skills/openclaw/clawscan/clawscan-cli/Gen Agent Trust Hub

clawscan-cli

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation for a security tool (ClawScan) and includes explicit warnings against insecure practices, such as passing API keys as CLI flags.
  • [SAFE]: External dependencies (e.g., skillspector, aig, socket) are clearly identified as part of the tool's intended security auditing purpose. The skill uses standard package managers (pip, uv, npm) for installation.
  • [SAFE]: The skill emphasizes the use of a Docker-based sandbox (ghcr.io/openclaw/clawscan-runtime:latest) for running command-backed scanners and judges, reducing the risk of host compromise during scans.
  • [SAFE]: Environment variable configurations for various scanners (e.g., LLM_API_KEY, SNYK_TOKEN) are standard for security tools and do not involve hardcoded credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:25 PM
Security Audit — agent-trust-hub — clawscan-cli