tunnel
2 critical 23 high 0
openclawopenclaw/wp-to-static
3 critical 4 high 0
openclawopenclaw/kosmi-dj
6 high 0
openclawopenclaw/vault0
4 high 0
sickn33sickn33/github-workflow-automation
6 critical 15 high 0
openclawopenclaw/nutrient-document-processing
0
sickn33sickn33/convex
2 high 0
openclawopenclaw/credential-manager
0
openclawopenclaw/osint-investigator
0
sickn33sickn33/cal-com-automation
0
openclawopenclaw/security-sentinel
3 critical 3 high 0
agenticnotetakingagenticnotetaking/ask
13 high 0
openclawopenclaw/stock-evaluator-v3
0
sickn33sickn33/incident-runbook-templates
7 high 0
openclawopenclaw/kryptogo-meme-trader
0
githubgithub/write-coding-standards-from-file
38 high 0
openclawopenclaw/dns-networking
0
sickn33sickn33/linux-privilege-escalation
10 high 0
openclawopenclaw/fomo-research
0
sickn33sickn33/cloud-penetration-testing
3 high 0
openclawopenclaw/imap-idle
14 high 0
openclawopenclaw/skillvet
7 critical 3 high 0
openclawopenclaw/permission-creep-scanner
6 critical 1 high 0
openclawopenclaw/dm-bot
0
openclawopenclaw/planning-with-files
3 critical 2 high 0
openclawopenclaw/veryfi-documents-ai
0
openclawopenclaw/protocol-doc-auditor
5 critical 2 high 0
openclawopenclaw/kirk-content-pipeline
1 critical 0
openclawopenclaw/security-check
6 critical 1 high 0
openclawopenclaw/keychain-bridge
42 high 0
openclawopenclaw/opengraph-io
0