{"id":"4078b51f-e503-4b47-ba37-498fbffe5f87","entityType":"agent","slug":"clawhub-skills-0xrapi-isnad-scan","name":"isnad-scan","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-0xrapi-isnad-scan","canonicalPath":"/agent/clawhub-skills-0xrapi-isnad-scan","generatedAt":"2026-10-09T21:48:18.664Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Scan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat patterns. Use when installing new skills, auditing existing ones, reviewing untrusted code, or validating packages before publishing. --- name: isnad-scan description: Scan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat patterns. Use when installing new skills, auditing existing ones, reviewing untrusted code, or validating packages before publishing. metadata: openclaw: emoji: \"🛡️\" requires: bins: [\"isnad-scan\"] primaryEnv: null install: - id:","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:0xrapi:isnad-scan","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/0xrapi/isnad-scan","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/0xrapi/isnad-scan","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Scan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat patt"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[{"label":"any","status":"self-declared"},{"label":"the","status":"self-declared"},{"label":"a","status":"self-declared"},{"label":"import","status":"self-declared"},{"label":"is","status":"self-declared"}],"verifiedCount":0,"selfDeclaredCount":6,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"},{"key":"any","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"the","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"a","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"import","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"},{"key":"is","type":"capability","support":"supported","confidenceSource":"profile","notes":"Declared in agent profile metadata"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile capability:any|supported|profile capability:the|supported|profile capability:a|supported|profile capability:import|supported|profile capability:is|supported|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-28T15:29:03.621Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-28T15:29:03.621Z","lastIndexedAt":null,"nextCrawlAt":"2026-03-01T15:29:03.621Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:0xrapi:isnad-scan","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T21:48:18.663Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-0xrapi-isnad-scan/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\nname: isnad-scan\ndescription: Scan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat patterns. Use when installing new skills, auditing existing ones, reviewing untrusted code, or validating packages before publishing.\nmetadata:\n  openclaw:\n    emoji: \"🛡️\"\n    requires:\n      bins: [\"isnad-scan\"]\n    primaryEnv: null\n    install:\n      - id: isnad-scan-pip\n        kind: pipx\n        package: isnad-scan\n        bins: [\"isnad-scan\"]\n        label: \"Install isnad-scan (pipx)\"\n---\n\n# isnad-scan — Security Scanner for AI Agent Skills\n\nScan any skill, package, or directory for security threats before installing or running it.\n\n## Quick Scan\n\n```bash\nisnad-scan <path>\n```\n\nScans a directory and reports findings by severity (CRITICAL, HIGH, MEDIUM, LOW).\n\n## Options\n\n```bash\nisnad-scan <path> --cve          # Also check dependencies for known CVEs (via OSV.dev)\nisnad-scan <path> -v             # Verbose output (show matched lines)\nisnad-scan <path> --json         # Machine-readable JSON output\nisnad-scan <path> --cve -v       # Full audit: CVEs + verbose findings\n```\n\n## What It Detects (69+ patterns)\n\n**Code Injection** — shell execution, eval, exec, subprocess, os.system, dynamic imports\n**Prompt Injection** — role override attempts, instruction hijacking, jailbreak patterns\n**Credential Exfiltration** — env var harvesting, keychain access, token theft, file reads of sensitive paths\n**Network Threats** — reverse shells, DNS exfiltration, unauthorized outbound connections, webhook data leaks\n**Filesystem Attacks** — path traversal, symlink attacks, /etc/passwd reads, SSH