Last checked

Compare

How Ironheights fits next to the other ways people check OpenClaw skills. Written from public documentation, with sources, and with the places where other tools are stronger stated plainly.

Quick answerLast updated

How does Ironheights compare with VirusTotal and Cisco skill-scanner?

VirusTotal checks ClawHub skills when they are published. Cisco skill-scanner is an open-source static scanner with an optional LLM judge and published accuracy. Ironheights is rules-only and runs on your machine: it scans the copy you install and reports later changes against a baseline. They cover different moments, so using more than one is reasonable.

Marketplace scanning on ClawHub
Checks every ClawHub skill at publish time with an LLM review and antivirus engines. Ironheights checks your installed copy and watches it for changes. Use both.
Read the comparison
Open-source static scanner with an LLM judge
More capable with its judge, and it publishes held-out accuracy. Ironheights is rules-only, OpenClaw-specific, and adds baselines and verify.
Read the comparison

The landscape

Ways to check OpenClaw skills
OptionWhy people use itWhere it falls short
Marketplace scanning (VirusTotal on ClawHub)Automatic and free for every published skill, with an LLM review of intent.Runs when a skill is published, not on the copy you install from elsewhere. Its maintainers call it one layer, not a silver bullet.
Open-source static scanners (for example Cisco skill-scanner)Credible, free, and auditable. Some add an LLM judge and publish measured accuracy.General-purpose for agent skills rather than built around OpenClaw installs and agent files.
Scanner skills that run inside the agentOne-click and free.A hostile skill can try to talk the agent out of them. Our own advisory skill has the same limit, which is why the CLI is the trusted path.
Enterprise AI security platformsBroad coverage, support, and governance features.Built and priced for large organizations. We have not evaluated specific products, so we make no claims about them.
Reading every skill by handNo cost, and a careful reader catches intent that rules miss.Slow, and one missed line can be expensive. Our checklist makes it faster and repeatable.

Where Ironheights fits

Ironheights runs outside the agent, on your machine, before and after install. It reads skill files with published rules and reports changes to installed skills and agent files against a baseline. It does not read intent with a model, does not watch runtime behavior, and has no real-world detection rate yet. See the benchmark and the limitations.

How we write comparisons

  • Every claim about another tool links to public documentation, and each page shows the date we last checked it.
  • We say where the other tool is stronger.
  • Numbers from our benchmark carry its limits: a tiny, synthetic, self-written corpus.
  • Spotted an error or something out of date? Open an issue on GitHub and we will correct it.