Answers
Short, sourced answers to the questions people ask before they trust an OpenClaw skill. Each page starts with a direct answer, then the detail, the limits, and the sources. Longer guides are on the blog.
Skill safety
Not automatically. Most ClawHub skills are ordinary, but researchers found hundreds of malicious ones in 2026, and some passed the marketplace's VirusTotal scan. Treat every skill as code that runs with your agent's access: check the listing, read the setup section and links, scan it, and give it only the access it needs.
Read the answerA malicious ClawHub skill is an OpenClaw skill written to harm the person who installs it. Its SKILL.md instructions get the agent, or you, to run a hidden installer, send credentials or files to an attacker, weaken the agent's safeguards, or move money. Most reported cases hid malware behind a fake setup step.
Read the answerPrompt injection in an agent skill is text in the skill's files that tries to take control of the agent: telling it to ignore earlier rules, hide actions from you, turn off confirmations, or edit its own instruction files. It works because the agent cannot reliably tell trusted instructions from text supplied by the skill's author.
Read the answerOpenClaw skill supply-chain risk is the risk you take on by running instructions written by someone else. A third-party skill, a later update to it, or a website or file it depends on can turn harmful, and it acts with your agent's access to files, accounts and keys. It is the agent version of a malicious package.
Read the answerYes. Since 7 February 2026, every skill published to ClawHub is scanned with VirusTotal, including Code Insight, an LLM review of SKILL.md and the files it references. Benign skills are approved, suspicious ones get a warning, malicious ones are blocked from download, and active skills are re-scanned daily. OpenClaw calls it helpful but not a silver bullet.
Read the answer
Checking a skill
Run npx ironheights scan with the path to the skill folder, or paste its SKILL.md into the free browser scanner on this site. Both read the files as text, never run them, and report each risky pattern with a rule id, line and evidence. Then read every finding: no findings means no rule matched, not that the skill is safe.
Read the answerConfirm you are on the skill's real ClawHub listing and the name and publisher are what you expect, read its VirusTotal status, then read the raw SKILL.md setup section, commands and links yourself. Scan the downloaded folder with a local scanner, install only if everything fits the skill's job, and record a baseline right after.
Read the answerRecord a baseline right after you install and review the skill: npx ironheights baseline create stores a hash, size and mode for every watched file. Later, npx ironheights verify compares the current files with that record and lists every file that was added, modified, removed or had its permissions changed, with a rule id for each.
Read the answer
Using Ironheights
You need Node.js 20 or newer. Run npx ironheights scan with the path to a skill to use it without installing, or install the command globally with npm install -g ironheights; ih is a shorter alias for the same command. Get it only from the ironheights package on npm, the project's GitHub releases, or this site.
Read the answerYes. The Ironheights command-line scanner, its detection rules, the benchmark harness and the advisory OpenClaw skill are free and open source under the Apache-2.0 license, with the source on GitHub. Paid Pro, Team, Threat Intel API and Enterprise tiers are planned, but their prices are hypotheses and nothing paid is on sale yet.
Read the answerThe CLI has no telemetry, and a scan makes no network call. Only commands you run on purpose use the network, such as fetch or the optional model review. The in-browser scanner never sends your skill's content anywhere. The website uses Google Analytics only after you accept it, and then records only the scan verdict.
Read the answerYes. Ironheights reads files and never runs another tool, and its guard stays in monitor mode unless you change it, so it can sit beside other scanners. Run ironheights coexist to list the other security tools it can see and where they overlap, with a fix for each. The check is heuristic, and a clean report is not proof.
Read the answerIronheights only sees patterns its rules describe in the files it reads. It misses payloads hosted on a linked website or paste site, files over 1 MiB by default, behavior that appears only at runtime, instructions to move money, novel or heavily obfuscated attacks, and tampering by someone who can rewrite its baseline. No findings is not proof of safety.
Read the answer
Check the next skill before your agent reads it
Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.