Rule of Claw

Security

Every submission is automatically scanned before publishing.

Scanning pipeline

01

Pattern matching

Scan for known prompt injection phrases, credential exfiltration patterns, hidden unicode characters, and obfuscated code.

02

URL analysis

Flag direct IP addresses, URL shorteners, suspicious top-level domains, and unusual port numbers.

03

Trust-based routing

Low risk + verified author = auto-approve. Medium risk = manual review. High risk = quarantine.

04

MCP-Scan

For skills and MCP servers, we run Invariant Labs' mcp-scan to detect tool poisoning, toxic flows, and malware payloads hidden in natural language.

05

VirusTotal URL scanning

Repository and documentation URLs are checked against 70+ security engines via VirusTotal for malware, phishing, and malicious content.

What we detect

Prompt injection attempts
Credential exfiltration patterns
Hidden unicode characters
Base64-encoded payloads
Suspicious URLs and domains
Obfuscated code patterns
Zero-width character injection
Homoglyph/Cyrillic attacks
Tool poisoning (via mcp-scan)
Toxic flow detection (via mcp-scan)
Rug pull patterns (via mcp-scan)
Code injection patterns
URL reputation via VirusTotal
Malware/phishing URL detection

MCP-Scan integration

For skills and MCP server submissions, we integrate with Invariant Labs' mcp-scan - an open-source security scanner specifically designed for the Model Context Protocol.

Tool poisoning detection

Identifies malicious tool descriptions that attempt to manipulate agent behavior.

Toxic flow analysis

Detects dangerous data flows between tools that could exfiltrate sensitive information.

Rug pull prevention

Scans for patterns that could change server behavior after initial approval.

Natural language payloads

Finds malware instructions hidden in seemingly innocent documentation.

Trust tiers

🆕
New

Account created. Full review on all submissions.

Member

3+ approved submissions, 30+ day account. Faster review.

Verified

Manual verification + GitHub history. Can submit skills.

🏛️
Official

OpenClaw team or endorsed projects. Instant publish.

Report something

Found something suspicious? Every listing has a Report button. 3+ reports trigger automatic quarantine and manual review.

Read the security policy →