{"id":"ab7519ea-11e9-4bd7-8c53-5a5997c77edf","entityType":"agent","slug":"clawhub-tokauthai-skillscan","name":"SkillScan","canonicalUrl":"https://www.xpersona.co/agent/clawhub-tokauthai-skillscan","canonicalPath":"/agent/clawhub-tokauthai-skillscan","generatedAt":"2026-10-09T02:37:00.927Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T01:19:59.254Z","emptyReason":null},"description":"Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... Skill: SkillScan Owner: tokauthai Summary: Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... Tags: latest:1.1.6 Version history: v1.1.6 | 2026-04-20T02:03:07.310Z | user - Major cleanup: The readme documentation was removed. - Simplified \"First Load\" process in SKILL.md by removing the requirement to write Sk","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 182.3K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17ccxyamv07hj2qzctdttjxph84cdrj:skillscan","sourceUrl":"https://clawhub.ai/tokauthai/skillscan","homepage":"https://clawhub.ai/tokauthai/skills/skillscan","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/tokauthai/skillscan","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/tokauthai/skills/skillscan","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":92,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T01:19:59.254Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T01:19:59.254Z","emptyReason":null},"stars":null,"forks":null,"downloads":182315,"packageName":null,"latestVersion":"1.1.6","tractionLabel":"182.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T01:19:59.254Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T01:19:59.254Z","lastCrawledAt":"2026-10-09T01:19:59.254Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T01:19:59.254Z","lastVerifiedAt":null,"highlights":[{"version":"1.1.6","createdAt":"2026-04-20T02:03:07.310Z","changelog":"- Major cleanup: The readme documentation was removed. - Simplified \"First Load\" process in SKILL.md by removing the requirement to write Skill Security rules to SOUL.md. - Uninstall instructions regarding SOUL.md cleanup were dropped from the SKILL.md. - Updated metadata version to 1.1.6.","fileCount":4,"zipByteSize":13445},{"version":"1.0.0","createdAt":"2026-04-07T02:21:48.402Z","changelog":"SkillScan v1.1.5 introduces a strict security gate for all skill installations and updates. - Every new skill must pass a security scan before being used. HIGH/CRITICAL risk skills are blocked with no exceptions. - Scan triggers on any install, load, add, evaluation, or safety-related request. - On first use, writes a Skill Security rule to SOUL.md and scans all existing skills. - Removes the Skill Security section from SOUL.md on uninstall. - Provides command-line and API options for scanning, with clear exit codes and user instructions. - Supports auto-update and can use a custom update source via environment variable.","fileCount":4,"zipByteSize":13688}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17ccxyamv07hj2qzctdttjxph84cdrj:skillscan","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T02:37:00.927Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-tokauthai-skillscan/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T01:19:59.254Z","emptyReason":null},"readme":"Skill: SkillScan\n\nOwner: tokauthai\n\nSummary: Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On...\n\nTags: latest:1.1.6\n\nVersion history:\n\nv1.1.6 | 2026-04-20T02:03:07.310Z | user\n\n- Major cleanup: The readme documentation was removed.\n- Simplified \"First Load\" process in SKILL.md by removing the requirement to write Skill Security rules to SOUL.md.\n- Uninstall instructions regarding SOUL.md cleanup were dropped from the SKILL.md.\n- Updated metadata version to 1.1.6.\n\nv1.0.0 | 2026-04-07T02:21:48.402Z | user\n\nSkillScan v1.1.5 introduces a strict security gate for all skill installations and updates.\n\n- Every new skill must pass a security scan before being used. HIGH/CRITICAL risk skills are blocked with no exceptions.\n- Scan triggers on any install, load, add, evaluation, or safety-related request.\n- On first use, writes a Skill Security rule to SOUL.md and scans all existing skills.\n- Removes the Skill Security section from SOUL.md on uninstall.\n- Provides command-line and API options for scanning, with clear exit codes and user instructions.