1 in 36 OpenClaw skills contains security threats — is yours one of them?

The AI Skills you use could be
your nightmare

Community skills can contain malware, data exfiltration, and backdoors. ClawGuard scans them all so you don't have to.

Get ClawGuard Free
$ npx clawguard init
0
Executable skills analyzed
1/36
Contain security threats
0
Downloads at risk

Real threats we found

These skills are live in the OpenClaw marketplace right now

Run Code
by etienneperot · 7.6K downloads
F — Shell execution + filesystem access
OpenRouter 380+ Models
by rbb-dev · 3.8K downloads
F — Code injection + SSH access
GitHub Copilot SDK Pipe
by Fu-Jie · 1.1K downloads
F — DB access + file deletion
Fileshed 1.0.0
by did100 · 802 downloads
F — Privilege escalation
Diagram Generator
by newnol · 747 downloads
F — Dynamic code execution
user_storage
by did100 · 532 downloads
F — Shell exec + file deletion

These skills have been downloaded 22,000+ times. Is yours one of them?

Check your skills now

Protected in 60 seconds

No config, no Docker, no cloud account required

1

Install

One command. Works on Mac, Linux, and Windows. Detects your OpenClaw automatically.

npx clawguard init
2

Scan

Instantly grades every installed skill from A (safe) to F (dangerous). Shows you what's risky.

clawguard scan
3

Protect

Auto-fixes what it can, warns about the rest, and monitors for new threats 24/7.

clawguard protect

Free vs Pro

Free detects threats. Pro stops them.

Feature
Free
$0
Pro
$29/mo
Skill safety lookup
Letter grade (A-F)
Threat count per skill
Full scan report
Detailed pattern analysis
Auto-fix vulnerabilities
Real-time detection
Real-time blocking
Community threat definitions
Priority threat feed
Telegram/Slack alerts
Multi-instance (up to 5)

Don't install blind

Every community skill is a piece of code running on your machine. Know what it does before it does it.

Get ClawGuard Free
npx clawguard init

Part of the Cyberforce Security Suite

ClawGuard is one product in a complete cybersecurity platform. Protect your APIs, endpoints, browsers, and AI agents — all from one team.

ByeBot Agents
API security — 8 AI agents, 229 skills protecting your endpoints
Watchdog
Endpoint scanner — 25 modules detecting hidden threats on dev machines
Striker
Offensive testing — 34 security checks across recon, assess & attack modes
Hammer SDK
Browser-side protection — 24 packages for client-side security
Explore Cyberforce Suite →