Security
How every submission is reviewed before publishing.
Scanning pipeline
Pattern matching
Scan for known prompt injection phrases, credential exfiltration patterns, hidden unicode characters, and obfuscated code.
URL verification
Check all embedded URLs against malware databases. Flag IP addresses, URL shorteners, and suspicious domains.
AI analysis
Claude reviews content intent, risk scoring, and identifies subtle injection attempts that pattern matching misses.
Trust-based routing
Low risk + verified author → auto-approve. Medium risk → manual review. High risk → quarantine.
What we detect
Trust tiers
Account created. Full review on all submissions.
3+ approved submissions, 30+ day account. Faster review.
Manual verification + GitHub history. Can submit skills.
OpenClaw team or endorsed projects. Instant publish.
Report something
Found something suspicious? Every listing has a Report button. 3+ reports trigger automatic quarantine and manual review.
Read the security policy →