Agent skill

Clawscan CLI

by openclaw in openclaw/clawscan

A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…

MITAuto-check passedSecurity

Install Clawscan CLI

skills CLI
$ npx skills add openclaw/clawscan --skill clawscan-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/clawscan clawscan-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/clawscan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/clawscan-cli .claude/skills/clawscan-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
clawscan-cli
GitHub stars
142
Token cost
~3k tokens
SKILL.md length
1,274 words
Files
2
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…

  • Explaining the ClawScan CLI
  • SKILL.md covers Overview, Command Surface, Targets, Profiles, And Config and Scanners, plus 4 more sections
  • Calls go, uv and npm; reaches github.com; needs OPENAI_API_KEY and LLM_API_KEY
  • Including one-off agent-skill scans

What it does

Clawscan CLI is an agent skill from openclaw/clawscan. Use when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and interpreting clawscan-run-v1 and clawscan-benchmark-v1 artifacts.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Prompt injection and agent security. The repository describes itself as: Composable security scanning harness for agent skills. The licence is MIT.

When your agent uses it

  • Explaining the ClawScan CLI
  • Including one-off agent-skill scans
  • Scanner fixtures
  • Judge harness commands

Example prompts

  • “/clawscan-cli”

Requirements

  • Python 3
  • Node.js
  • Docker
  • A credential in OPENAI_API_KEY
  • A credential in CODEX_API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 6cde6b1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • uv
    • npm
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY
    • LLM_API_KEY
    • VIRUSTOTAL_API_KEY
    • SOCKET_CLI_API_TOKEN
    • SNYK_TOKEN
    • NVIDIA_INFERENCE_KEY
    • ANTHROPIC_API_KEY
    • ANTHROPIC_PROXY_API_KEY
    • AI_DEFENSE_API_KEY
    • AIG_MODEL_API_KEY
    • AIG_API_KEY
    • CODEX_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Clawscan CLI loads about 3k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 1,274 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/clawscan at commit 6cde6b1, republished under its MIT licence (© openclaw). 1,274 words, ~2,988 tokens.

Download SKILL.mdSave it as .claude/skills/clawscan-cli/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
clawscan-cli
description
Use when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and interpreting clawscan-run-v1 and clawscan-benchmark-v1 artifacts.

ClawScan CLI

Overview

Use ClawScan to run one or more security scanners against agent skills, preserve raw scanner evidence, and optionally pass the evidence to an external judge harness. The public CLI is general-purpose; ClawHub-specific parity helpers belong outside cmd/clawscan. Keep secrets in environment variables, never CLI flags.

Command Surface

Run from the repo root during development:

bash
go run ./cmd/clawscan <target> --scanner <scanner-id> [flags]

Use the installed binary when available:

bash
clawscan <target> --scanner <scanner-id> [flags]

Choose the run mode:

NeedShape
Scan repo skills with one scannerclawscan --scanner skillspector from a repo with ./skills/<name>/SKILL.md
Scan repo skills with the ClawHub profileclawscan --profile clawhub from a repo with ./skills/<name>/SKILL.md
Scan one explicit target with a profileclawscan ./my-skill --profile clawhub
Capture raw scanner evidence onlyclawscan ./my-skill --scanner clawscan-static
Print raw JSON to stdoutAdd --json.
Run all profiles from a configclawscan ./my-skill --config ./security/clawscan.yml
Run one config profileclawscan ./my-skill --config ./security/clawscan.yml --profile review
Install scanner dependenciesclawscan install aig cisco skillspector
List scanner catalogclawscan scanners
Inspect one scannerclawscan scanners skillspector
List resolved profilesclawscan profiles
Print resolved profile YAMLclawscan profiles -v
List benchmark catalogclawscan benchmark list
Run SkillTrustBenchclawscan benchmark SkillTrustBench --limit 10 --scanner clawscan-static --output run.json
Run ClawHub Security Signalsclawscan benchmark clawhub-security-signals --split eval_holdout --limit 10 --scanner clawscan-static --output run.json
Use stable scanner evidenceAdd --scanner-result <id=path> for each fixture-backed scanner.
Add or override a judge harnessAdd --judge '<command with placeholders>'.
Use host-installed scanner/judge CLIsAdd --sandbox off only in an already-isolated environment.

