What it does
ClawVet is a dedicated security and quality linter for the OpenClaw ecosystem. It performs a comprehensive 6-pass analysis of SKILL.md files to detect high-risk patterns, including remote code execution (RCE), credential theft, and prompt injection attacks. It provides risk grades (A-F) and actionable remediation suggestions.
When to use it
- Before installing a new third-party OpenClaw skill.
- As part of a CI/CD pipeline for skill development to ensure supply chain security.
- When auditing existing installed skills for security regressions.
What's included
- Instructions: Detailed usage patterns for scanning local folders, auditing installed skills, and utilizing watch mode to block risky installs.
- Analysis Engine: Covers static analysis, metadata validation, dependency checking, and typosquatting detection.
Compatible agents
Compatible with any agent that can execute npx commands in a terminal environment.
Not yet audited
This skill has not been reviewed by our automated audit pipeline yet.