Agent skill

Skill Scanner

by sundial-org in sundial-org/awesome-openclaw-skills

Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them.

No licenceAuto-check passedSecurity

Install Skill Scanner

skills CLI
$ npx skills add sundial-org/awesome-openclaw-skills --skill skill-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sundial-org/awesome-openclaw-skills skill-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sundial-org/awesome-openclaw-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/skill-scanner .claude/skills/skill-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-scanner
GitHub stars
663
Used in
1 other repo
Token cost
~364 tokens
SKILL.md length
99 words
Files
4
Skills in repo
353
Repo updated
First seen
Licence
None found

At a glance

Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them.

  • Tasks that involve Prompt injection and agent security
  • SKILL.md covers Capabilities, Usage, Requirements and Entry Point, plus 1 more section
  • Runs Python scripts from its folder; calls python, pip and streamlit
  • Tasks that involve Security review

What it does

Skill Scanner is an agent skill from sundial-org/awesome-openclaw-skills. Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.

Its SKILL.md is about 360 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `README.md`, `skill_scanner.py` and `streamlit_ui.py`).

It sits in Security, covering Prompt injection and agent security and Security review. It works with Model Context Protocol and Streamlit. The repository describes itself as: Top OpenClaw skills, with the most popular and useful ones.

When your agent uses it

  • Tasks that involve Prompt injection and agent security
  • Tasks that involve Security review

Example prompts

  • “/skill-scanner”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit b80cde2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python
    • pip
    • streamlit

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Scanner loads about 364 tokens when it runs. Until then it costs about 63 tokens; SKILL.md has 99 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~63
When it runs · the whole SKILL.md, loaded when a task matches
~364

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 99 words (~364 tokens).

“Security audit tool for Clawdbot/MCP skills - scans for malware, spyware, crypto-mining, and malicious patterns.”

— opening of SKILL.md by sundial-org
name
skill-scanner

Read the full SKILL.md on GitHub

Files

SKILL.md and 3 other files in skills/skill-scanner of sundial-org/awesome-openclaw-skills.

  • SKILL.md
  • README.md
  • skill_scanner.py
  • streamlit_ui.py

Open the folder on GitHubat commit b80cde2

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sundial-org/awesome-openclaw-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Skill Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Scanner this skillsundial-org/awesome-openclaw-skills6631 repos~364Automated safety check: PassNone
Slowmist Agent Securityslowmist/slowmist-agent-security508—~1.4kAutomated safety check: PassMIT
AI SAFE2 Secure Build CopilotCyberStrategyInstitute/ai-safe2-framework146—~1.2kAutomated safety check: PassCustom licence
AI SAFE2 Secure Build CopilotCyberStrategyInstitute/ai-safe2-framework146—~2.7kAutomated safety check: PassCustom licence
MCP Server Security Auditawarexone/Agentic-Bug-Hunter5.3k—~1.9kAutomated safety check: WarnMIT
Security ReviewChatbotXIO/ChatbotX879—~1.6kAutomated safety check: NotesCustom licence

Similar skills

  • Slowmist Agent Security

    slowmist/slowmist-agent-security

    Comprehensive security review framework for AI agents. An agent skill from slowmist/slowmist-agent-security.

    508 GitHub stars~1.4k tokensUpdated 5 mo ago
    SecurityAuto-check passed
  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 framework to security reviews, code reviews and compliance mapping for AI agents, RAG pipelines and MCP servers.

    146 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • AI SAFE2 Secure Build Copilot

    CyberStrategyInstitute/ai-safe2-framework

    Applies the AI SAFE2 v3.1 governance framework to designing, building, auditing and testing AI agents, RAG pipelines, MCP and tool integrations and AI infrastructure.

    146 GitHub stars~2.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • MCP Server Security Audit

    awarexone/Agentic-Bug-Hunter

    Audits MCP servers and their client configs for tool poisoning, prompt injection, over-privileged tools, injection bugs, secret leaks and missing approval gates.