Helpful metadata:

bash
clawscan --help
clawscan -h
clawscan --version
clawscan scanners
clawscan profiles
clawscan benchmark list

Unless --json is passed, ClawScan writes the full artifact to ./clawscan-results/artifact.json by default, preserves per-scanner JSON files in the same visible results bundle, and prints a concise key/value summary ending in full_results: ./clawscan-results/artifact.json. Use --output <path> to choose a different artifact path; explicit .json paths keep that artifact file and write scanner JSON beside it.

Targets, Profiles, And Config

If no target is passed with --scanner, --profile, or --config, ClawScan scans child skill directories under ./skills. If ./skills is missing or contains no children with SKILL.md, it fails with a target-discovery error. Plain clawscan without --scanner, --profile, or --config is invalid. Benchmark runs use clawscan benchmark <benchmark-id> and do not accept scan targets.

Built-in profiles:

ProfileScannersJudge
clawhubskillspector, clawscan-staticbundled Codex judge with ClawHub prompt/schema

Profiles are loaded from embedded built-ins. Project .clawscan.yml / .clawscan.yaml files are NOT loaded automatically: pass --config <path> to load a specific config, or --discover-config to load the nearest one found upward from the current directory. A project profile with the same name shadows the built-in whole profile. --config <path> without --profile runs every profile in that config and emits a clawscan-batch-v1 artifact. Discovery is off by default because project configs can define scanner commands that execute with the caller's environment and credentials.

Use clawscan profiles to inspect the built-in profile catalog. Use clawscan profiles -v to print it as pasteable YAML.

CLI flags override the selected profile for one run. Passing --scanner without --profile creates an ad hoc scanner-only run, so profile judges are not invoked accidentally.

Minimal config:

yaml
version: 1
sandbox:
  mode: docker
  env:
    - OPENAI_API_KEY
    - CODEX_API_KEY
profiles:
  review:
    scanners:
      - clawscan-static
    json: true
    judge:
      command: judge --out {{ output }}

sandbox.env is an allowlist of env var names to pass into the Docker runtime; store names there, not secret values. CLI equivalents are --sandbox, --sandbox-image, and repeatable --sandbox-env.

Scanners

Use clawscan scanners for the registry-backed scanner catalog and clawscan scanners <scanner-id> for one scanner's repository, description, env vars, and install guidance.

Accepted scanner IDs:

text
agentverus, aig, cisco, clawscan-static, skillspector, snyk, socket, virustotal

Credential rules:

ScannerEnv vars
aigrequired: LLM_API_KEY or OPENAI_API_KEY; optional local scanner config: DEFAULT_MODEL, DEFAULT_BASE_URL, DEFAULT_MODEL_CONTEXT_WINDOW, LOG_LEVEL
socketrequired: SOCKET_CLI_API_TOKEN
snykrequired: SNYK_TOKEN
virustotalrequired: VIRUSTOTAL_API_KEY
skillspectoroptional provider config: SKILLSPECTOR_PROVIDER, SKILLSPECTOR_MODEL, NVIDIA_INFERENCE_KEY, OPENAI_API_KEY, OPENAI_BASE_URL, ANTHROPIC_API_KEY, ANTHROPIC_PROXY_ENDPOINT_URL, ANTHROPIC_PROXY_API_KEY
ciscooptional upstream analyzers: SKILL_SCANNER_LLM_*, SKILL_SCANNER_META_LLM_*, VIRUSTOTAL_API_KEY, AI_DEFENSE_API_KEY, AI_DEFENSE_API_URL

Artifact env fields record only present or missing; they must never contain secret values. GenDigital/Gen Agent Trust Hub is not a built-in scanner because there is no local CLI for ClawScan to invoke.

Dependency setup:

bash
clawscan install aig cisco skillspector

clawscan install accepts one or more scanner IDs. It follows upstream scanner install docs where they publish an install command, including A.I.G's pip install aig-skill-scan, Cisco's uv pip install cisco-ai-skill-scanner, SkillSpector's uv tool install git+https://github.com/NVIDIA/skillspector.git, Socket's npm install -g socket, and AgentVerus' npm install --save-dev agentverus-scanner. Snyk is launcher-based, so ClawScan verifies uvx; built-in and simple API-backed scanners are skipped. The aig adapter runs aig-skill-scan --repo <target> --language en -o <result.sarif.json> and stores the SARIF 2.1.0 document as raw scanner evidence.

