Agent skill

Review Clawhub Profile Proposal

by openclaw in openclaw/clawscan

A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability…

MITAuto-check passedSecurity

Install Review Clawhub Profile Proposal

skills CLI
$ npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/clawscan review-clawhub-profile-proposal --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/clawscan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review-clawhub-profile-proposal .claude/skills/review-clawhub-profile-proposal && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
review-clawhub-profile-proposal
GitHub stars
143
Token cost
~1.9k tokens
SKILL.md length
701 words
Files
2
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability…

  • Works in 8 steps: Read the current repo and PR state. → Read the private report privately. → Validate the candidate profile. → …
  • An OpenClaw maintainer
  • SKILL.md covers Overview, Safety Boundary, Review Workflow and Promotion Patch Shape, plus 1 more section
  • Calls go and git; reaches huggingface.co

What it does

Review Clawhub Profile Proposal is an agent skill from openclaw/clawscan. Use when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability context without leaking it, running the SkillTrustBench Profile Gate or equivalent local benchmark, updating the accepted baseline, and promoting an accepted candidate into internal/profiles/clawhub/clawscan.yml.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Security, covering Prompt injection and agent security and Proposals and quotes. The repository describes itself as: Composable security scanning harness for agent skills. The licence is MIT.

When your agent uses it

  • An OpenClaw maintainer
  • Owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml
  • Reading the private vulnerability context without leaking it
  • Running the SkillTrustBench Profile Gate

Example prompts

  • “/review-clawhub-profile-proposal”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Read the current repo and PR state.
  2. Read the private report privately.
  3. Validate the candidate profile.
  4. Review the benchmark artifact.
  5. Update the accepted baseline summary.
  6. Decide.
  7. Verify the promoted built-in profile.
  8. Update the PR.

What it can do on your machine

Read from SKILL.md and the folder at commit 128e696. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • go
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • huggingface.co

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Review Clawhub Profile Proposal loads about 1.9k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 701 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/clawscan at commit 128e696, republished under its MIT licence (© openclaw). 701 words, ~1,859 tokens.

Download SKILL.mdSave it as .claude/skills/review-clawhub-profile-proposal/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
review-clawhub-profile-proposal
description
Use when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking `proposals/<GHSA-ID>/clawscan.yml`, reading the private vulnerability context without leaking it, running the SkillTrustBench Profile Gate or equivalent local benchmark, updating the accepted baseline, and promoting an accepted candidate into `internal/profiles/clawhub/clawscan.yml`.

Review ClawHub Profile Proposal

Overview

Use this owner-side workflow for a public PR that proposes a candidate ClawHub profile at proposals/<GHSA-ID>/clawscan.yml after a private vulnerability report. The goal is to validate the candidate, keep sensitive details private, and, if accepted, promote the public profile behavior into the bundled internal/profiles/clawhub/clawscan.yml.

Safety Boundary

  • Treat the GitHub private vulnerability report as the source for sensitive malicious skill details.
  • Do not paste live exploit details, private report text, private artifacts, or suspicious skill payloads into public PR comments, public docs, commit messages, or committed baseline summaries.
  • The public proposal PR should start with only proposals/<GHSA-ID>/clawscan.yml. Do not trust it until reviewed.
  • Do not run the suspicious skill. ClawScan scans skill files as data; it should not execute the skill's behavior.
  • Do not promote a candidate unless the private report, proposal diff, and benchmark proof all line up.

Review Workflow

  1. Read the current repo and PR state.

    • Check git status --short --branch before editing.
    • Fetch the PR branch and inspect the changed files.
    • Confirm the public PR initially contains only proposals/<GHSA-ID>/clawscan.yml plus any baseline summary commit produced by the maintainer gate.
    • Confirm the proposal file defines a clawhub profile.
    • Confirm the proposal does not edit official bundled profile files yet: internal/profiles/clawhub/clawscan.yml, internal/profiles/clawhub/prompt.md, or internal/profiles/clawhub/output.schema.json.
  2. Read the private report privately.

    Use the private vulnerability report only to understand:

    • what malicious behavior must be caught
    • why the current built-in clawhub profile misses or under-detects it
    • what evidence should be preserved privately
    • whether any proposal text or config comments leak sensitive details

    Keep public comments high-level, such as "validated against the private report" or "needs private-case follow-up"; do not quote private details.

