Oathe Security Badge

Is sreejith77/skill-installer safe?

https://clawhub.ai/sreejith77/skill-installer

100
SAFE

The ClawHub Skill Manager appears to be a legitimate and safely implemented skill management tool for the OpenClaw ecosystem. It contains no malicious code, prompt injection attempts, or data exfiltration mechanisms, and follows security best practices by warning users about third-party skill risks.

Category Scores

Prompt Injection 100/100 · 30%
Data Exfiltration 100/100 · 25%
Code Execution 100/100 · 20%
Clone Behavior 100/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 90/100 · 5%

Findings (1)

LOW Package Manager Inherent Risk -10

This skill enables installation of third-party skills from ClawHub registry, which could potentially include malicious skills. However, the skill appropriately warns users to 'treat third-party skills as untrusted' and review before enabling.