Agent skill

Report Clawhub Malicious Skill

by openclaw in openclaw/clawscan

A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…

MITAuto-check passedSecurity

Install Report Clawhub Malicious Skill

skills CLI
$ npx skills add openclaw/clawscan --skill report-clawhub-malicious-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/clawscan report-clawhub-malicious-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/clawscan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/report-clawhub-malicious-skill .claude/skills/report-clawhub-malicious-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
report-clawhub-malicious-skill
GitHub stars
143
Token cost
~1.1k tokens
SKILL.md length
426 words
Files
2
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…

  • Works in 5 steps: Open a GitHub private vulnerability… → Create a proposal-only branch and config. → Prove the candidate catches the reported… → …
  • Contributor found
  • SKILL.md covers Overview, Safety Boundary, Workflow and Output Shape
  • Reaches huggingface.co

What it does

Report Clawhub Malicious Skill is an agent skill from openclaw/clawscan. Use when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability report, preparing a proposal-only PR, creating proposals/<GHSA-ID/clawscan.yml, running ClawScan against the malicious skill, and explaining what evidence belongs in private versus public channels.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Prompt injection and agent security. It works with GitHub. The repository describes itself as: Composable security scanning harness for agent skills. The licence is MIT.

When your agent uses it

  • Contributor found
  • Suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability report
  • Preparing a proposal-only PR
  • Creating proposals/<GHSA-ID/clawscan.yml

Example prompts

  • “/report-clawhub-malicious-skill”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Open a GitHub private vulnerability report.
  2. Create a proposal-only branch and config.
  3. Prove the candidate catches the reported skill locally.
  4. Open the public PR.
  5. Explain maintainer validation.

What it can do on your machine

Read from SKILL.md and the folder at commit 128e696. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • huggingface.co

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Report Clawhub Malicious Skill loads about 1.1k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 426 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/clawscan at commit 128e696, republished under its MIT licence (© openclaw). 426 words, ~1,129 tokens.

Download SKILL.mdSave it as .claude/skills/report-clawhub-malicious-skill/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
report-clawhub-malicious-skill
description
Use when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability report, preparing a proposal-only PR, creating `proposals/<GHSA-ID>/clawscan.yml`, running ClawScan against the malicious skill, and explaining what evidence belongs in private versus public channels.

Report ClawHub Malicious Skill

Overview

Use this workflow to help someone report a malicious ClawHub skill and propose a ClawScan profile change that catches it. Keep sensitive details private and make the public PR contain only the candidate ClawScan config.

Safety Boundary

Separate private evidence from public contribution material:

  • Put live malicious skill URLs/slugs, impact, exploit details, reproduction notes, and private ClawScan artifacts in GitHub private vulnerability reporting.
  • Do not paste secrets, exploit payloads, private artifacts, or live bypass details into public issues, public PR text, README edits, or config comments.
  • Do not ask the reporter to execute the suspicious skill. ClawScan should scan a local copy as data; it should not run the skill's behavior.
  • If the reporter does not have a GHSA/private report id yet, have them open the private report first and wait for the identifier before opening the public proposal PR.

Workflow

  1. Open a GitHub private vulnerability report.

    Ask the reporter to include:

    • affected ClawHub skill URLs or slugs
    • why the current clawhub profile missed it
    • why the proposed ClawScan config catches it
    • local ClawScan artifact paths or attached artifacts
    • any private reproduction context maintainers need
  2. Create a proposal-only branch and config.

    The public PR should add only:

    text
    proposals/<GHSA-ID>/clawscan.yml

    The file must define a clawhub profile. Start from the current profile and change only what is needed to catch the reported case:

    yaml
    version: 1
    profiles:
      clawhub:
       scanners:
         - skillspector
         - clawscan-static
        judge:
          command: >
            # candidate judge command, if changed

    Do not edit the official bundled profile files in the proposal PR:

    • internal/profiles/clawhub/clawscan.yml
    • internal/profiles/clawhub/prompt.md
    • internal/profiles/clawhub/output.schema.json
  3. Prove the candidate catches the reported skill locally.

    Use a local copy of the suspicious skill:

    bash
    clawscan /path/to/suspect-skill \
      --config proposals/<GHSA-ID>/clawscan.yml \
      --profile clawhub \
      --output ./artifacts/reported-skill-candidate.json

    If useful, compare against the built-in profile:

    bash
    clawscan /path/to/suspect-skill \
      --profile clawhub \
      --output ./artifacts/reported-skill-current.json

    The public PR should not include the private artifacts unless maintainers say the contents are safe to publish. Reference them in the private report.

  4. Open the public PR.

    Keep the PR text minimal:

    • state that a private vulnerability report exists
    • point to proposals/<GHSA-ID>/clawscan.yml
    • do not include sensitive skill details
    • say maintainers should run the official SkillTrustBench Profile Gate
  5. Explain maintainer validation.

    Maintainers run the official gate against the proposal:

    bash
    clawscan benchmark SkillTrustBench \
      --ids https://huggingface.co/datasets/cuhk-zhuque/SkillTrustBench-results/resolve/main/data/evaluation_subset_10pct.jsonl \
      --config proposals/<GHSA-ID>/clawscan.yml \
      --profile clawhub \
      --output ./artifacts/skilltrustbench-candidate.json

    The proposal's clawhub profile shadows the built-in profile for that run. Maintainers review the private report, upload/preserve the benchmark artifact, add a dated baseline under benchmarks/skilltrustbench-leaderboard-10pct/, and port accepted behavior into the bundled clawhub profile. The latest YYYY-MM-DD.json baseline is the current accepted baseline.

