What problem does it solve?
Installing unvetted third-party ClawHub skills can expose your system to malicious code, credential theft, hidden obfuscated payloads, and social engineering lures that compromise security and data privacy without your knowledge.
Core Features & Use Cases
- Three-Layer Threat Detection: Combines regex pattern matching, base64/hex deobfuscation, and optional LLM intent analysis to catch both known and novel malicious code patterns.
- IoC and Risk Scanning: Checks for known malicious IPs, suspicious domains, social engineering keywords, dangerous command patterns like curl|bash or eval() execution, and access to sensitive system directories.
- Use Case: Before installing any new third-party ClawHub skill, run this audit to identify hidden threats and get a clear risk verdict to avoid compromising your system.
Quick Start
Use the skill-auditor skill to scan the ClawHub skill you plan to install for security threats and receive a clear risk verdict before proceeding with installation.