    5.3k GitHub stars~1.9k tokensUpdated 3 days ago
    SecurityAuto-check: warnings
  • Security Review

    ChatbotXIO/ChatbotX

    Use before committing changes to auth, workspace scoping, channel webhooks, AI tools/MCP, permission settings, or anything handling untrusted channel content in ChatbotX.

    879 GitHub stars~1.6k tokensUpdated today
    SecurityAuto-check: notes
  • Skill Inspector

    NVIDIA/SkillSpector

    Official

    Decides whether an agent skill is safe to install by combining a SkillSpector static scan with the agent's own source review, ending in APPROVE, CAUTION or REJECT.

    20k GitHub starsUsed in 1 repo~1.8k tokens
    SecurityAuto-check passed

More from sundial-org/awesome-openclaw-skills

All 353 skills in this repo
  • UI UX Pro Max

    sundial-org/awesome-openclaw-skills

    UI/UX design intelligence and implementation guidance for building polished interfaces.

    663 GitHub starsUsed in 2 repos~657 tokens
    Auto-check passed
  • Web Deploy GitHub

    sundial-org/awesome-openclaw-skills

    Create and deploy single-page static websites to GitHub Pages with autonomous workflow.

    663 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Clawd Modifier

    sundial-org/awesome-openclaw-skills

    Modify Clawd, the Claude Code mascot. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~625 tokensUpdated 7 mo ago
    Auto-check passed
  • Figma

    sundial-org/awesome-openclaw-skills

    Professional Figma design analysis and asset export. An agent skill from sundial-org/awesome-openclaw-skills.

    663 GitHub stars~1.7k tokensUpdated 7 mo ago
    Auto-check: notes
  • Edge Tts

    sundial-org/awesome-openclaw-skills

    Text-to-speech conversion using node-edge-tts npm package for generating audio from text.

    663 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Habit Flow

    sundial-org/awesome-openclaw-skills

    AI-powered atomic habit tracker with natural language logging, streak tracking, smart reminders, and coaching.

    663 GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed

Categories

Questions about Skill Scanner

What does Skill Scanner do?

Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Skill Scanner is an agent skill from sundial-org/awesome-openclaw-skills. Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them.

When should I use Skill Scanner?

Skill Scanner fits situations like: tasks that involve Prompt injection and agent security; tasks that involve Security review.

How do I install Skill Scanner in Claude Code?

Run `npx skills add sundial-org/awesome-openclaw-skills --skill skill-scanner -a claude-code`. Or copy the skill folder (skills/skill-scanner in sundial-org/awesome-openclaw-skills) into .claude/skills/skill-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Skill Scanner in Codex?

Run `npx skills add sundial-org/awesome-openclaw-skills --skill skill-scanner -a codex`. Or copy the skill folder (skills/skill-scanner in sundial-org/awesome-openclaw-skills) into .agents/skills/skill-scanner in your project. Codex loads it when a task matches its description.

Can I use Skill Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sundial-org/awesome-openclaw-skills --skill skill-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-scanner, .gemini/skills/skill-scanner, .github/skills/skill-scanner and .opencode/skills/skill-scanner in your project.

What does Skill Scanner need to run?

Going by SKILL.md and its folder, Skill Scanner needs Python for the scripts in its folder and the command-line tools its instructions call (python, pip and streamlit). Our summary lists: Python 3.

Does Skill Scanner access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Skill Scanner safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Skill Scanner use?

No licence was found for Skill Scanner or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Skill Scanner use?

About 364 tokens (SKILL.md is roughly 1.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Scanner?

Skills that share tags, products or a category with Skill Scanner: Slowmist Agent Security (slowmist/slowmist-agent-security, 508 stars), AI SAFE2 Secure Build Copilot (CyberStrategyInstitute/ai-safe2-framework, 146 stars), AI SAFE2 Secure Build Copilot (CyberStrategyInstitute/ai-safe2-framework, 146 stars) and MCP Server Security Audit (awarexone/Agentic-Bug-Hunter, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Scanner?

sundial-org (a GitHub organization) maintains it in sundial-org/awesome-openclaw-skills, which has 663 GitHub stars. The repository holds 353 skills in this directory. The repository was last updated on March 7, 2026.

Source: sundial-org/awesome-openclaw-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.