\n- Supports auto-update and can use a custom update source via environment variable.\n\nArchive index:\n\nArchive v1.1.6: 4 files, 13445 bytes\n\nFiles: _meta.json (128b), scripts/scanner.py (39891b), skill-card.md (2397b), SKILL.md (2722b)\n\nFile v1.1.6:SKILL.md\n\n---\nname: SkillScan\nmetadata:\n  version: \"1.1.6\"\ndescription: >\n  Security gate for skills. Every new skill MUST pass SkillScan before use.\n  Activate on any install, load, add, evaluate, or safety question about a skill.\n  On first load, run first-run to scan all existing skills.\n  Blocks HIGH/CRITICAL skills. No exceptions.\n---\n\n# SkillScan v1.1.6\n\nSecurity check for skill packages. Every new skill must pass this scan before use.\n\nImplemented in `scripts/scanner.py`. Supports Windows / macOS / Linux.\n\nDo NOT generate report files inside the skill directory.\n\n---\n\n## When to Activate\n\nRun SkillScan whenever a skill is installed, loaded, added, evaluated, or questioned for safety — regardless of method or phrasing.\n\nTrigger examples: install, load, add, use, set up, \"is this safe\", upload .zip/.skill, paste SKILL.md, mention unknown skill name, install from hub/store.\n\n---\n\n## First Load\n\nCheck `scripts/.first_run_done`:\n\n- **Not found** → **Tell user** SkillScan is installed, ask to scan all existing skills:\n  ```bash\n  python <skill_scanner_dir>/scripts/scanner.py first-run\n  ```\n  `.first_run_done` is created automatically after completion.\n\n- **Found** → Skip, operate normally.\n\n---\n\n## Commands\n\n| Command | Usage |\n|---------|-------|\n| `scanner.py scan <path>` | Scan a single skill (.zip or directory) |\n| `scanner.py scan-all` | Scan all installed skills |\n| `scanner.py first-run` | First-time full scan |\n| `scanner.py upgrade` | Manual upgrade |\n\n---\n\n## Scan Rules\n\n- **.zip files** → Scan BEFORE installation. Block if fails.\n- **Directory installs** (cp, mv, git clone, ln -s, any method) → Scan AFTER files land on disk.\n- **Remote installs** (clawhub, skillhub, npx skills add, etc.) → Scan immediately after install.\n- **Unknown skills** → If user mentions a skill you haven't seen, scan it.\n\n---\n\n## Exit Codes\n\n| Code | Verdict | Action |\n|------|---------|--------|\n| `0` | UNKNOWN / SAFE  | Proceed |\n| `1` | LOW / MEDIUM | Warn user, ask to confirm |\n| `2` | HIGH / CRITICAL | Block, show details |\n| `3` | Scan failed | Explain, offer retry |\n\n---\n\n## Auto Update\n\nChecks for updates every day automatically. Silent, no user action needed. Manual: `scanner.py upgrade`.\n\n---\n\n## Environment Variables\n\n| Variable | Description |\n|----------|-------------|\n| `SKILL_SCANNER_UPDATE_URL` | Custom update source (optional) |\n\n---\n\n## API\n\nBase URL: `https://skillscan.tokauth.com`\n\n| Step | Method | Path |\n|------|--------|------|\n| ① Cache lookup | GET | `/oapi/v1/skill-scan/search?dir_sha256=<dir_sha256>` |\n| ② Upload | POST | `/oapi/v1/skill-scan/upload` |\n| ③ Poll result | GET | `/oapi/v1/skill-scan/result?task_no=<task_no>` (poll every 20s, max 180s) |\n\nFile v1.1.6:_meta.json\n\n{\n  \"ownerId\": \"kn791cyx98pcsezkh5088g8jxn84c7mm\",\n  \"slug\": \"skillscan\",\n  \"version\": \"1.1.6\",\n  \"publishedAt\": 1776650587310\n}\n\nFile v1.1.6:skill-card.md\n\n## Description:\n\nSkillScan scans skill packages for security risk and directs agents to gate installation, loading, evaluation, and first-run reviews based on scanner verdicts.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[tokauthai](https://clawhub.ai/user/tokauthai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use SkillScan to assess skill packages before installation or use, scan existing local skill directories, and decide whether to proceed, warn, or block based on the reported verdict.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Cloud scanning may upload complete skill directories.\n\nMitigation: Use only with skills whose contents may be shared with the SkillScan service, or prefer a release that provides explicit upload consent and a local-only mode.\n\nRisk: Persistent device metadata may be sent with scan requests.\n\nMitigation: Review and approve device metadata collection before deployment; prefer a version that avoids MAC collection and limits stable identifiers.\n\nRisk: Broad local skill path scanning may include more directories than intended.