  3. Validate the candidate profile.

    Prefer the manual GitHub Actions workflow when available:

    text
    SkillTrustBench Profile Gate

    Dispatch it with the PR number and proposal path. It should run:

    bash
    clawscan benchmark SkillTrustBench \
      --ids https://huggingface.co/datasets/cuhk-zhuque/SkillTrustBench-results/resolve/main/data/evaluation_subset_10pct.jsonl \
      --config proposals/<GHSA-ID>/clawscan.yml \
      --profile clawhub \
      --output ./artifacts/skilltrustbench-candidate.json

    If running locally, use the same command. The --ids source is the public SkillTrustBench leaderboard subset and is mutually exclusive with --limit and --offset.

  4. Review the benchmark artifact.

    Check:

    • the artifact is full JSON and preserved as a workflow artifact or private maintainer artifact
    • benchmark.id is cuhk-zhuque/SkillTrustBench
    • benchmark.split is benchmark
    • benchmark.idsCount is 556
    • benchmark.idsSha256 matches the planned subset hash 903a036e4b7b16ee28e22d5d9db57a00b3764cfe41e43144acad67921e5196c2
    • scanner and judge statuses are acceptable
    • evaluation metrics are not an unacceptable regression
    • the candidate catches the private reported behavior when private proof is available
  5. Update the accepted baseline summary.

    Use the repo script so the compact baseline is generated from the full candidate artifact:

    bash
    go run ./scripts/update-skilltrustbench-baseline \
      --artifact ./artifacts/skilltrustbench-candidate.json \
      --output benchmarks/skilltrustbench-leaderboard-10pct/<YYYY-MM-DD>.json \
      --profile clawhub \
      --profile-source proposals/<GHSA-ID>/clawscan.yml \
      --subset-case-ids-sha256 903a036e4b7b16ee28e22d5d9db57a00b3764cfe41e43144acad67921e5196c2 \
      --workflow-url <workflow-url>

    If the PR merges, the newest dated JSON file in benchmarks/skilltrustbench-leaderboard-10pct/ is the latest accepted baseline for the bundled clawhub profile. The script fails if the candidate artifact's selected-ID hash does not match the planned subset. No post-merge rerun is required.

  6. Decide.

    If rejected:

    • leave a public PR comment with non-sensitive reasons
    • keep details that identify the malicious payload in the private report
    • do not edit official bundled profile files

    If accepted:

    • promote the accepted public clawhub profile behavior into internal/profiles/clawhub/clawscan.yml
    • add a dated baseline under benchmarks/skilltrustbench-leaderboard-10pct/ from the candidate artifact in the same PR
    • preserve or remove proposals/<GHSA-ID>/clawscan.yml according to the issue/PR instruction; default to preserving it as public proposal trail unless the maintainer explicitly chooses to remove it
    • keep prompt/schema changes maintainer-owned; edit internal/profiles/clawhub/prompt.md or internal/profiles/clawhub/output.schema.json only when that is the accepted change
  7. Verify the promoted built-in profile.

    Run at least:

    bash
    go test -count=1 ./...
    go vet ./...
    go run ./cmd/clawscan profiles -v
    go run ./cmd/clawscan --help

    For benchmark proof after promotion, run:

    bash
    clawscan benchmark SkillTrustBench \
      --ids https://huggingface.co/datasets/cuhk-zhuque/SkillTrustBench-results/resolve/main/data/evaluation_subset_10pct.jsonl \
      --profile clawhub \
      --output ./artifacts/skilltrustbench-clawhub.json

    Use a smaller proof only when explicitly accepted; the official gate uses the subset ID source above.

  8. Update the PR.

    • Push the promotion commit to the PR branch if that is the chosen review path.
    • Keep the PR body/comments free of private exploit details.
    • Add proof with commands, artifact links, and residual risk.
Show full SKILL.md (88 more words)Show less

Promotion Patch Shape

The maintainer promotion commit usually touches:

text
internal/profiles/clawhub/clawscan.yml
benchmarks/skilltrustbench-leaderboard-10pct/<YYYY-MM-DD>.json

It may also touch:

text
internal/profiles/clawhub/prompt.md
internal/profiles/clawhub/output.schema.json
docs/
tests

Do not include private artifacts, malicious payload details, or generated dist/ output in ordinary promotion commits unless the issue explicitly asks for them.

