Sail
pillar-labs/sail-skill
Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.
A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability…
$ npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openclaw/clawscan review-clawhub-profile-proposal --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openclaw/clawscan.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/review-clawhub-profile-proposal .claude/skills/review-clawhub-profile-proposal && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "review-clawhub-profile-proposal" agent skill from https://github.com/openclaw/clawscan/tree/main/skills/review-clawhub-profile-proposal into .claude/skills/review-clawhub-profile-proposal/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-clawhub-profile-proposal", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openclaw/clawscan/tree/main/skills/review-clawhub-profile-proposalType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openclaw/clawscan review-clawhub-profile-proposal --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/clawscan.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/review-clawhub-profile-proposal .agents/skills/review-clawhub-profile-proposal && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "review-clawhub-profile-proposal" agent skill from https://github.com/openclaw/clawscan/tree/main/skills/review-clawhub-profile-proposal into .agents/skills/review-clawhub-profile-proposal/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-clawhub-profile-proposal", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openclaw/clawscan review-clawhub-profile-proposal --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/clawscan.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/review-clawhub-profile-proposal .cursor/skills/review-clawhub-profile-proposal && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "review-clawhub-profile-proposal" agent skill from https://github.com/openclaw/clawscan/tree/main/skills/review-clawhub-profile-proposal into .cursor/skills/review-clawhub-profile-proposal/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-clawhub-profile-proposal", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openclaw/clawscan.git --path skills/review-clawhub-profile-proposal--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openclaw/clawscan review-clawhub-profile-proposal --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/clawscan.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/review-clawhub-profile-proposal .gemini/skills/review-clawhub-profile-proposal && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "review-clawhub-profile-proposal" agent skill from https://github.com/openclaw/clawscan/tree/main/skills/review-clawhub-profile-proposal into .gemini/skills/review-clawhub-profile-proposal/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-clawhub-profile-proposal", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openclaw/clawscan review-clawhub-profile-proposalInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openclaw/clawscan.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/review-clawhub-profile-proposal .github/skills/review-clawhub-profile-proposal && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "review-clawhub-profile-proposal" agent skill from https://github.com/openclaw/clawscan/tree/main/skills/review-clawhub-profile-proposal into .github/skills/review-clawhub-profile-proposal/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-clawhub-profile-proposal", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openclaw/clawscan review-clawhub-profile-proposal --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/clawscan.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/review-clawhub-profile-proposal .opencode/skills/review-clawhub-profile-proposal && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "review-clawhub-profile-proposal" agent skill from https://github.com/openclaw/clawscan/tree/main/skills/review-clawhub-profile-proposal into .opencode/skills/review-clawhub-profile-proposal/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "review-clawhub-profile-proposal", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
review-clawhub-profile-proposalA skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability…
Review Clawhub Profile Proposal is an agent skill from openclaw/clawscan. Use when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability context without leaking it, running the SkillTrustBench Profile Gate or equivalent local benchmark, updating the accepted baseline, and promoting an accepted candidate into internal/profiles/clawhub/clawscan.yml.
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).
It sits in Security, covering Prompt injection and agent security and Proposals and quotes. The repository describes itself as: Composable security scanning harness for agent skills. The licence is MIT.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 128e696. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gogitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
huggingface.coFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Review Clawhub Profile Proposal loads about 1.9k tokens when it runs. Until then it costs about 107 tokens; SKILL.md has 701 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from openclaw/clawscan at commit 128e696, republished under its MIT licence (© openclaw). 701 words, ~1,859 tokens.