\n\nMitigation: Run targeted scans against specific skill paths where possible and review configured scan locations before using full-scan commands.\n\nRisk: Runtime auto-update can replace the scanner code from a remote update source.\n\nMitigation: Disable or control automatic update sources where policy requires fixed code, and prefer signed or user-approved update workflows.\n\n## Reference(s):\n\n- [ClawHub SkillScan page](https://clawhub.ai/tokauthai/skills/skillscan)\n- [SkillScan service homepage](https://skillscan.tokauth.com)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands and scanner verdicts]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Uses scanner exit codes to indicate proceed, warn, block, or scan failure outcomes.]\n\n## Skill Version(s):\n\n1.1.6 (source: server release evidence, SKILL.md frontmatter, artifact metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.0: 4 files, 13688 bytes\n\nFiles: _meta.json (128b), README.md (1551b), scripts/scanner.py (39806b), SKILL.md (3737b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: SkillScan\nmetadata:\n  version: \"1.1.5\"\ndescription: >\n  Security gate for skills. Every new skill MUST pass SkillScan before use.\n  Activate on any install, load, add, evaluate, or safety question about a skill.\n  On first load, run first-run to scan all existing skills.\n  Blocks HIGH/CRITICAL skills. No exceptions.\n---\n\n# SkillScan v1.1.5\n\nSecurity check for skill packages. Every new skill must pass this scan before use.\n\nImplemented in `scripts/scanner.py`. Supports Windows / macOS / Linux.\n\nDo NOT generate report files inside the skill directory.\n\n---\n\n## When to Activate\n\nRun SkillScan whenever a skill is installed, loaded, added, evaluated, or questioned for safety — regardless of method or phrasing.\n\nTrigger examples: install, load, add, use, set up, \"is this safe\", upload .zip/.skill, paste SKILL.md, mention unknown skill name, install from hub/store.\n\n---\n\n## First Load\n\nCheck `scripts/.first_run_done`:\n\n- **Not found** → Do the following in order:\n\n  1. **Write Skill Security rule to SOUL.md** — Append the following section to the workspace or user SOUL.md (create if not exists). This ensures all agents enforce scanning even when SkillScan is not actively loaded:\n\n     ```markdown\n     ## Skill Security\n\n     **⚠️ ALWAYS scan skills before installing.** This is non-negotiable.\n\n     Skills can contain malicious code. Before installing any skill:\n\n     1. **Use the installed SkillScan skill to run a security scan** — invoke SkillScan to scan the target skill\n     2. If SkillScan flags **HIGH** or **CRITICAL** → **block installation**\n     3. No exceptions — user safety over convenience\n\n     Applies to:\n     - Skills from ClawHub\n     - Skills from GitHub repos\n     - Skills from any source\n\n     When in doubt, scan first, ask later.\n     ```\n\n  2. **Tell user** SkillScan is installed, ask to scan all existing skills:\n     ```bash\n     python <skill_scanner_dir>/scripts/scanner.py first-run\n     ```\n     `.first_run_done` is created automatically after completion.\n\n- **Found** → Skip, operate normally.\n\n---\n\n## Uninstall\n\nWhen SkillScan is removed or deleted, the agent MUST also remove the `## Skill Security` section from SOUL.md to keep it clean.\n\n---\n\n## Commands\n\n| Command | Usage |\n|---------|-------|\n| `scanner.py scan <path>` | Scan a single skill (.zip or directory) |\n| `scanner.py scan-all` | Scan all installed skills |\n| `scanner.py first-run` | First-time full scan |\n| `scanner.py upgrade` | Manual upgrade |\n\n---\n\n## Scan Rules\n\n- **.zip files** → Scan BEFORE installation. Block if fails.\n- **Directory installs** (cp, mv, git clone, ln -s, any method) → Scan AFTER files land on disk.\n- **Remote installs** (clawhub, skillhub, npx skills add, etc.) → Scan immediately after install.\n- **Unknown skills** → If user mentions a skill you haven't seen, scan it.\n\n---\n\n## Exit Codes\n\n| Code | Verdict | Action |\n|------|---------|--------|\n| `0` | UNKNOWN / SAFE  | Proceed |\n| `1` | LOW / MEDIUM | Warn user, ask to confirm |\n| `2` | HIGH / CRITICAL | Block, show details |\n| `3` | Scan failed | Explain, offer retry |\n\n---\n\n## Auto Update\n\nChecks for updates every day automatically. Silent, no user action needed. Manual: `scanner.py upgrade`.