agentCLAWHUBUnverified

AgentTrust — Security Scanner for AI Skills

Scan AI agent skills for malware, prompt injection, data exfiltration, and 47 other security threats. JWS-signed ACT/HALT receipts. x402-native, no API keys, no accounts. MCP manifest scanning.

OpenClaw

Rank

62

Safety

84

Downloads

1.7k

Updated

Oct 10, 2026

Version

1.4.1

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.7K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.7K downloadsadoption · observed Oct 10, 2026
Latest release
1.4.1release · observed Sep 17, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17aeqzzfhw3z8bjbdcjbzdz9985ht06:agenttrust-scanner
  1. Install using `clawhub skill install s17aeqzzfhw3z8bjbdcjbzdz9985ht06:agenttrust-scanner` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/poteshniy/agenttrust-scanner before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/snapshot"

Documentation

CLAWHUB

46,036 characters of source documentation, loaded on request.

Extracted files

3 files captured from the source.

SKILL.md

# AgentTrust
## Description
Security Scanner and Reputation Oracle for AI agent skills and MCP servers. Scans for malware, prompt injection, tool poisoning, and 47 other threat patterns. Returns cryptographically signed ACT/HALT receipts (JWS, draft-krausz-verification-state-01). x402-native on Base mainnet. Conforming implementation of IETF draft-krausz-verification-state-01 alongside AgentOracle.

Unique features:
- SKILL.md scanner — 40 rules, 12 categories
- MCP manifest scanner — tool poisoning, shadowing, hidden unicode, rug pull detection
- Unified trust gate — skill + MCP + endpoint reputation in one signed call
- Composed receipt — two-issuer JWS envelope (AgentTrust + AgentOracle, Phase 1 live)
- JWS-signed receipts — verifiable ACT/HALT per IETF draft-krausz-verification-state-01
- Endpoint reputation — on-chain trust score before your agent pays
- Trust badge — SVG badge for x402 providers
- MCP server — install via npx @poteshniy/[email protected] (pinned) for Claude Desktop, Cursor, Windsurf

**Privacy notice:** Submitted content is transmitted to the external host agenttrust.uk for analysis. This applies to ALL endpoints including free ones. The agent MUST obtain explicit per-request user consent before any submission and MUST exclude secrets (credentials, keys, tokens, internal URLs) by default. Submitting content is an opt-in action, not a default.

**Payment notice:** Full scan endpoints require x402 USDC payments on Base. Free tiers require no wallet.

## Instructions
Before sending ANY content to agenttrust.uk — free or paid — ask the user for explicit confirmation and show that the submitted content will leave the local machine and go to the host agenttrust.uk. Do NOT submit content containing credentials, API keys, authorization headers, private keys, tokens, or internal URLs; redact them first or skip submission. Prefer local summarization when content is sensitive. Free endpoints require no wallet; paid endpoints additionally require x402 confirmation with the exact price disclosed.

### Free SKILL.md scan (no payment required)
POST https://agenttrust.uk/v1/scan/free
Price: FREE
Body: { "content": "<skill content, max 50 lines>" }
Returns: safety score 0-100, level (SAFE/MEDIUM/HIGH/CRITICAL), findings, v_gate (act/halt), JWS receipt
Note: Rate limited to 10 requests/hour per IP.

### Full SKILL.md scan (requires explicit user approval)
POST https://agenttrust.uk/v1/scan
Price: 0.015 USDC on Base (x402)
Body: { "content": "<full skill content>" }
Returns: safety score, all 40 findings, integrity hash, JWS receipt
Note: Results are cached — repeated scans return instantly.

### Free MCP manifest scan (no payment required)
POST https://agenttrust.uk/v1/scan/mcp/free
Price: FREE
Body: { "manifest": <MCP server manifest JSON> }
Returns: safety score, level, findings (tool poisoning, shadowing, etc.), v_gate, JWS receipt
Note: Rate limited to 10 requests/hour per IP.

