Checking a skillUpdated

How do I verify a skill from ClawHub?

Short answer

Confirm you are on the skill's real ClawHub listing and the name and publisher are what you expect, read its VirusTotal status, then read the raw SKILL.md setup section, commands and links yourself. Scan the downloaded folder with a local scanner, install only if everything fits the skill's job, and record a baseline right after.

1. Confirm the listing and the publisher

Open the skill from ClawHub itself or from the publisher's own repository, not from a link someone sent you. Several campaigns used lookalike websites and names that imitate official OpenClaw and ClawHub tools, so compare the name letter by letter. Be wary of a brand-new publisher account, or one that publishes dozens of near-identical skills: Bitdefender tied 199 skills to a single publisher, and VirusTotal tied 314 to one user.

2. Read the marketplace scan status

ClawHub scans every published skill with VirusTotal and shows the result on the skill page. A warning means stop until you understand exactly what was flagged. A clean result is useful but not proof: skills whose payload lived on an outside website have passed. See does VirusTotal scan ClawHub skills.

3. Read the raw SKILL.md

Read the raw file, not the rendered page, starting with the setup section. Stop if you see:

  • a "prerequisite" that downloads and runs a script, binary or archive;
  • an encoded command, or remote content piped into a shell;
  • links to paste sites, raw IP addresses, URL shorteners or password-protected archives;
  • instructions to ignore rules, hide steps from you, turn off confirmations, or edit agent files;
  • requests for credentials, wallets or hosts that the skill's job does not need.

4. Scan the files

The simplest route is npx ironheights fetch <owner>/<slug>, which downloads the skill into a staging folder outside your agent's skill directories, scans it without running anything, and installs nothing. You can also download it yourself and run npx ironheights scan ./path/to/skill, or paste the SKILL.md into the browser scanner. Read each finding; the rules reference explains what each rule means and how it misfires.

5. Install, then record a baseline

If everything fits, install the skill (npx ironheights safe-install <owner>/<slug> does this only when the scan has no findings) and run npx ironheights baseline create. Later, npx ironheights verify tells you whether the skill or your agent files changed. Note who approved the skill and why; the checklist tool exports that record.

Re-verify on every update

Verification is a point-in-time check. When the skill updates, the version you approved is gone, so repeat steps 3 and 4 on the new files before you accept the change. verify will tell you which files changed.

Limits

These steps catch the common patterns in public reports; they do not prove a skill is safe. Ironheights cannot see payloads hosted on linked sites, runtime behavior, or instructions that use no pattern its rules describe. Our malicious skill tracker shows which reported cases its rules cover, and the limitations page lists the rest.

Sources

All answers

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.