Skill Audit — Pre-Install Security Scanner
Don't install blind. Audit before you trust.
Why This Exists
Research findings (2026):
- 7.5% of 14,706 OpenClaw skills are confirmed malicious (RankClaw)
- 22-26% contain vulnerabilities (multiple studies)
- 59 critical-risk skills found: base64-obfuscated droppers disguised as Google/LinkedIn tools
- Cisco, CrowdStrike, NCC Group all published findings on skill supply chain attacks
One malicious skill install = leaked API keys
[Description truncada. Veja o README completo no GitHub.]