### Full MCP manifest scan (requires explicit user approv

_meta.json

{
  "ownerId": "kn7ab822drvwj0k2kk86awrpen85hexk",
  "slug": "agenttrust-scanner",
  "version": "1.4.1",
  "publishedAt": 1789638712672
}

skill-card.md

## Description:

AgentTrust scans AI agent skills and MCP server manifests for security threats and returns signed ACT/HALT trust receipts.

This skill is ready for commercial/non-commercial use.

## Publisher:

[poteshniy](https://clawhub.ai/user/poteshniy)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and security reviewers use this skill to assess SKILL.md files, MCP manifests, endpoint reputation, and wallet trust signals before an agent installs, trusts, or calls external tools. The skill is intended for workflows where users explicitly approve any outbound submission and redact sensitive content first.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Skill or manifest content may be transmitted outside the local machine to agenttrust.uk.

Mitigation: Ask for explicit approval before each submission and disclose that the selected content will leave the local environment.

Risk: Submitted content may contain credentials, tokens, internal URLs, or other sensitive material.

Mitigation: Redact secrets and internal details by default, skip submission when redaction is not sufficient, and prefer local summarization for sensitive material.

Risk: Paid endpoints may incur x402 USDC charges on Base.

Mitigation: Confirm the exact cost with the user before using any paid endpoint.

Risk: Installing the MCP server fetches an npm package.

Mitigation: Verify the pinned package version, publisher, and integrity before adding the MCP server configuration.

## Reference(s):

- [ClawHub skill page](https://clawhub.ai/poteshniy/skills/agenttrust-scanner)
- [AgentTrust service host](https://agenttrust.uk)
- [AgentTrust JWKS](https://agenttrust.uk/.well-known/jwks.json)
- [IETF Verification State draft](https://datatracker.ietf.org/doc/draft-krausz-verification-state/)
- [AgentTrust receipt mapping](https://raw.githubusercontent.com/poteshniy/agenttrust/main/docs/mapping-v0.3.md)

## Skill Output:

**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]

**Output Format:** [Markdown guidance with endpoint descriptions, shell commands, JSON configuration, and API request examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Requires explicit per-request consent before transmitting content to agenttrust.uk; paid endpoints require explicit x402 USDC cost confirmation.]

## Skill Version(s):

1.4.1 (source: server release evidence)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 12h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/poteshniy/skills/agenttrust-scanner",
      "sourceUrl": "https://clawhub.ai/poteshniy/skills/agenttrust-scanner",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T03:40:58.354Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T03:40:58.354Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.7K downloads",
      "href": "https://clawhub.ai/poteshniy/agenttrust-scanner",
      "sourceUrl": "https://clawhub.ai/poteshniy/agenttrust-scanner",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T03:40:58.354Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "1.4.1",
      "href": "https://clawhub.ai/poteshniy/agenttrust-scanner",
      "sourceUrl": "https://clawhub.ai/poteshniy/agenttrust-scanner",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-17T09:51:52.672Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-poteshniy-agenttrust-scanner/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.4.1",
      "description": "AgentTrust Scanner 1.4.1 introduces stricter privacy and consent requirements for all submissions. - Enhanced privacy notice: Explicitly states that content is sent outside the local machine, including for free scans. - Consent required: The agent must get explicit approval from users before sending any data, and redact sensitive information by default. - Revised instructions: Clarify to always disclose outbound submissions, avoid uploading secrets, and prefer local summarization for sensitive material. - MCP server install command now uses a pinned package version (@1.0.1) and removes automatic approval flags (no -y). - Removed file: skill-card.md.",
      "href": "https://clawhub.ai/poteshniy/agenttrust-scanner",
      "sourceUrl": "https://clawhub.ai/poteshniy/agenttrust-scanner",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-17T09:51:52.672Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to AgentTrust — Security Scanner for AI Skills and adjacent AI workflows.