Starting in ClawScan v0.1.2, aig no longer uses the legacy A.I.G Docker/API service. Replace AIG_MODEL with DEFAULT_MODEL, AIG_MODEL_BASE_URL with DEFAULT_BASE_URL, and AIG_MODEL_API_KEY with LLM_API_KEY or OPENAI_API_KEY; AIG_BASE_URL and AIG_API_KEY are retired. The local scanner accepts directory targets only.

For normal runs, command-backed scanners and judges run in ghcr.io/openclaw/clawscan-runtime:latest. clawscan install is mainly for local development or --sandbox off environments.

Use --scanner-result when a test or fixture should supply stable scanner JSON:

bash
clawscan ./my-skill \
  --scanner skillspector \
  --scanner-result skillspector=./fixtures/skillspector.json \
  --json

The scanner must still be requested with --scanner or via the selected profile.

Show full SKILL.md (472 more words)Show less

Benchmarks

Use clawscan benchmark list for the registry-backed benchmark catalog.

Supported benchmarks:

text
cuhk-zhuque/SkillTrustBench
clawhub-security-signals

Run SkillTrustBench with the canonical Hugging Face ID or the short alias SkillTrustBench:

bash
clawscan benchmark SkillTrustBench \
  --limit 10 \
  --scanner clawscan-static \
  --output /tmp/clawscan-benchmark.json

SkillTrustBench uses split benchmark. The first live run downloads and caches benchmark_full_v1.0.zip, then extracts only the requested case directories into temporary scan targets.

Use --ids <path-or-url> with SkillTrustBench to run a fixed subset from a plain text file with one ID per line or JSONL rows with an id field. The source is streamed and may contain at most 5,520 unique IDs, at most 256 bytes per trimmed ID, and at most 256 KiB (262,144 bytes) of retained ID text. These are selection limits, not a total source-size limit; JSONL sources may exceed 256 KiB. Individual lines must be smaller than the parser's 1 MiB buffer limit. --ids preserves source order, records idsSource, idsCount, and idsSha256 in the artifact, and is mutually exclusive with --limit and --offset.

ClawHub Security Signals splits: train, validation, test, eval_holdout. --limit 0 means run the full selected split. Use --offset with --limit for reproducible chunks.

For clawhub-security-signals, --output ./clawscan-benchmark.json also writes ./predictions.jsonl. Use --predictions-output <path> to choose another path. --predictions-output is only supported for clawhub-security-signals.

Benchmark artifacts use clawscan-benchmark-v1. Each case embeds the normal clawscan-run-v1 artifact, expected verdict metadata, and evaluation status. The summary includes case counts, scanner/judge statuses, and accuracy over scored cases. Inspect the JSON artifact for full evidence.

Judge Harness

--judge runs through the platform shell and must produce a JSON object on stdout or at {{ output }}.

Important placeholders:

PlaceholderMeaning
{{ workspace }}Temporary judge workspace with copied target files, scanner JSON, and metadata.
{{ prompt }} / {{ prompt:path }}Render prompt template and interpolate the rendered prompt path.
{{ output_schema }} / {{ output_schema:path }}Copy schema and interpolate the copied schema path.
{{ output }}Path where the judge should write final JSON.

Prompt files can reference requested scanner JSON:

md
```json
{{ scanners.skillspector }}
```

If a prompt references an unrequested scanner, ClawScan should fail clearly. The built-in clawhub profile uses this same judge mechanism with embedded prompt and output-schema files.

Verification

Use static scanner smokes for local proof because they do not need secrets:

bash
go run ./cmd/clawscan ./README.md --scanner clawscan-static --output /tmp/clawscan-smoke.json
go run ./cmd/clawscan benchmark SkillTrustBench --limit 1 --scanner clawscan-static --output /tmp/clawscan-benchmark-smoke.json
go run ./cmd/clawscan --help
go test -count=1 ./...
go vet ./...

