SkillScan
Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... Skill: SkillScan Owner: tokauthai Summary: Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... Tags: latest:1.1.6 Version history: v1.1.6 | 2026-04-20T02:03:07.310Z | user - Major cleanup: The readme documentation was removed. - Simplified "First Load" process in SKILL.md by removing the requirement to write Sk
Rank
62
Safety
84
Downloads
182k
Updated
Oct 9, 2026
Version
1.1.6
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 182.3K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Adoption signal
- 182.3K downloadsadoption · observed Oct 9, 2026
- Vendor
- Clawhubvendor · observed May 20, 2026
- Protocol compatibility
- OpenClawcompatibility · observed May 20, 2026
- Adoption signal
- 168.6K downloadsadoption · observed May 20, 2026
- Latest release
- 1.1.6release · observed Apr 20, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17ccxyamv07hj2qzctdttjxph84cdrj:skillscan- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/snapshot"
Documentation
CLAWHUB
11,938 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
--- name: SkillScan metadata: version: "1.1.6" description: > Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On first load, run first-run to scan all existing skills. Blocks HIGH/CRITICAL skills. No exceptions. --- # SkillScan v1.1.6 Security check for skill packages. Every new skill must pass this scan before use. Implemented in `scripts/scanner.py`. Supports Windows / macOS / Linux. Do NOT generate report files inside the skill directory. --- ## When to Activate Run SkillScan whenever a skill is installed, loaded, added, evaluated, or questioned for safety — regardless of method or phrasing. Trigger examples: install, load, add, use, set up, "is this safe", upload .zip/.skill, paste SKILL.md, mention unknown skill name, install from hub/store. --- ## First Load Check `scripts/.first_run_done`: - **Not found** → **Tell user** SkillScan is installed, ask to scan all existing skills: ```bash python <skill_scanner_dir>/scripts/scanner.py first-run ``` `.first_run_done` is created automatically after completion. - **Found** → Skip, operate normally. --- ## Commands | Command | Usage | |---------|-------| | `scanner.py scan <path>` | Scan a single skill (.zip or directory) | | `scanner.py scan-all` | Scan all installed skills | | `scanner.py first-run` | First-time full scan | | `scanner.py upgrade` | Manual upgrade | --- ## Scan Rules - **.zip files** → Scan BEFORE installation. Block if fails. - **Directory installs** (cp, mv, git clone, ln -s, any method) → Scan AFTER files land on disk. - **Remote installs** (clawhub, skillhub, npx skills add, etc.) → Scan immediately after install. - **Unknown skills** → If user mentions a skill you haven't seen, scan it. --- ## Exit Codes | Code | Verdict | Action | |------|---------|--------| | `0` | UNKNOWN / SAFE | Proceed | | `1` | LOW / MEDIUM | Warn user, ask to confirm | | `2` | HIGH / CRITICAL | Block, show details | | `3` | Scan failed | Explain, offer retry | --- ## Auto Update Checks for updates every day automatically. Silent, no user action needed. Manual: `scanner.py upgrade`. --- ## Environment Variables | Variable | Description | |----------|-------------| | `SKILL_SCANNER_UPDATE_URL` | Custom update source (optional) | --- ## API Base URL: `https://skillscan.tokauth.com` | Step | Method | Path | |------|--------|------| | ① Cache lookup | GET | `/oapi/v1/skill-scan/search?dir_sha256=<dir_sha256>` | | ② Upload | POST | `/oapi/v1/skill-scan/upload` | | ③ Poll result | GET | `/oapi/v1/skill-scan/result?task_no=<task_no>` (poll every 20s, max 180s) |
_meta.json
{
"ownerId": "kn791cyx98pcsezkh5088g8jxn84c7mm",
"slug": "skillscan",
"version": "1.1.6",
"publishedAt": 1776650587310
}skill-card.md
## Description: SkillScan scans skill packages for security risk and directs agents to gate installation, loading, evaluation, and first-run reviews based on scanner verdicts. This skill is ready for commercial/non-commercial use. ## Publisher: [tokauthai](https://clawhub.ai/user/tokauthai) ### License/Terms of Use: MIT-0 ## Use Case: Developers and agent operators use SkillScan to assess skill packages before installation or use, scan existing local skill directories, and decide whether to proceed, warn, or block based on the reported verdict. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Cloud scanning may upload complete skill directories. Mitigation: Use only with skills whose contents may be shared with the SkillScan service, or prefer a release that provides explicit upload consent and a local-only mode. Risk: Persistent device metadata may be sent with scan requests. Mitigation: Review and approve device metadata collection before deployment; prefer a version that avoids MAC collection and limits stable identifiers. Risk: Broad local skill path scanning may include more directories than intended. Mitigation: Run targeted scans against specific skill paths where possible and review configured scan locations before using full-scan commands. Risk: Runtime auto-update can replace the scanner code from a remote update source. Mitigation: Disable or control automatic update sources where policy requires fixed code, and prefer signed or user-approved update workflows. ## Reference(s): - [ClawHub SkillScan page](https://clawhub.ai/tokauthai/skills/skillscan) - [SkillScan service homepage](https://skillscan.tokauth.com) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, guidance] **Output Format:** [Markdown guidance with inline shell commands and scanner verdicts] **Output Parameters:** [1D] **Other Properties Related to Output:** [Uses scanner exit codes to indicate proceed, warn, block, or scan failure outcomes.] ## Skill Version(s): 1.1.6 (source: server release evidence, SKILL.md frontmatter, artifact metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/tokauthai/skills/skillscan",
"sourceUrl": "https://clawhub.ai/tokauthai/skills/skillscan",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T01:19:59.254Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "182.3K downloads",
"href": "https://clawhub.ai/tokauthai/skillscan",
"sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T01:19:59.254Z",
"isPublic": true
},
{
"factKey": "vendor",
"label": "Vendor",
"value": "Clawhub",
"category": "vendor",
"href": "https://clawhub.ai/tokauthai/skillscan",
"sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-05-20T07:05:02.945Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "protocols",
"label": "Protocol compatibility",
"value": "OpenClaw",
"category": "compatibility",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-05-20T07:05:02.945Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "traction",
"label": "Adoption signal",
"value": "168.6K downloads",
"category": "adoption",
"href": "https://clawhub.ai/tokauthai/skillscan",
"sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-05-20T07:05:02.945Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "latest_release",
"label": "Latest release",
"value": "1.1.6",
"category": "release",
"href": "https://clawhub.ai/tokauthai/skillscan",
"sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-20T02:03:07.310Z",
"isPublic": true,
"metadata": {}
},
{
"factKey": "handshake_status",
"label": "Handshake status",
"value": "UNKNOWN",
"category": "security",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true,
"metadata": {}
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.1.6",
"description": "- Major cleanup: The readme documentation was removed. - Simplified \"First Load\" process in SKILL.md by removing the requirement to write Skill Security rules to SOUL.md. - Uninstall instructions regarding SOUL.md cleanup were dropped from the SKILL.md. - Updated metadata version to 1.1.6.",
"href": "https://clawhub.ai/tokauthai/skillscan",
"sourceUrl": "https://clawhub.ai/tokauthai/skillscan",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-20T02:03:07.310Z",
"isPublic": true,
"metadata": {}
}
]
}Record generated Oct 10, 2026.
