Scans OpenClaw skill directories for malware, prompt injection, data exfiltration, and other security threats.
v2 improvements:
▶️Context-aware analysis: distinguishes "uses .env" vs "steals .env"
▶️Well-known application ports whitelisted (Radarr, Sonarr, Plex, etc.)
▶️Self-scan exclusion (scanner ignores its own detection patterns)
▶️Smarter risk scoring: only counts real threats, not documentation
▶️False positive tags: findings can be marked as likely FP with explanation
▶️VT threshold: 1 detection on 90+ engines = not CRITICAL
Usage:
python3 scan_skill.py <skill_path>
python3 scan_skill.py --batch <path1> <path2> ...
python3 scan_skill.py --json <skill_path>
python3 scan_skill.py --vt <skill_path>
python3 scan_skill.py --vt --vt-key <api_key> <skill_path>
python3 scan_skill.py --vt --no-upload <skill_path>