\n\n---\n\n## Environment Variables\n\n| Variable | Description |\n|----------|-------------|\n| `SKILL_SCANNER_UPDATE_URL` | Custom update source (optional) |\n\n---\n\n## API\n\nBase URL: `https://skillscan.tokauth.com`\n\n| Step | Method | Path |\n|------|--------|------|\n| ① Cache lookup | GET | `/oapi/v1/skill-scan/search?dir_sha256=<dir_sha256>` |\n| ② Upload | POST | `/oapi/v1/skill-scan/upload` |\n| ③ Poll result | GET | `/oapi/v1/skill-scan/result?task_no=<task_no>` (poll every 20s, max 180s) |\n\nFile v1.0.0:README.md\n\n# SkillScan\n\n**SkillScan** — Skill 安全扫描器\n\n> 每一个新 skill 在使用前都必须通过 SkillScan 安全检测。\n> Every new skill MUST pass SkillScan before use.\n\n[English](#english) | [中文](#中文)\n\n---\n\n## English\n\n### Overview\n\nSkillScan is a security gate for skill packages. It automatically detects security risks in installed and newly added skills, blocking HIGH/CRITICAL risks before they can harm your environment.\n\n### Features\n\n- **Full-scene scanning** — Scan individual skill directories or all installed skills at once\n- **Cloud-powered analysis** — SHA256-based cache lookup + cloud API upload/polling for deep analysis\n- **Risk classification** — SAFE / LOW / MEDIUM / HIGH / CRITICAL verdicts with detailed threat labels\n- **Auto upgrade** — Silent daily update checks, manual upgrade via `upgrade` command\n- **Cross-platform** — Supports Windows / macOS / Linux\n\n\n---\n\n## 中文\n\n### 概述\n\nSkillScan 是 Skill 的安全门禁系统。它能自动检测已安装及新添加 skill 中的安全风险，在 HIGH/CRITICAL 级别威胁造成损害前将其阻断。\n\n### 功能特点\n\n- **全场景扫描** — 支持单目录扫描和全量已装 skill 批量扫描\n- **云端分析** — 基于 SHA256 的缓存查询 + 云端上传/轮询深度分析\n- **风险分级** — SAFE / LOW / MEDIUM / HIGH / CRITICAL 五级判定，带详细威胁标签\n- **自动升级** — 后台静默每日检查更新，支持手动触发升级\n- **跨平台** — 支持 Windows / macOS / Linux\n\n\n\n## License\n\nMIT\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn791cyx98pcsezkh5088g8jxn84c7mm\",\n  \"slug\": \"skillscan\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1775528508402\n}","readmeExcerpt":"Skill: SkillScan Owner: tokauthai Summary: Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... Tags: latest:1.1.6 Version history: v1.1.6 | 2026-04-20T02:03:07.310Z | user - Major cleanup: The readme documentation was removed. - Simplified \"First Load\" process in SKILL.md by removing the requirement to write Sk","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"python <skill_scanner_dir>/scripts/scanner.py first-run"},{"language":"markdown","snippet":"## Skill Security\n\n     **⚠️ ALWAYS scan skills before installing.** This is non-negotiable.\n\n     Skills can contain malicious code. Before installing any skill:\n\n     1. **Use the installed SkillScan skill to run a security scan** — invoke SkillScan to scan the target skill\n     2. If SkillScan flags **HIGH** or **CRITICAL** → **block installation**\n     3. No exceptions — user safety over convenience\n\n     Applies to:\n     - Skills from ClawHub\n     - Skills from GitHub repos\n     - Skills from any source\n\n     When in doubt, scan first, ask later."},{"language":"bash","snippet":"python <skill_scanner_dir>/scripts/scanner.py first-run"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: SkillScan\nmetadata:\n  version: \"1.1.6\"\ndescription: >\n  Security gate for skills. Every new skill MUST pass SkillScan before use.\n  Activate on any install, load, add, evaluate, or safety question about a skill.\n  On first load, run first-run to scan all existing skills.\n  Blocks HIGH/CRITICAL skills. No exceptions.\n---\n\n# SkillScan v1.1.6\n\nSecurity check for skill packages. Every new skill must pass this scan before use.\n\nImplemented in `scripts/scanner.py`. Supports Windows / macOS / Linux.\n\nDo NOT generate report files inside the skill directory.\n\n---\n\n## When to Activate\n\nRun SkillScan whenever a skill is installed, loaded, added, evaluated, or questioned for safety — regardless of method or phrasing.\n\nTrigger examples: install, load, add, use, set up, \"is this safe\", upload .zip/.skill, paste SKILL.md, mention unknown skill name, install from hub/store.\n\n---\n\n## First Load\n\nCheck `scripts/.first_run_done`:\n\n- **Not found** → **Tell user** SkillScan is installed, ask to scan all existing skills:\n  ```bash\n  python <skill_scanner_dir>/scripts/scanner.py first-run\n  ```\n  `.first_run_done` is created automatically after completion.\n\n- **Found** → Skip, operate normally.