Show full SKILL.md (45 more words)Show less

Output Shape

When walking someone through the process, end with:

  • private report checklist
  • exact proposal file path
  • candidate config draft or edits needed
  • local ClawScan commands to run
  • public PR checklist
  • clear note that maintainers own the official SkillTrustBench gate and final built-in profile port

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/report-clawhub-malicious-skill of openclaw/clawscan.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 128e696

Compare with similar skills

Report Clawhub Malicious Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Report Clawhub Malicious Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Report Clawhub Malicious Skill this skillopenclaw/clawscan143—~1.1kAutomated safety check: PassMIT
Agentic GitHub Actions Auditortrailofbits/skills7.5k6 repos~5.4kAutomated safety check: NotesCC-BY-SA-4.0
Slowmist Agent Securityslowmist/slowmist-agent-security508—~1.4kAutomated safety check: PassMIT
PR Auditakitaonrails/my-skills216—~4.8kAutomated safety check: PassNone
Binance Token AuditTermiX-official/cryptoclaw100—~695Automated safety check: PassMIT
Iss Auditakitaonrails/my-skills216—~4.1kAutomated safety check: PassNone

Similar skills

  • Official

    Statically audits GitHub Actions workflows that run AI coding agents, tracing attacker-controlled input to agent prompts and flagging unsafe sandbox, trigger and allowlist settings.

    7.5k GitHub starsUsed in 6 repos~5.4k tokens
    SecurityAuto-check: notes
  • Slowmist Agent Security

    slowmist/slowmist-agent-security

    Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.

    508 GitHub stars~1.4k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • PR Audit

    akitaonrails/my-skills

    Audit GitHub pull requests before merge, including contributor-claim verification, prompt-injection resistance, malicious-code and supply-chain review, regressions, tests, documentation…

    216 GitHub stars~4.8k tokensUpdated 17 days ago
    SecurityAuto-check passed
  • Binance Token Audit

    TermiX-official/cryptoclaw

    Binance Web3 official skill — security audit for token contracts, detecting honeypots, rug pulls, and malicious functions across BSC, Base, Solana, and Ethereum.

    100 GitHub stars~695 tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Iss Audit

    akitaonrails/my-skills

    Audit GitHub issues before implementation, including skeptical claim verification, safe reproduction, prompt-injection resistance, malicious-link and attachment handling, root-cause analysis…

    216 GitHub stars~4.1k tokensUpdated 17 days ago
    DevelopmentAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings

More from openclaw/clawscan

  • Clawscan CLI

    openclaw/clawscan

    A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…

    143 GitHub stars~3k tokensUpdated 3 days ago
    Auto-check passed
  • A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability…

    143 GitHub stars~1.9k tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Report Clawhub Malicious Skill

What does Report Clawhub Malicious Skill do?

A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…. Report Clawhub Malicious Skill is an agent skill from openclaw/clawscan.yml, running ClawScan against the malicious skill, and explaining what evidence belongs in private versus public channels.

When should I use Report Clawhub Malicious Skill?

Report Clawhub Malicious Skill fits situations like: contributor found; suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability report; preparing a proposal-only PR; creating proposals/<GHSA-ID/clawscan.yml.

How do I install Report Clawhub Malicious Skill in Claude Code?

Run `npx skills add openclaw/clawscan --skill report-clawhub-malicious-skill -a claude-code`. Or copy the skill folder (skills/report-clawhub-malicious-skill in openclaw/clawscan) into .claude/skills/report-clawhub-malicious-skill in your project. Claude Code loads it when a task matches its description.

How do I install Report Clawhub Malicious Skill in Codex?

Run `npx skills add openclaw/clawscan --skill report-clawhub-malicious-skill -a codex`. Or copy the skill folder (skills/report-clawhub-malicious-skill in openclaw/clawscan) into .agents/skills/report-clawhub-malicious-skill in your project. Codex loads it when a task matches its description.

Can I use Report Clawhub Malicious Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/clawscan --skill report-clawhub-malicious-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/report-clawhub-malicious-skill, .gemini/skills/report-clawhub-malicious-skill, .github/skills/report-clawhub-malicious-skill and .opencode/skills/report-clawhub-malicious-skill in your project.

What does Report Clawhub Malicious Skill need to run?

SKILL.md names no scripts, command-line tools or credentials: Report Clawhub Malicious Skill is instructions for the agent only.

Does Report Clawhub Malicious Skill access the network?

SKILL.md names 1 domain. In commands or code: huggingface.co; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Report Clawhub Malicious Skill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Report Clawhub Malicious Skill use?

Report Clawhub Malicious Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Report Clawhub Malicious Skill use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Report Clawhub Malicious Skill?

Skills that share tags, products or a category with Report Clawhub Malicious Skill: Agentic GitHub Actions Auditor (trailofbits/skills, 7.5k stars), Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars), PR Audit (akitaonrails/my-skills, 216 stars) and Binance Token Audit (TermiX-official/cryptoclaw, 100 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Report Clawhub Malicious Skill?

openclaw (a GitHub organization) maintains it in openclaw/clawscan, which has 143 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: openclaw/clawscan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.