13 questions

Answers

Short, sourced answers to the questions people ask before they trust an OpenClaw skill. Each page starts with a direct answer, then the detail, the limits, and the sources. Longer guides are on the blog.

Skill safety

  • Not automatically. Most ClawHub skills are ordinary, but researchers found hundreds of malicious ones in 2026, and some passed the marketplace's VirusTotal scan. Treat every skill as code that runs with your agent's access: check the listing, read the setup section and links, scan it, and give it only the access it needs.

    Read the answer
  • A malicious ClawHub skill is an OpenClaw skill written to harm the person who installs it. Its SKILL.md instructions get the agent, or you, to run a hidden installer, send credentials or files to an attacker, weaken the agent's safeguards, or move money. Most reported cases hid malware behind a fake setup step.

    Read the answer
  • Prompt injection in an agent skill is text in the skill's files that tries to take control of the agent: telling it to ignore earlier rules, hide actions from you, turn off confirmations, or edit its own instruction files. It works because the agent cannot reliably tell trusted instructions from text supplied by the skill's author.

    Read the answer
  • OpenClaw skill supply-chain risk is the risk you take on by running instructions written by someone else. A third-party skill, a later update to it, or a website or file it depends on can turn harmful, and it acts with your agent's access to files, accounts and keys. It is the agent version of a malicious package.

    Read the answer
  • Yes. Since 7 February 2026, every skill published to ClawHub is scanned with VirusTotal, including Code Insight, an LLM review of SKILL.md and the files it references. Benign skills are approved, suspicious ones get a warning, malicious ones are blocked from download, and active skills are re-scanned daily. OpenClaw calls it helpful but not a silver bullet.

    Read the answer

Checking a skill

  • Run npx ironheights scan with the path to the skill folder, or paste its SKILL.md into the free browser scanner on this site. Both read the files as text, never run them, and report each risky pattern with a rule id, line and evidence. Then read every finding: no findings means no rule matched, not that the skill is safe.

    Read the answer
  • Confirm you are on the skill's real ClawHub listing and the name and publisher are what you expect, read its VirusTotal status, then read the raw SKILL.md setup section, commands and links yourself. Scan the downloaded folder with a local scanner, install only if everything fits the skill's job, and record a baseline right after.

    Read the answer
  • Record a baseline right after you install and review the skill: npx ironheights baseline create stores a hash, size and mode for every watched file. Later, npx ironheights verify compares the current files with that record and lists every file that was added, modified, removed or had its permissions changed, with a rule id for each.

    Read the answer

Using Ironheights

  • You need Node.js 20 or newer. Run npx ironheights scan with the path to a skill to use it without installing, or install the command globally with npm install -g ironheights; ih is a shorter alias for the same command. Get it only from the ironheights package on npm, the project's GitHub releases, or this site.

    Read the answer
  • Yes. The Ironheights command-line scanner, its detection rules, the benchmark harness and the advisory OpenClaw skill are free and open source under the Apache-2.0 license, with the source on GitHub. Paid Pro, Team, Threat Intel API and Enterprise tiers are planned, but their prices are hypotheses and nothing paid is on sale yet.

    Read the answer
  • The CLI has no telemetry, and a scan makes no network call. Only commands you run on purpose use the network, such as fetch or the optional model review. The in-browser scanner never sends your skill's content anywhere. The website uses Google Analytics only after you accept it, and then records only the scan verdict.

    Read the answer
  • Yes. Ironheights reads files and never runs another tool, and its guard stays in monitor mode unless you change it, so it can sit beside other scanners. Run ironheights coexist to list the other security tools it can see and where they overlap, with a fix for each. The check is heuristic, and a clean report is not proof.

    Read the answer
  • Ironheights only sees patterns its rules describe in the files it reads. It misses payloads hosted on a linked website or paste site, files over 1 MiB by default, behavior that appears only at runtime, instructions to move money, novel or heavily obfuscated attacks, and tampering by someone who can rewrite its baseline. No findings is not proof of safety.

    Read the answer

Check the next skill before your agent reads it

Ironheights is a free, open-source, local-first scanner and integrity monitor for OpenClaw skills. It reports what its rules match; it cannot prove a skill is safe.