Claim this agent
agentCLAWHUBUnverified

SkillScan

Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... Skill: SkillScan Owner: tokauthai Summary: Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... Tags: latest:1.1.6 Version history: v1.1.6 | 2026-04-20T02:03:07.310Z | user - Major cleanup: The readme documentation was removed. - Simplified "First Load" process in SKILL.md by removing the requirement to write Sk

OpenClaw

Rank

62

Safety

84

Downloads

177k

Updated

Jun 1, 2026

Version

1.1.6

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 177.3K downloads reported by the source. Last updated 6/1/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Adoption signal
177.3K downloadsadoption · observed Jun 1, 2026
Vendor
Clawhubvendor · observed May 30, 2026
Protocol compatibility
OpenClawcompatibility · observed May 30, 2026
Adoption signal
177.1K downloadsadoption · observed May 30, 2026
Latest release
1.1.6release · observed Apr 20, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17ccxyamv07hj2qzctdttjxph84cdrj:skillscan
  1. Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/snapshot"

Documentation

CLAWHUB

11,949 characters of source documentation, loaded on request.

Extracted files

3 files captured from the source.

SKILL.md

---
name: SkillScan
metadata:
  version: "1.1.6"
description: >
  Security gate for skills. Every new skill MUST pass SkillScan before use.
  Activate on any install, load, add, evaluate, or safety question about a skill.
  On first load, run first-run to scan all existing skills.
  Blocks HIGH/CRITICAL skills. No exceptions.
---

# SkillScan v1.1.6

Security check for skill packages. Every new skill must pass this scan before use.

Implemented in `scripts/scanner.py`. Supports Windows / macOS / Linux.

Do NOT generate report files inside the skill directory.

---

## When to Activate

Run SkillScan whenever a skill is installed, loaded, added, evaluated, or questioned for safety — regardless of method or phrasing.

Trigger examples: install, load, add, use, set up, "is this safe", upload .zip/.skill, paste SKILL.md, mention unknown skill name, install from hub/store.

---

## First Load

Check `scripts/.first_run_done`:

- **Not found** → **Tell user** SkillScan is installed, ask to scan all existing skills:
  ```bash
  python <skill_scanner_dir>/scripts/scanner.py first-run
  ```
  `.first_run_done` is created automatically after completion.

- **Found** → Skip, operate normally.

---

## Commands

| Command | Usage |
|---------|-------|
| `scanner.py scan <path>` | Scan a single skill (.zip or directory) |
| `scanner.py scan-all` | Scan all installed skills |
| `scanner.py first-run` | First-time full scan |
| `scanner.py upgrade` | Manual upgrade |

---

## Scan Rules

- **.zip files** → Scan BEFORE installation. Block if fails.
- **Directory installs** (cp, mv, git clone, ln -s, any method) → Scan AFTER files land on disk.
- **Remote installs** (clawhub, skillhub, npx skills add, etc.) → Scan immediately after install.
- **Unknown skills** → If user mentions a skill you haven't seen, scan it.

---

## Exit Codes

| Code | Verdict | Action |
|------|---------|--------|
| `0` | UNKNOWN / SAFE  | Proceed |
| `1` | LOW / MEDIUM | Warn user, ask to confirm |
| `2` | HIGH / CRITICAL | Block, show details |
| `3` | Scan failed | Explain, offer retry |

---

## Auto Update

Checks for updates every day automatically. Silent, no user action needed. Manual: `scanner.py upgrade`.

---

## Environment Variables

| Variable | Description |
|----------|-------------|
| `SKILL_SCANNER_UPDATE_URL` | Custom update source (optional) |

---

## API

Base URL: `https://skillscan.tokauth.com`

| Step | Method | Path |
|------|--------|------|
| ① Cache lookup | GET | `/oapi/v1/skill-scan/search?dir_sha256=<dir_sha256>` |
| ② Upload | POST | `/oapi/v1/skill-scan/upload` |
| ③ Poll result | GET | `/oapi/v1/skill-scan/result?task_no=<task_no>` (poll every 20s, max 180s) |

_meta.json

{
  "ownerId": "kn791cyx98pcsezkh5088g8jxn84c7mm",
  "slug": "skillscan",
  "version": "1.1.6",
  "publishedAt": 1776650587310
}

skill-card.md

## Description: <br>
SkillScan scans skill packages through its hosted service, reports security verdicts, and guides agents to block high- or critical-risk skills. <br>

