ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      john-niu-07

      Safety Report

      OpenClaw Safety Guard

      @john-niu-07

      Security guard skill for OpenClaw - Analyzes user input for harmful content, risky commands, and security threats before invoking LLM

      264Downloads
      0Installs
      0Stars
      2Versions
      Security & Compliance3,689AI & Machine Learning3,159Legal & Compliance1,710

      Security Analysis

      medium confidence
      Suspicious0.04 risk

      The skill's description (a CLI/tool that scans input) doesn't match the package contents and metadata: there is no code/binary, install spec is inconsistent, and meta files conflict — this mismatch is unexplained and warrants caution.

      Mar 15, 20262 files4 concerns
      Purpose & Capabilityconcern

      The SKILL.md describes a CLI tool (examples like `safety-guard ...`) and references Python + PyYAML installation, but the published package contains no code files or executable. The registry metadata lists python3 as a required binary but provides no actual binary or script. This incoherence (a claimed tool with no implementation) is unexpected and unexplained.

      Instruction Scopenote

      Instructions describe reading URLs and local files (e.g., /path/to/file.pdf) and a config path (~/.safety-guard/config.json), which is reasonable for a content-scanning tool, but the SKILL.md is high-level and presumes a runtime component that isn't present. It also mentions optional services (FIRECRAWL, APIFY) and many model API keys — these would enable network access and third-party services if implemented, but the actual behavior is unknown because no code is included.

      Install Mechanismconcern

      Registry shows 'no install spec', yet SKILL.md metadata contains an install hint (pip install PyYAML). That discrepancy means there is no verified, repeatable installation path included with the published skill. Lack of a proper install manifest for a tool that claims to be a CLI is a red flag.

      Credentialsconcern

      The registry lists no required environment variables, but SKILL.md instructs users to set multiple provider API keys (OPENAI_API_KEY, ANTHROPIC_API_KEY, XAI, GEMINI_API_KEY and optional FIRECRAWL/APIFY tokens). Requiring numerous unrelated provider keys is plausible for a multi-model guard, but the package does not declare or justify those env requirements, increasing the risk of unexpected credential use if an implementation is obtained elsewhere.

      Persistence & Privilegeok

      The skill does not request 'always: true' and is user-invocable only. It does reference an optional config file under the user's home directory, which is normal for CLI tools. There is no evidence here of the skill attempting to modify other skills or request persistent elevated privileges.

      Guidance

      Do not install or run this skill as-is. The package contains only documentation and conflicting metadata: there is no CLI binary or source code even though the README shows CLI usage and a pip install hint. Steps to take before trusting this skill: 1) Ask the publisher for the actual source code or executable and a reproducible install manifest (e.g., pip package or GitHub release). 2) Verify the repository and owner identity (the included _meta.json has mismatched owner/slug/version info). 3) If you obtain code, review it for any network calls or credential exfiltration (it references many model API keys and optional third-party tokens). 4) Prefer skills that include code or a vetted install mechanism from a trusted source. If you must test, do so in an isolated environment and avoid supplying real API keys or sensitive files until you confirm the implementation.

      Latest Release

      v1.0.1

      Updated description and metadata

      More by @john-niu-07

      karpathy-llm-wiki

      @john-ver · 6 stars

      Test Safety

      1 stars

      OpenClaw Safety Guard

      1 stars

      OpenClaw Safety Guard

      0 stars

      see-video

      @john-ver · 0 stars

      下载电影/电视剧/综艺的剧照/海报

      @zj-john · 0 stars

      Published by @john-niu-07 on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]