Skip to content
Home

ClawDefend

Security scanner for OpenClaw skills that detects malicious code, data exfiltration, and prompt injection before publishing

The product is a security scanner for OpenClaw skills that identifies malicious code, data exfiltration, prompt injection, and other vulnerabilities before publication to ClawHub. It is for developers and development teams that build and ship OpenClaw skills, including B2B teams managing skill distribution. It is delivered as a SaaS with a free tier that scans GitHub or ClawHub URLs and gates deployments through REST API and CI/CD webhooks.

Key features

  • Scan OpenClaw skills for malicious code
  • Detect data exfiltration via env variables
  • Detect prompt injection
  • Shell command injection detection
  • Hardcoded credentials detection
  • Arbitrary file access detection
  • AST parsing and regex pattern matching
  • LLM-powered intent detection
  • Line-by-line reports with severity and remediation
  • Malware signatures database
  • Risk score per scan
  • GitHub and ClawHub URL scanning
  • REST API and webhooks
  • CI/CD integration to gate deployments
  • Verified skill badges for README
Social posts
  • No social media activity detected
GTM channels
  • Blog
  • Community
  • API
ICP
  • Software developers
  • Engineering teams
  • Security teams