Skip to content

OpenClaw Skill Trust Scanner

Scan SKILL.md instructions for destructive command patterns, missing safety boundaries, and trust posture

OpenClaw Skill Trust Scanner

{
  "score": 40,
  "findings": [
    {
      "severity": "high",
      "rule": "shell-pipe-exec",
      "match": "curl https://example.com/install.sh | bash"
    },
    {
      "severity": "medium",
      "rule": "unbounded-sudo",
      "match": "sudo"
    },
    {
      "severity": "medium",
      "rule": "always-execute",
      "match": "always execute"
    }
  ],
  "summary": {
    "high": 1,
    "medium": 2,
    "low": 0
  },
  "recommendation": "block-until-fixed"
}

Updated . Provided as is. Check the output before you rely on it in production.

How to use OpenClaw Skill Trust Scanner

  1. 1

    Paste SKILL.md content

    Paste your full skill instructions, including tool usage guidance and safety boundaries, into the scanner input.

  2. 2

    Run trust scan

    Click Scan Skill Trust to evaluate the text against destructive command patterns and missing-guardrail heuristics.

  3. 3

    Review score and findings

    Inspect trust score, recommendation tier, and rule-level findings to understand which sections require hardening.

  4. 4

    Patch skill and validate again

    Apply safety edits to the source skill file and rerun the scan until recommendation reaches your target readiness level.

Questions and answers

What is OpenClaw Skill Trust Scanner?
An OpenClaw skill is a SKILL.md file of instructions an agent follows, so a careless line can trigger destructive commands. This scanner matches the text against risk rules such as rm -rf, curl piped to a shell and sudo, checks for a safety or approval section, and scores trust from 0 to 100.
What rules are checked?
Five patterns are checked: recursive force deletes (rm -rf), curl piped into sh or bash, sudo, 'always execute' wording and 'any network request' wording. The skill is also flagged when it never mentions safety, guardrails or approval.
What does the trust score represent?
The score summarizes rule outcomes on a 0-100 scale. Higher values indicate stronger safety posture, while low scores signal skills that should be reviewed before use.
Does OpenClaw Skill Trust Scanner store or send my data?
No. Skill text is processed locally in your browser with no server upload.
For AI agents: how to call this tool

Machine-readable contract, endpoints and examples. Humans can ignore this section.

Best Path For Builders

Browser workflow

Runs instantly in the browser with private local processing and copy/export-ready output.

Browser Workflow

This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.

/openclaw-skill-trust-scanner/

For automation planning, fetch the canonical contract at /api/tool/openclaw-skill-trust-scanner.json.