Free tool Stays in your browser

Skill safety checklist

Sixteen checks, an eight-question risk quiz, and a summary you can hand to a client. Do it by hand in about 10 minutes, then let npx ironheights scan ./path/to/skill read the files for you.

Quick answerLast updated

How do I vet an OpenClaw skill before installing it?

Take about 10 minutes. Work through 16 checks: where the skill comes from, what its SKILL.md asks the agent to do, and what it can reach. Run npx ironheights scan, then answer 8 risk questions for a rating. Everything stays in your browser. It lowers risk; it does not guarantee a skill is harmless.

0 of 16 checks done.

01The 10-minute checklist

Where it comes from
About 2 minutes · 0/4 done

ClawHub or the publisher's own repository, not a link from a chat, a forum post, or a look-alike site.

Compare it letter by letter with the skill you meant. Impostor “official CLI” skills and near-miss names are a documented trick.

A brand-new account, or one publishing dozens of near-identical skills, is a red flag.

ClawHub shows a VirusTotal result on each skill page. A warning means stop. A clean result is one data point, not proof of safety.

Read the SKILL.md
About 4 minutes · 0/5 done

Any setup step that downloads and runs a script, binary, or archive before the skill works is the most common malware pattern in public reports.

Look for curl or wget piped to bash, eval of fetched content, and base64 blobs that get decoded and run.

Check for paste sites, URL shorteners, raw IP addresses, and password-protected archives.

“Ignore previous instructions”, “do not tell the user”, or requests to turn off confirmations are a stop.

Open the raw file, not the rendered page. Look for zero-width characters, HTML comments, and long runs of padding.

What it can reach
About 2 minutes · 0/4 done

Reads of ~/.ssh, ~/.aws, .env files, browser profiles, or wallet files need a clear reason. Most skills need none.

Every host the skill talks to should be named and fit its purpose. Webhooks to unknown hosts are an exfiltration channel.

Watch for crontab edits, shell rc files, launch agents or services, sudo, and chmod 777.

No binaries or archives you cannot inspect. If you cannot read it, you cannot vet it.

Scan and record
About 2 minutes · 0/3 done

It reads files as data and runs nothing. No findings means no rule matched, not that the skill is safe.

npx ironheights scan ./path/to/skill

Then run verify later to see whether the skill or your agent files changed.

npx ironheights baseline create

A one-line note per skill is what a client or a teammate will ask for later.

02Risk quiz

8 questions · answers stay in this browser
1.Where did you get the skill?
2.Does it ask you or the agent to install or run anything first?
3.What can the agent reach while this skill runs?
4.Does the skill read credentials or secrets?
5.Which network hosts does it contact?
6.Did you find hidden text or instruction overrides?
7.What do you know about the publisher?
8.What did the Ironheights scan say?
Your result
Answer the questions to see a risk level
npx ironheights scan ./path/to/skill

A risk level is a prompt to look closer, not a verdict on the skill. The scanner reads files and runs nothing.

03Client-ready summary

Hand your client a record of what was checked, not a promise. Print it, save it as PDF from the print dialog, copy it as Markdown, or download a file. It is built in your browser.

Saved only in this browser's local storage.

Why check by hand at all

An OpenClaw skill is a Markdown file your agent treats as instructions, often with access to your shell, files, and accounts. Public research on malicious ClawHub skills keeps finding the same few moves: a fake “prerequisite” that downloads and runs code, remote content piped into a shell, credential reads, instruction overrides, hidden text, and persistence. Each check above targets one of them.

Scanners help, including ours, but none sees everything. See what a static scanner cannot catch, how the rules did on our first benchmark, and how tools compare.

Questions

About 10 minutes for a typical skill: 2 minutes on where it comes from, 4 reading the SKILL.md, 2 on what it can reach, and 2 to scan it and write down the decision. Skills with scripts or bundled files take longer.

Not necessarily. The checklist and the scanner catch common, documented patterns. Novel, heavily obfuscated, or runtime-only attacks can still get through, so give new skills the least access they need.

No. Your checks, quiz answers, and summary details are stored only in this browser's local storage. The page makes no network calls with them, and Reset clears them.

Yes. Fill in the skill and client names, then print it, save it as a PDF from the print dialog, copy it as Markdown, or download a .md file. It records what was checked and says plainly that it is not a guarantee.