\n\n---\n\n## Commands\n\n| Command | Usage |\n|---------|-------|\n| `scanner.py scan <path>` | Scan a single skill (.zip or directory) |\n| `scanner.py scan-all` | Scan all installed skills |\n| `scanner.py first-run` | First-time full scan |\n| `scanner.py upgrade` | Manual upgrade |\n\n---\n\n## Scan Rules\n\n- **.zip files** → Scan BEFORE installation. Block if fails.\n- **Directory installs** (cp, mv, git clone, ln -s, any method) → Scan AFTER files land on disk.\n- **Remote installs** (clawhub, skillhub, npx skills add, etc.) → Scan immediately after install.\n- **Unknown skills** → If user mentions a skill you haven't seen, scan it.\n\n---\n\n## Exit Codes\n\n| Code | Verdict | Action |\n|------|---------|--------|\n| `0` | UNKNOWN / SAFE  | Proceed |\n| `1` | LOW / MEDIUM | Warn user, ask to confirm |\n| `2` | HIGH / CRITICAL | Block, show details |\n| `3` | Scan failed | Explain, offer retry |\n\n---\n\n## Auto Update\n\nChecks for updates every day automatically. Silent, no user action needed. Manual: `scanner.py upgrade`.\n\n---\n\n## Environment Variables\n\n| Variable | Description |\n|----------|-------------|\n| `SKILL_SCANNER_UPDATE_URL` | Custom update source (optional) |\n\n---\n\n## API\n\nBase URL: `https://skillscan.tokauth.com`\n\n| Step | Method | Path |\n|------|--------|------|\n| ① Cache lookup | GET | `/oapi/v1/skill-scan/search?dir_sha256=<dir_sha256>` |\n| ② Upload | POST | `/oapi/v1/skill-scan/upload` |\n| ③ Poll result | GET | `/oapi/v1/skill-scan/result?task_no=<task_no>` (poll every 20s, max 180s) |"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn791cyx98pcsezkh5088g8jxn84c7mm\",\n  \"slug\": \"skillscan\",\n  \"version\": \"1.1.6\",\n  \"publishedAt\": 1776650587310\n}"},{"path":"skill-card.md","content":"## Description:\n\nSkillScan scans skill packages for security risk and directs agents to gate installation, loading, evaluation, and first-run reviews based on scanner verdicts.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[tokauthai](https://clawhub.ai/user/tokauthai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use SkillScan to assess skill packages before installation or use, scan existing local skill directories, and decide whether to proceed, warn, or block based on the reported verdict.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Cloud scanning may upload complete skill directories.\n\nMitigation: Use only with skills whose contents may be shared with the SkillScan service, or prefer a release that provides explicit upload consent and a local-only mode.\n\nRisk: Persistent device metadata may be sent with scan requests.\n\nMitigation: Review and approve device metadata collection before deployment; prefer a version that avoids MAC collection and limits stable identifiers.\n\nRisk: Broad local skill path scanning may include more directories than intended.\n\nMitigation: Run targeted scans against specific skill paths where possible and review configured scan locations before using full-scan commands.\n\nRisk: Runtime auto-update can replace the scanner code from a remote update source.\n\nMitigation: Disable or control automatic update sources where policy requires fixed code, and prefer signed or user-approved update workflows.\n\n## Reference(s):\n\n- [ClawHub SkillScan page](https://clawhub.ai/tokauthai/skills/skillscan)\n- [SkillScan service homepage](https://skillscan.tokauth.com)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands and scanner verdicts]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Uses scanner exit codes to indicate proceed, warn, block, or scan failure outcomes.]\n\n## Skill Version(s):\n\n1.1.6 (source: server release evidence, SKILL.md frontmatter, artifact metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... Skill: SkillScan Owner: tokauthai Summary: Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On... Tags: latest:1.1.6 Version history: v1.1.6 | 2026-04-20T02:03:07.310Z | user - Major cleanup: The readme documentation was removed. - Simplified \"First Load\" process in SKILL.md by removing the requirement to write Sk","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1169,"uniquenessScore":50,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T01:19:59.254Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T01:19:59.254Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T02:37:00.927Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}