Common Mistakes

  • Do not pass API keys as CLI flags.
  • Do not run plain clawscan; choose --scanner, --profile, --config, or clawscan benchmark <benchmark-id>.
  • Do not assume clawscan scans .; no target means discover ./skills.
  • Do not expect a profile judge when passing explicit --scanner flags without --profile.
  • Do not use benchmark flags such as --split, --limit, or --offset outside clawscan benchmark <benchmark-id>.
  • Do not use --config without --profile for benchmark runs; all-profile config runs are target scans only.
  • Do not assume host-installed scanner CLIs are used by default; command-backed scanners and judges use the Docker runtime unless --sandbox off is set.
  • Do not add unsupported dataset names; built-ins are SkillTrustBench and clawhub-security-signals.
  • Do not assume scanner failures are final policy verdicts; scanner output is raw evidence for comparison or judging.

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/clawscan-cli of openclaw/clawscan.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 6cde6b1

Compare with similar skills

Clawscan CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Clawscan CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Clawscan CLI this skillopenclaw/clawscan142—~3kAutomated safety check: PassMIT
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Forensifyalexgreensh/repo-forensics187—~2.5kAutomated safety check: NotesCustom licence
Hol Guardhashgraph-online/hol-guard797—~542Automated safety check: PassApache-2.0
Kesekit Checkcdppcorp/KESE-KIT359—~1.3kAutomated safety check: PassMIT
Setuphashgraph-online/hol-guard797—~443Automated safety check: PassApache-2.0

Similar skills

  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    187 GitHub stars~2.5k tokensUpdated 10 days ago
    SecurityAuto-check: notes
  • Hol Guard

    hashgraph-online/hol-guard

    Run HOL Guard scanner and guard operations via uv run hol-guard.

    797 GitHub stars~542 tokensUpdated today
    SecurityAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    359 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Setup

    hashgraph-online/hol-guard

    Install or initialize HOL Guard local runtime protection for Claude Code.

    797 GitHub stars~443 tokensUpdated today
    SecurityAuto-check passed
  • Kesekit Fix

    cdppcorp/KESE-KIT

    Auto-fix security vulnerabilities found in CII, AI, robot, space, and supply chain systems.

    359 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed

More from openclaw/clawscan

  • A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…

    142 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability…

    142 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Clawscan CLI

What does Clawscan CLI do?

A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…. Clawscan CLI is an agent skill from openclaw/clawscan. Use when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and interpreting clawscan-run-v1 and clawscan-benchmark-v1 artifacts.

When should I use Clawscan CLI?

Clawscan CLI fits situations like: explaining the ClawScan CLI; including one-off agent-skill scans; scanner fixtures; judge harness commands.

How do I install Clawscan CLI in Claude Code?

Run `npx skills add openclaw/clawscan --skill clawscan-cli -a claude-code`. Or copy the skill folder (skills/clawscan-cli in openclaw/clawscan) into .claude/skills/clawscan-cli in your project. Claude Code loads it when a task matches its description.

How do I install Clawscan CLI in Codex?

Run `npx skills add openclaw/clawscan --skill clawscan-cli -a codex`. Or copy the skill folder (skills/clawscan-cli in openclaw/clawscan) into .agents/skills/clawscan-cli in your project. Codex loads it when a task matches its description.

Can I use Clawscan CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/clawscan --skill clawscan-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/clawscan-cli, .gemini/skills/clawscan-cli, .github/skills/clawscan-cli and .opencode/skills/clawscan-cli in your project.

What does Clawscan CLI need to run?

Going by SKILL.md and its folder, Clawscan CLI needs the command-line tools its instructions call (go, uv, npm and pip) and credentials named OPENAI_API_KEY, LLM_API_KEY, VIRUSTOTAL_API_KEY and SOCKET_CLI_API_TOKEN. Our summary lists: Python 3; Node.js; Docker; A credential in OPENAI_API_KEY; A credential in CODEX_API_KEY.

Does Clawscan CLI access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Clawscan CLI safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Clawscan CLI use?

Clawscan CLI is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Clawscan CLI use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Clawscan CLI?

Skills that share tags, products or a category with Clawscan CLI: Skill Scanner (getsentry/skills, 1k stars), Forensify (alexgreensh/repo-forensics, 187 stars), Hol Guard (hashgraph-online/hol-guard, 797 stars) and Kesekit Check (cdppcorp/KESE-KIT, 359 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Clawscan CLI?

openclaw (a GitHub organization) maintains it in openclaw/clawscan, which has 142 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 6, 2026.

Source: openclaw/clawscan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.