Skill safety checklist
Sixteen checks, an eight-question risk quiz, and a summary you can hand to a client. Do it by hand in about 10 minutes, then let npx ironheights scan ./path/to/skill read the files for you.
0 of 16 checks done.
01The 10-minute checklist
02Risk quiz
8 questions · answers stay in this browser03Client-ready summary
Hand your client a record of what was checked, not a promise. Print it, save it as PDF from the print dialog, copy it as Markdown, or download a file. It is built in your browser.
Why check by hand at all
An OpenClaw skill is a Markdown file your agent treats as instructions, often with access to your shell, files, and accounts. Public research on malicious ClawHub skills keeps finding the same few moves: a fake “prerequisite” that downloads and runs code, remote content piped into a shell, credential reads, instruction overrides, hidden text, and persistence. Each check above targets one of them.
Scanners help, including ours, but none sees everything. See what a static scanner cannot catch, how the rules did on our first benchmark, and how tools compare.
Questions
About 10 minutes for a typical skill: 2 minutes on where it comes from, 4 reading the SKILL.md, 2 on what it can reach, and 2 to scan it and write down the decision. Skills with scripts or bundled files take longer.
Not necessarily. The checklist and the scanner catch common, documented patterns. Novel, heavily obfuscated, or runtime-only attacks can still get through, so give new skills the least access they need.
No. Your checks, quiz answers, and summary details are stored only in this browser's local storage. The page makes no network calls with them, and Reset clears them.
Yes. Fill in the skill and client names, then print it, save it as a PDF from the print dialog, copy it as Markdown, or download a .md file. It records what was checked and says plainly that it is not a guarantee.