This skill is ready for commercial/non-commercial use. <br>

## Publisher: <br>
[tokauthai](https://clawhub.ai/user/tokauthai) <br>

### License/Terms of Use: <br>
MIT-0 <br>


## Use Case: <br>
Developers and agent operators use SkillScan to scan installed, newly added, zipped, or remote skill packages and decide whether to proceed, warn, or block based on scan verdicts. <br>

### Deployment Geography for Use: <br>
Global <br>

## Known Risks and Mitigations: <br>
Risk: Skill contents are uploaded to skillscan.tokauth.com for analysis. <br>
Mitigation: Scan only skills whose contents can be shared with the service; avoid private, proprietary, or secret-bearing skills unless that upload is acceptable. <br>
Risk: The scanner stores device-linked client information for reuse across scan requests. <br>
Mitigation: Review the generated client information and run the scanner only in environments where this telemetry is acceptable. <br>
Risk: The scanner can replace its own files through the update path. <br>
Mitigation: Review or disable automatic updates when deterministic tooling or separate change control is required. <br>
Risk: Scan results are advisory unless the surrounding agent or workflow enforces the scanner exit codes. <br>
Mitigation: Configure the calling workflow to enforce nonzero exit codes and require review for low or medium findings. <br>


## Reference(s): <br>
- [SkillScan ClawHub Release](https://clawhub.ai/tokauthai/skillscan) <br>
- [SkillScan Service](https://skillscan.tokauth.com) <br>


## Skill Output: <br>
**Output Type(s):** [Text, Shell commands, Guidance] <br>
**Output Format:** [Markdown with inline shell commands and scanner verdict summaries] <br>
**Output Parameters:** [1D] <br>
**Other Properties Related to Output:** [Exit codes distinguish pass, warning, block, and scan-failure outcomes.] <br>

## Skill Version(s): <br>
1.1.6 (source: release evidence, SKILL.md frontmatter, and _meta.json) <br>

## Ethical Considerations: <br>
Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>
Github OpenclewUpdated 4mo agoRank 65

@x1pay/langchain

LangChain/LangGraph tools for AI agent x402 payments on X1

OPENCLAW
Github OpenclewUpdated 4mo agoRank 65

oceanbus-langchain

LangChain tools for OceanBus — give your LangChain and CrewAI agents a global identity, encrypted messaging, and Yellow Pages service discovery with a single import.

OPENCLAWoceanbuslangchainlangchain-tools

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "177.3K downloads",
      "href": "https://clawhub.ai/tokauthai/skillscan",
      "sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-06-01T00:29:39.236Z",
      "isPublic": true
    },
    {
      "factKey": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "category": "vendor",
      "href": "https://clawhub.ai/tokauthai/skillscan",
      "sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-05-30T06:44:41.490Z",
      "isPublic": true,
      "metadata": {}
    },
    {
      "factKey": "protocols",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "category": "compatibility",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-05-30T06:44:41.490Z",
      "isPublic": true,
      "metadata": {}
    },
    {
      "factKey": "traction",
      "label": "Adoption signal",
      "value": "177.1K downloads",
      "category": "adoption",
      "href": "https://clawhub.ai/tokauthai/skillscan",
      "sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-05-30T06:44:41.490Z",
      "isPublic": true,
      "metadata": {}
    },
    {
      "factKey": "latest_release",
      "label": "Latest release",
      "value": "1.1.6",
      "category": "release",
      "href": "https://clawhub.ai/tokauthai/skillscan",
      "sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-04-20T02:03:07.310Z",
      "isPublic": true,
      "metadata": {}
    },
    {
      "factKey": "handshake_status",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "category": "security",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true,
      "metadata": {}
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.1.6",
      "description": "- Major cleanup: The readme documentation was removed. - Simplified \"First Load\" process in SKILL.md by removing the requirement to write Skill Security rules to SOUL.md. - Uninstall instructions regarding SOUL.md cleanup were dropped from the SKILL.md. - Updated metadata version to 1.1.6.",
      "href": "https://clawhub.ai/tokauthai/skillscan",
      "sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-04-20T02:03:07.310Z",
      "isPublic": true,
      "metadata": {}
    }
  ]
}

Record generated Oct 8, 2026.

Sponsored

Ads related to SkillScan and adjacent AI workflows.