giraffe-guard

Coding Agents & IDEs
v3.1.0
Benign

Scan OpenClaw skill directories for supply chain attacks and malicious code.

483 downloads483 installsby @lida408

Setup & Installation

Install command

clawhub install lida408/giraffe-guard

If the CLI is not installed:

Install command

npx clawhub@latest install lida408/giraffe-guard

Or install with OpenClaw CLI:

Install command

openclaw skills install lida408/giraffe-guard

or paste the repo link into your assistant's chat

Install command

https://github.com/openclaw/skills/tree/main/skills/lida408/giraffe-guard

What This Skill Does

Scans OpenClaw skill directories for supply chain attacks and malicious code using 22 detection rules. Context-aware analysis distinguishes documentation from executable code to reduce false positives. Outputs colored terminal results or JSON reports.

Zero external dependencies means it runs on any macOS or Linux system without setup, unlike scanners that require language runtimes or package installs.

When to Use It

  • Auditing a new third-party skill before installing it
  • Running automated security checks in a CI pipeline for skill repos
  • Identifying prompt injection attempts hidden in SKILL.md files
  • Detecting typosquatted npm/pip packages bundled with skills
  • Finding reverse shells or credential exfiltration patterns in skill scripts

Example Workflow

Here's how your AI assistant might use this skill in practice.

INPUT

User asks: Auditing a new third-party skill before installing it

AGENT
  1. 1Auditing a new third-party skill before installing it
  2. 2Running automated security checks in a CI pipeline for skill repos
  3. 3Identifying prompt injection attempts hidden in SKILL.md files
  4. 4Detecting typosquatted npm/pip packages bundled with skills
  5. 5Finding reverse shells or credential exfiltration patterns in skill scripts
OUTPUT
Scan OpenClaw skill directories for supply chain attacks and malicious code.

Share this skill

Security Audits

VirusTotalBenign
OpenClawBenign
View full report

These signals reflect official OpenClaw status values. A Suspicious status means the skill should be used with extra caution.

Details

LanguageMarkdown
Last updatedFeb 25, 2026