The Oathe Scan MCP is live. Give your agent the audit engine as a tool. Check any skill before you install it. npx oathe-mcp

oathe / runtime / scan · agent security is behavioral

Let us run your skill in a sandbox before you install it.

Oathe Scan is our audit engine, and it came first. Before agents could share a runtime, we had to measure what a skill does to one. Every skill is run in a sandbox and scored on what it did before it enters the runtime.

Why it matters

1,184+ malicious skills

shipped through one registry. Agents don't just run code — they take action with your credentials.

The leading scanner missed 91%

ClawMutiny: our behavioral audit of 1,620 OpenClaw skills. Read the research on the engineering blog →

2,986 public reports

Every skill in the registry was run, not read. Each report is dated and re-runnable. Browse the registry →

OpenClaw Benchmark

Loading audit results...

Browse every audit without searching: the full report registrymalicious · dangerous · caution · safe

Trust badge for your README · CI/CD gate · Free 200/mo · Premium $30/mo · Enterprise · Install the runtime →