skill-cleaner
Automatically verify "suspicious" skills via VirusTotal and add them to the security allowlist via the Bridge.
Install via CLI (Recommended)
clawhub install openclaw/skills/skills/jacobthejacobs/skill-cleanerSkill Cleaner
Scans your installed skills for suspicious patterns, verifies them against VirusTotal, and "fixes" false positives by adding them to the safety allowlist.
Usage
Run the cleaner to automatically verify and allowlist suspicious skills:
# Dry run (safe, just shows what would happen)
npx tsx ./skills/skill-cleaner/scripts/clean.ts
# Commit trust to safety allowlist for clean files
npx tsx ./skills/skill-cleaner/scripts/clean.ts --commit
# Full Security Fix: Trust clean files AND quarantine malicious ones
npx tsx ./skills/skill-cleaner/scripts/clean.ts --fix
Features
- Heuristic Scanning: Uses OpenClaw Core scanner to find suspicious code patterns.
- VirusTotal Integration: Cross-references hashes with VT for reputation.
- Trust Bridge: Automatically allowlists "false positives" via the Gateway.
- Quarantine: Moves malicious files (detects > 0 on VT) to a
.quarantine/folder for safety.
Security Disclosure
This skill requires high-privilege access to function as a security utility:
- Safe Bridge: Uses a hardened, non-shell Bridge (Gateway RPC) to verify and trust skills. This avoids direct file system mutation for the allowlist.
- Privacy: Only loads the
VIRUSTOTAL_API_KEYfrom your.envfile; it does not access or expose unrelated secrets. - Verification: Performs a Live Scan of your
skills/directory using the internal OpenClaw security module to compute hashes.
Audit Guidance: If you see "High Privilege" flags on the Hub, this is expected behavior for a tool that interacts with the Security Core. Always run in dry-run mode first to inspect planned changes.
Metadata
Not sure this is the right skill?
Describe what you want to build — we'll match you to the best skill from 16,000+ options.
Find the right skillPaste this into your clawhub.json to enable this plugin.
{
"plugins": {
"official-jacobthejacobs-skill-cleaner": {
"enabled": true,
"auto_update": true
}
}
}Tags
Related Skills
doctorbot-ci-validator
Stop failing in production. Validate your GitHub Actions, GitLab CI & Keep workflows offline with surgical precision. Born from Keep bounty research, perfected for agents.
arc-shield
Output sanitization for agent responses - prevents accidental secret leaks
AURA Security Scanner
Scan AI agent skills for malware, credential theft, prompt injection, and dangerous permissions before installing them
sbom-explainer
把依赖清单或 SBOM 翻译成非技术可读的风险说明,按影响面排序。;use for sbom, dependencies, risk workflows;do not use for 伪造 CVE 状态, 替代专业漏洞扫描.
securityvitals
Security vitals checker for OpenClaw. Scans your installation, scores your setup, and shows you exactly what to fix. First scan in seconds.