clawscan-cli
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation for a security tool (ClawScan) and includes explicit warnings against insecure practices, such as passing API keys as CLI flags.
- [SAFE]: External dependencies (e.g.,
skillspector,aig,socket) are clearly identified as part of the tool's intended security auditing purpose. The skill uses standard package managers (pip,uv,npm) for installation. - [SAFE]: The skill emphasizes the use of a Docker-based sandbox (
ghcr.io/openclaw/clawscan-runtime:latest) for running command-backed scanners and judges, reducing the risk of host compromise during scans. - [SAFE]: Environment variable configurations for various scanners (e.g.,
LLM_API_KEY,SNYK_TOKEN) are standard for security tools and do not involve hardcoded credentials.
Audit Metadata