.claude/skills/review-clawhub-profile-proposal/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this owner-side workflow for a public PR that proposes a candidate ClawHub
profile at proposals/<GHSA-ID>/clawscan.yml after a private vulnerability
report. The goal is to validate the candidate, keep sensitive details private,
and, if accepted, promote the public profile behavior into the bundled
internal/profiles/clawhub/clawscan.yml.
proposals/<GHSA-ID>/clawscan.yml. Do not trust it until reviewed.Read the current repo and PR state.
git status --short --branch before editing.proposals/<GHSA-ID>/clawscan.yml plus any baseline summary commit
produced by the maintainer gate.clawhub profile.internal/profiles/clawhub/clawscan.yml,
internal/profiles/clawhub/prompt.md, or
internal/profiles/clawhub/output.schema.json.Read the private report privately.
Use the private vulnerability report only to understand:
clawhub profile misses or under-detects itKeep public comments high-level, such as "validated against the private report" or "needs private-case follow-up"; do not quote private details.
Validate the candidate profile.
Prefer the manual GitHub Actions workflow when available:
SkillTrustBench Profile GateDispatch it with the PR number and proposal path. It should run:
clawscan benchmark SkillTrustBench \
--ids https://huggingface.co/datasets/cuhk-zhuque/SkillTrustBench-results/resolve/main/data/evaluation_subset_10pct.jsonl \
--config proposals/<GHSA-ID>/clawscan.yml \
--profile clawhub \
--output ./artifacts/skilltrustbench-candidate.jsonIf running locally, use the same command. The --ids source is the public
SkillTrustBench leaderboard subset and is mutually exclusive with --limit
and --offset.
Review the benchmark artifact.
Check:
benchmark.id is cuhk-zhuque/SkillTrustBenchbenchmark.split is benchmarkbenchmark.idsCount is 556benchmark.idsSha256 matches the planned subset hash
903a036e4b7b16ee28e22d5d9db57a00b3764cfe41e43144acad67921e5196c2Update the accepted baseline summary.
Use the repo script so the compact baseline is generated from the full candidate artifact:
go run ./scripts/update-skilltrustbench-baseline \
--artifact ./artifacts/skilltrustbench-candidate.json \
--output benchmarks/skilltrustbench-leaderboard-10pct/<YYYY-MM-DD>.json \
--profile clawhub \
--profile-source proposals/<GHSA-ID>/clawscan.yml \
--subset-case-ids-sha256 903a036e4b7b16ee28e22d5d9db57a00b3764cfe41e43144acad67921e5196c2 \
--workflow-url <workflow-url>If the PR merges, the newest dated JSON file in
benchmarks/skilltrustbench-leaderboard-10pct/ is the latest accepted
baseline for the bundled clawhub profile. The script fails if the
candidate artifact's selected-ID hash does not match the planned subset. No
post-merge rerun is required.
Decide.
If rejected:
If accepted:
clawhub profile behavior into
internal/profiles/clawhub/clawscan.ymlbenchmarks/skilltrustbench-leaderboard-10pct/
from the candidate artifact in the same PRproposals/<GHSA-ID>/clawscan.yml according to the
issue/PR instruction; default to preserving it as public proposal trail
unless the maintainer explicitly chooses to remove itinternal/profiles/clawhub/prompt.md or
internal/profiles/clawhub/output.schema.json only when that is the
accepted changeVerify the promoted built-in profile.
Run at least:
go test -count=1 ./...
go vet ./...
go run ./cmd/clawscan profiles -v
go run ./cmd/clawscan --helpFor benchmark proof after promotion, run:
clawscan benchmark SkillTrustBench \
--ids https://huggingface.co/datasets/cuhk-zhuque/SkillTrustBench-results/resolve/main/data/evaluation_subset_10pct.jsonl \
--profile clawhub \
--output ./artifacts/skilltrustbench-clawhub.jsonUse a smaller proof only when explicitly accepted; the official gate uses the subset ID source above.
Update the PR.
The maintainer promotion commit usually touches:
internal/profiles/clawhub/clawscan.yml
benchmarks/skilltrustbench-leaderboard-10pct/<YYYY-MM-DD>.jsonIt may also touch:
internal/profiles/clawhub/prompt.md
internal/profiles/clawhub/output.schema.json
docs/
testsDo not include private artifacts, malicious payload details, or generated
dist/ output in ordinary promotion commits unless the issue explicitly asks
for them.