key access\n**Supply Chain** — typosquatting detection, minified JS analysis, binary file scanning, hidden files\n**Crypto Risks** — weak algorithms, hardcoded keys, wallet seed extraction\n\n## When to Use\n\n1. **Before installing a new skill** — scan the skill directory first\n2. **Auditing existing skills** — periodic security review\n3. **Reviewing PRs/contributions** — catch malicious code in submissions\n4. **Pre-publish validation** — ensure your own skills are clean before sharing\n5. **CI/CD integration** — `isnad-scan . --json` for automated checks\n\n## Interpreting Results\n\n```\n🔴 CRITICAL  — Immediate threat. Do not install/run.\n🟠 HIGH      — Likely malicious or dangerous. Review carefully.\n🟡 MEDIUM    — Suspicious pattern. May be legitimate, verify intent.\n🔵 LOW       — Informational. Common in legitimate code but worth noting.\n```\n\n## Examples\n\nScan a ClawHub skill before installing:\n```bash\nisnad-scan ./skills/some-new-skill/\n```\n\nFull audit with CVE checking:\n```bash\nisnad-scan ./skills/some-new-skill/ --cve -v\n```\n\nJSON output for automation:\n```bash\nisnad-scan . --json | python3 -c \"import sys,json; d=json.load(sys.stdin); print(f'{d[\\\"summary\\\"][\\\"critical\\\"]} critical, {d[\\\"summary\\\"][\\\"high\\\"]} high')\"\n```\n\n## Python API\n\n```python\nfrom isnad_scan import scan_directory\n\nresults = scan_directory(\"/path/to/skill\")\nfor finding in results.findings:\n    print(f\"[{finding.severity}] {finding.category}: {finding.description}\")\n    print(f\"  File: {finding.file}:{finding.line}\")\n```\n\n## About ISNAD\n\nISNAD (إسناد) means \"chain of transmission\" — a method for verifying the authenticity of transmitted knowledge. isnad-scan is the security layer of the [ISNAD Protocol](https://isnad.md), bringing trust verification to the AI agent skill ecosystem.\n\n**PyPI:** `pip install isnad-scan`\n**GitHub:** [counterspec/isnad](https://github.com/counterspec/isnad)\n**Protocol:** [isnad.md](https://isnad.md)\n","readmeExcerpt":"--- name: isnad-scan description: Scan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat patterns. Use when installing new skills, auditing existing ones, reviewing untrusted code, or validating packages before publishing. metadata: openclaw: emoji: \"🛡️\" requires: bins: [\"isnad-scan\"] primaryEnv: null install: - id: ","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"isnad-scan <path>"},{"language":"bash","snippet":"isnad-scan <path> --cve          # Also check dependencies for known CVEs (via OSV.dev)\nisnad-scan <path> -v             # Verbose output (show matched lines)\nisnad-scan <path> --json         # Machine-readable JSON output\nisnad-scan <path> --cve -v       # Full audit: CVEs + verbose findings"},{"language":"text","snippet":"🔴 CRITICAL  — Immediate threat. Do not install/run.\n🟠 HIGH      — Likely malicious or dangerous. Review carefully.\n🟡 MEDIUM    — Suspicious pattern. May be legitimate, verify intent.\n🔵 LOW       — Informational. Common in legitimate code but worth noting."},{"language":"bash","snippet":"isnad-scan ./skills/some-new-skill/"},{"language":"bash","snippet":"isnad-scan ./skills/some-new-skill/ --cve -v"},{"language":"bash","snippet":"isnad-scan . --json | python3 -c \"import sys,json; d=json.load(sys.stdin); print(f'{d[\\\"summary\\\"][\\\"critical\\\"]} critical, {d[\\\"summary\\\"][\\\"high\\\"]} high')\""}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Scan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat patterns. Use when installing new skills, auditing existing ones, reviewing untrusted code, or validating packages before publishing. --- name: isnad-scan description: Scan AI agent skills for security vulnerabilities — detects code injection, prompt injection, credential exfiltration, supply chain attacks, and 69+ threat patterns. Use when installing new skills, auditing existing ones, reviewing untrusted code, or validating packages before publishing. metadata: openclaw: emoji: \"🛡️\" requires: bins: [\"isnad-scan\"] primaryEnv: null install: - id:","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":390,"uniquenessScore":64,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:48:18.664Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}