Handoff Shape

End with:

  • verdict: accepted, rejected, or blocked
  • proposal path and PR/ref reviewed
  • private report checked, without sensitive details
  • benchmark command and artifact location
  • baseline summary update status
  • bundled profile files changed
  • exact verification commands and results
  • commit SHA or reason no commit was created
  • residual risk and next owner action

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/review-clawhub-profile-proposal of openclaw/clawscan.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 128e696

Compare with similar skills

Review Clawhub Profile Proposal next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Review Clawhub Profile Proposal compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Review Clawhub Profile Proposal this skillopenclaw/clawscan143—~1.9kAutomated safety check: PassMIT
Sailpillar-labs/sail-skill113—~5.1kAutomated safety check: PassCustom licence
Skill Scannergetsentry/skills1k4 repos~2.5kAutomated safety check: WarnApache-2.0
Forensifyalexgreensh/repo-forensics190—~2.5kAutomated safety check: NotesCustom licence
Hol Guardhashgraph-online/hol-guard845—~542Automated safety check: PassApache-2.0
Kesekit Checkcdppcorp/KESE-KIT360—~1.3kAutomated safety check: PassMIT

Similar skills

  • Sail

    pillar-labs/sail-skill

    Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.

    113 GitHub stars~5.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    SecurityAuto-check: warnings
  • Forensify

    alexgreensh/repo-forensics

    Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.

    190 GitHub stars~2.5k tokensUpdated 14 days ago
    SecurityAuto-check: notes
  • Hol Guard

    hashgraph-online/hol-guard

    Run HOL Guard scanner and guard operations via uv run hol-guard.

    845 GitHub stars~542 tokensUpdated today
    SecurityAuto-check passed
  • Kesekit Check

    cdppcorp/KESE-KIT

    Run a pre-deployment security compliance checklist based on KISA guidelines.

    360 GitHub stars~1.3k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Setup

    hashgraph-online/hol-guard

    Install or initialize HOL Guard local runtime protection for Claude Code.

    845 GitHub stars~443 tokensUpdated today
    SecurityAuto-check passed

More from openclaw/clawscan

  • Clawscan CLI

    openclaw/clawscan

    A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…

    143 GitHub stars~3k tokensUpdated 4 days ago
    Auto-check passed
  • A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…

    143 GitHub stars~1.1k tokensUpdated 4 days ago
    Auto-check passed

Questions about Review Clawhub Profile Proposal

What does Review Clawhub Profile Proposal do?

A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability…. Review Clawhub Profile Proposal is an agent skill from openclaw/clawscan.yml.

When should I use Review Clawhub Profile Proposal?

Review Clawhub Profile Proposal fits situations like: an OpenClaw maintainer; owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml; reading the private vulnerability context without leaking it; running the SkillTrustBench Profile Gate.

How do I install Review Clawhub Profile Proposal in Claude Code?

Run `npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a claude-code`. Or copy the skill folder (skills/review-clawhub-profile-proposal in openclaw/clawscan) into .claude/skills/review-clawhub-profile-proposal in your project. Claude Code loads it when a task matches its description.

How do I install Review Clawhub Profile Proposal in Codex?

Run `npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a codex`. Or copy the skill folder (skills/review-clawhub-profile-proposal in openclaw/clawscan) into .agents/skills/review-clawhub-profile-proposal in your project. Codex loads it when a task matches its description.

Can I use Review Clawhub Profile Proposal in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-clawhub-profile-proposal, .gemini/skills/review-clawhub-profile-proposal, .github/skills/review-clawhub-profile-proposal and .opencode/skills/review-clawhub-profile-proposal in your project.

What does Review Clawhub Profile Proposal need to run?

Going by SKILL.md and its folder, Review Clawhub Profile Proposal needs the command-line tools its instructions call (go and git).

Does Review Clawhub Profile Proposal access the network?

SKILL.md names 1 domain. In commands or code: huggingface.co; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Review Clawhub Profile Proposal safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Review Clawhub Profile Proposal use?

Review Clawhub Profile Proposal is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Review Clawhub Profile Proposal use?

About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Review Clawhub Profile Proposal?

Skills that share tags, products or a category with Review Clawhub Profile Proposal: Sail (pillar-labs/sail-skill, 113 stars), Skill Scanner (getsentry/skills, 1k stars), Forensify (alexgreensh/repo-forensics, 190 stars) and Hol Guard (hashgraph-online/hol-guard, 845 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Review Clawhub Profile Proposal?

openclaw (a GitHub organization) maintains it in openclaw/clawscan, which has 143 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: openclaw/clawscan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.