Overview
- Skill Key
- adamthompson33/moltcops
- Author
- adamthompson33
- Source Repo
- openclaw/skills
- Version
- 1.0.0
- Source Path
- skills/adamthompson33/moltcops
- Latest Commit SHA
- 385cc2159d2af8a6fe2130f1ae481b477fa141ee
Pre-install security scanner for AI agent skills. Detects malicious patterns before you trust code. Local-first — code never leaves your machine.
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
直接复制以下提示词,发送给你的 AI 助手即可完成安装。
请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 moltcops 技能。 若已安装,则直接安装 moltcops 技能。
# MoltCops — Skill Security Scanner Scan any skill for security threats **before** you install it. Detects prompt injection, data exfiltration, sleeper triggers, drain patterns, and 16 more threat categories. **Local-first.** Your code never leaves your machine. No API calls. No uploads. No accounts. ## When to Use - **Before installing any skill** from ClawHub, GitHub, or other sources - **Before running** skills shared by other agents - **When evaluating** unknown code from any source - **After ClawHavoc**: 341 malicious skills were found on ClawHub this week. Scan first. ## How to Run ```bash python3 scripts/scan.py <path-to-skill-folder> ``` Example: ```bash # Scan a skill before installing python3 scripts/scan.py ~/.openclaw/skills/suspicious-skill # Scan a freshly downloaded skill python3 scripts/scan.py ./my-new-skill ``` **No dependencies required** — uses only Python 3 standard library. ## Reading Results The scanner returns three verdicts: | Verdict | Exit Code | Meaning | |---------|-----------|---------| | **PASS** | 0 | No critical or high-risk threats detected. Safe to install. | | **WARN** | 1 | High-risk patterns found. Review findings before installing. | | **BLOCK** | 2 | Critical threats detected. Do NOT install this skill. | ## What It Detects 20 detection rules across these threat categories: | Category | Rules | Examples | |----------|-------|---------| | **Prompt Injection** | MC-001, MC-002, MC-003 | System prompt override, jailbreak payloads, tool-use steering | | **Code Injection** | MC-004, MC-005, MC-006, MC-019 | Shell injection, eval/exec, base64-to-exec, child_process | | **Data Exfiltration** | MC-007, MC-008, MC-009, MC-010, MC-020 | Webhook URLs, env var harvesting, SSH key access, credential files | | **Hardcoded Secrets** | MC-011, MC-012 | API keys in source, private key material | | **Financial** | MC-013 | Drain patterns, unlimited withdrawals | | **Lateral Movement** | MC-014 | Git credential access, repo manipu...
heyixuan2
Bambu Lab 3D printer control and automation. Activate when user mentions: printer status, 3D printing, slice, analyze model, generate 3D, AMS filament, print monitor, Bambu Lab, or any 3D printing task. Full pipeline: search → generate → analyze → colorize → preview → open BS → user slice → print → monitor. Supports all 9 Bambu Lab printers (A1 Mini, A1, P1S, P2S, X1C, X1E, H2C, H2S, H2D).
human-pages-ai
Search and hire real humans for tasks — photography, delivery, research, and more
zseven-w
Reusable skill templates for OpenClaw AI agents. Templates for API integration, data processing, web scraping, CLI tools, and file processing.
capt-marbles
Generative Engine Optimization (GEO) for AI search visibility. Optimize content to appear in ChatGPT, Perplexity, Claude, and Google AI Overviews. Use when optimizing websites, pages, or content for LLM discoverability and citation.
cchacons
The job marketplace where bots hire bots. Post FREE or paid $WAGE jobs, with on-chain escrow, faucet rewards, referrals, judge staking, task inbox, smart matching, checkpoints, oversight, webhooks, onboarding, and human owner dashboard.
cchacons
The job marketplace where bots hire bots. Post FREE or paid $WAGE jobs, with on-chain escrow, faucet rewards, referrals, judge staking, task inbox, smart matching, checkpoints, oversight, webhooks, onboarding, and human owner dashboard.