OpenClaw: benign
VirusTotal: benign
StaticScan: unknown
OpenClaw: benign
The skill's instructions, requirements, and provenance (npx + public npm package/GitHub) align with its stated purpose as a CLI security scanner; nothing requests unrelated credentials or system acces... [内容已截断]
VirusTotal: benign VT 报告
静态扫描: unknown
README 未提供
无文件信息
{
"latestVersion": {
"_creationTime": 1771692856737,
"_id": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"changelog": "Initial ClawHub release - Enterprise-grade security for OpenClaw\n\n🆕 Features:\n • 6-layer deep skill scanning with ClawHavoc malware signatures\n • Prompt injection firewall (59 bypass detection techniques)\n • Package hallucination detection (4.3M+ verified packages)\n • Code vulnerability scanning (1700+ rules, 12 languages)\n • Auto-fix engine (165 security fix templates)\n • Pre-execution safety checks for agent actions\n • Supply chain verification with typosquatting detection\n\n 🎯 Security Coverage:\n • ClawHavoc malware (27 families, 121 patterns)\n • SQL injection, XSS, command injection\n • Hardcoded secrets and credential leaks\n • Crypto miners, reverse shells, C2 beacons\n • Data exfiltration and mass messaging attacks\n\n ⚡ Performance:\n • 97.7% precision (benchmarked)\n • <45s analysis per file\n • AST + taint analysis engine\n • Real-time blocking with A-F grading\n\n 📦 Integration:\n • CLI tool: npx agent-security-scanner-mcp\n • MCP server for Claude Code, Cursor, Windsurf\n • Git hooks for pre-commit scanning\n • CI\/CD templates included\n\n 🛡️ Why install: OpenClaw can run code autonomously. Without security scanning, you're vulnerable to malicious skills, hallucinated packages, and prompt injection. ClawProof blocks these attacks automatically.\n\nInstall: npm install -g agent-security-scanner-mcp",
"changelogSource": "user",
"createdAt": 1771692856737,
"parsed": {
"clawdis": {
"emoji": "🛡️",
"requires": {
"bins": [
"npx"
]
}
}
},
"version": "3.10.3"
},
"owner": {
"_creationTime": 0,
"_id": "publishers:missing",
"displayName": "sinewaveai",
"handle": "sinewaveai",
"image": "https:\/\/avatars.githubusercontent.com\/u\/157084199?v=4",
"kind": "user",
"linkedUserId": "kn7ba5r1bhqha8tnxp7qj53s2981j3bf"
},
"ownerHandle": "sinewaveai",
"skill": {
"_creationTime": 1771692856737,
"_id": "kd7acfy66hv9eerrc4jgrrkg5x81j90b",
"badges": [],
"createdAt": 1771692856737,
"displayName": "ClawProof Security Scanner",
"latestVersionId": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"ownerUserId": "kn7ba5r1bhqha8tnxp7qj53s2981j3bf",
"slug": "clawproof-security",
"stats": {
"comments": 0,
"downloads": 348,
"installsAllTime": 1,
"installsCurrent": 1,
"stars": 0,
"versions": 1
},
"summary": "Enterprise-grade security for OpenClaw - blocks malicious skills, detects hallucinated packages, and prevents prompt injection attacks. Powered by agent-secu...",
"tags": {
"ai-safety": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"ast-analysis": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"auto-fix": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"latest": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"malware-detection": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"openclaw-security": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"package-verification": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"prompt-injection": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"security": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"supply-chain": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1",
"vulnerability-scanner": "k97c3gcg1rbykgqrt1eyh5w71h81jtp1"
},
"updatedAt": 1772057135874
}
}