End with:
© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/review-clawhub-profile-proposal of openclaw/clawscan.
Open the folder on GitHubat commit 128e696
Review Clawhub Profile Proposal next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Review Clawhub Profile Proposal this skillopenclaw/clawscan | 143 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Sailpillar-labs/sail-skill | 113 | — | ~5.1k | Automated safety check: Pass | Custom licence | |
| Skill Scannergetsentry/skills | 1k | 4 repos | ~2.5k | Automated safety check: Warn | Apache-2.0 | |
| Forensifyalexgreensh/repo-forensics | 190 | — | ~2.5k | Automated safety check: Notes | Custom licence | |
| Hol Guardhashgraph-online/hol-guard | 845 | — | ~542 | Automated safety check: Pass | Apache-2.0 | |
| Kesekit Checkcdppcorp/KESE-KIT | 360 | — | ~1.3k | Automated safety check: Pass | MIT |
pillar-labs/sail-skill
Apply the SAIL (Secure AI Lifecycle) V2 framework by Pillar Security to secure AI applications and agents.
getsentry/skills
Scan agent skills for security issues. An agent skill from getsentry/skills.
alexgreensh/repo-forensics
Cross-agent self-inspection of your AI-agent stack. An agent skill from alexgreensh/repo-forensics.
hashgraph-online/hol-guard
Run HOL Guard scanner and guard operations via uv run hol-guard.
cdppcorp/KESE-KIT
Run a pre-deployment security compliance checklist based on KISA guidelines.
hashgraph-online/hol-guard
Install or initialize HOL Guard local runtime protection for Claude Code.
openclaw/clawscan
A skill your agent uses when running or explaining the ClawScan CLI, including one-off agent-skill scans, benchmark runs, scanner fixtures, judge harness commands, env var validation, and…
openclaw/clawscan
A skill your agent uses when a researcher, maintainer, or contributor found or suspects a malicious skill on ClawHub and needs a private reporting workflow: opening a GitHub private vulnerability…
Categories
A skill your agent uses when an OpenClaw maintainer or owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml, reading the private vulnerability…. Review Clawhub Profile Proposal is an agent skill from openclaw/clawscan.yml.
Review Clawhub Profile Proposal fits situations like: an OpenClaw maintainer; owner is reviewing a ClawHub malicious-skill profile proposal PR: checking proposals/<GHSA-ID/clawscan.yml; reading the private vulnerability context without leaking it; running the SkillTrustBench Profile Gate.
Run `npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a claude-code`. Or copy the skill folder (skills/review-clawhub-profile-proposal in openclaw/clawscan) into .claude/skills/review-clawhub-profile-proposal in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a codex`. Or copy the skill folder (skills/review-clawhub-profile-proposal in openclaw/clawscan) into .agents/skills/review-clawhub-profile-proposal in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/clawscan --skill review-clawhub-profile-proposal -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/review-clawhub-profile-proposal, .gemini/skills/review-clawhub-profile-proposal, .github/skills/review-clawhub-profile-proposal and .opencode/skills/review-clawhub-profile-proposal in your project.
Going by SKILL.md and its folder, Review Clawhub Profile Proposal needs the command-line tools its instructions call (go and git).
SKILL.md names 1 domain. In commands or code: huggingface.co; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Review Clawhub Profile Proposal is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Review Clawhub Profile Proposal: Sail (pillar-labs/sail-skill, 113 stars), Skill Scanner (getsentry/skills, 1k stars), Forensify (alexgreensh/repo-forensics, 190 stars) and Hol Guard (hashgraph-online/hol-guard, 845 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openclaw (a GitHub organization) maintains it in openclaw/clawscan, which has 143 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.
Source: openclaw/clawscan on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.