What problem does it solve?
ClawGuard Auditor mitigates the risk of installing untrusted Skills by performing comprehensive security analysis before execution, including intent drift detection, SAST, supply chain vetting, and code-block scanning.
Core Features & Use Cases
- Static Analysis: 100+ SAST rules plus intent drift checks to catch dangerous patterns.
- Intent Drift Detection: Validates declared capabilities against actual code usage to flag misalignment.
- Supply Chain Vetting: Dependency CVE checks, typosquatting detection, and provenance scoring for safer installations.
- SKILL.md Code Scanning: Analyzes code blocks inside documentation to uncover hidden risks.
- Pre-install Output: Produces a risk verdict and actionable recommendations for safe deployment.
- Use Case: Evaluate a Skill before installation or during audits of existing repos.
Quick Start
Run the Auditor CLI in the auditor-skill directory to audit a target Skill.