OpenClaw agents have full system access. One malicious skill could steal your data or API keys. SClawHub scans every skill for security issues and gives you a trust score (0-100) before you install. Free, transparent, open methodology.
Hey Product Hunt! 👋
I'm Mladjan, and I built SClawHub over a weekend to solve a real problem in the OpenClaw community.
🔍 **The Problem:**
OpenClaw skills have full access to your system, files, APIs, and credentials. But there's no easy way to know if they're safe before installing them.
🛡️ **The Solution:**
SClawHub automatically scans every skill for:
• Data exfiltration attempts
• Credential theft
• Unsafe file operations
• Code execution risks
• Obfuscation attempts
Each skill gets a trust score (0-100) with a detailed vulnerability report.
✨ **What's Cool:**
• Chrome extension shows trust badges directly on ClawHub
• Same URL schema: clawhub.ai → sclawhub.com (just add 's' and change to .com)
• Built in 4 hours for $10 (domain cost only)
• Already scanned 28+ skills
🚀 **Stack:**
Node.js scanner + Next.js + Semgrep + Claude AI + Vercel
Try it: https://sclawhub.com
Extension: [pending Chrome Web Store approval]
Questions? Feedback? I'm here all day! 🦞
P.S. If you're building AI agents or using OpenClaw, I'd love your thoughts on what security features would be most valuable.
This is incredibly important. Security in the OpenClaw ecosystem is still way too overlooked. I've been deep in the security side of agent systems since day one and the skill layer is one of the biggest attack surfaces. A trust score before install is such a smart approach. Are you scanning for prompt injection vectors in skills too?
Report
This is super needed — agent skills having full system access without a safety signal is scary. A simple trust score + clear report makes “install or skip” decisions way easier for builders.
Stellup maps
ClawSecure
This is incredibly important. Security in the OpenClaw ecosystem is still way too overlooked. I've been deep in the security side of agent systems since day one and the skill layer is one of the biggest attack surfaces. A trust score before install is such a smart approach. Are you scanning for prompt injection vectors in skills too?
This is super needed — agent skills having full system access without a safety signal is scary. A simple trust score + clear report makes “install or skip” decisions way easier for builders.