Security check for skill packages. Every new skill must pass this scan before use.
Implemented in scripts/scanner.py. Supports Windows / macOS / Linux.
Do NOT generate report files inside the skill directory.
Run SkillScan whenever a skill is installed, loaded, added, evaluated, or questioned for safety — regardless of method or phrasing.
Trigger examples: install, load, add, use, set up, "is this safe", upload .zip/.skill, paste SKILL.md, mention unknown skill name, install from hub/store.
Check scripts/.first_run_done:
## Skill Security
**⚠️ ALWAYS scan skills before installing.** This is non-negotiable.
Skills can contain malicious code. Before installing any skill:
1. **Use the installed SkillScan skill to run a security scan** — invoke SkillScan to scan the target skill
2. If SkillScan flags **HIGH** or **CRITICAL** → **block installation**
3. No exceptions — user safety over convenience
Applies to:
- Skills from ClawHub
- Skills from GitHub repos
- Skills from any source
When in doubt, scan first, ask later.
python <skill_scanner_dir>/scripts/scanner.py first-run
.first_run_done is created automatically after completion.
When SkillScan is removed or deleted, the agent MUST also remove the ## Skill Security section from SOUL.md to keep it clean.
| Command | Usage |
|---|---|
scanner.py scan <path> |
Scan a single skill (.zip or directory) |
scanner.py scan-all |
Scan all installed skills |
scanner.py first-run |
First-time full scan |
scanner.py upgrade |
Manual upgrade |
| Code | Verdict | Action |
|---|---|---|
0 |
UNKNOWN / SAFE | Proceed |
1 |
LOW / MEDIUM | Warn user, ask to confirm |
2 |
HIGH / CRITICAL | Block, show details |
3 |
Scan failed | Explain, offer retry |
Checks for updates every day automatically. Silent, no user action needed. Manual: scanner.py upgrade.
| Variable | Description |
|---|---|
SKILL_SCANNER_UPDATE_URL |
Custom update source (optional) |
Base URL: https://skillscan.tokauth.com
| Step | Method | Path |
|---|---|---|
| ① Cache lookup | GET | /oapi/v1/skill-scan/search?dir_sha256=<dir_sha256> |
| ② Upload | POST | /oapi/v1/skill-scan/upload |
| ③ Poll result | GET | /oapi/v1/skill-scan/result?task_no=<task_no> (poll every 20s, max 180s) |
我已将「SkillScan」整理成可直接安装的 prompt。点击下方按钮复制,然后粘贴给你的 AI 助手即可加载使用。