Skill scanner
Check an OpenClaw skill before you install it. Paste a SKILL.md or drop the skill folder, and get the same verdict, rule ids, and evidence as the command-line scanner. It is a signal to read alongside the skill, not a guarantee.
Scan results
Questions about the browser scanner
No. The Ironheights rule engine is compiled into this page and runs in your browser tab. The scanner never sends your skill's content anywhere: the page has no upload endpoint and makes no network request with your input. With your consent, the site records only the scan verdict (no content). To check, open your browser's developer tools on the Network tab while you scan, or load the page, go offline, and scan.
Yes for content rules. The page uses the rule code from ironheights 0.1.5 unchanged, and a test runs the same fixtures through both and requires identical rule ids, lines, evidence, scores, and verdicts. The CLI adds integrity checks against a local baseline, your config file, and folder scans of installed skills.
Each finding adds points by severity: critical 100, high 40, medium 15, low 5. Block means a critical finding or a score of 80 or more. Review means a high or medium finding, or a score of 15 or more. No findings means no rule matched, which is not proof that a skill is safe.
The pasted text is compressed into the part of the link after the # sign. Browsers do not send that part to the server, so the skill travels inside the link itself. Anyone with the link can read the skill, so do not share links for private skills.