{"_id":"@clawsentinel/clawhub-scanner","_rev":"2-edea0f0b0fe876d453e2f065bc7a6020","name":"@clawsentinel/clawhub-scanner","dist-tags":{"latest":"0.7.1"},"versions":{"0.7.0":{"name":"@clawsentinel/clawhub-scanner","version":"0.7.0","keywords":["clawsentinel","openclaw","ai-security","supply-chain","skill-scanner","static-analysis"],"author":{"name":"hshdevhub"},"license":"Elastic-2.0","_id":"@clawsentinel/clawhub-scanner@0.7.0","maintainers":[{"name":"hshdevhub","email":"hsh.devhub@gmail.com"}],"homepage":"https://clawsentinel.dev","bugs":{"url":"https://github.com/hshdevhub/clawsentinel/issues"},"dist":{"shasum":"3965e5b71eaab9c1eb200b01915bd8303d63c9bf","tarball":"https://registry.npmjs.org/@clawsentinel/clawhub-scanner/-/clawhub-scanner-0.7.0.tgz","fileCount":5,"integrity":"sha512-fgSyg2iKfunnIGCPhfSiUME5ONgkGG3zCpzEEre4zwO2gAGVz8xOWQ8ooxXtSxx92DLscQvBv/595vAl0j+q3A==","signatures":[{"sig":"MEUCIFfiDXbTO+kD5cjIOVuE9I1cZNDgI9nRqgttTdIFWcETAiEAoj5JXQExpZQ/5S48rSYrSMZ1n6yNiQxQ4VmIwGxEJUU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":76626},"main":"./dist/index.js","types":"./dist/index.d.ts","module":"./dist/index.mjs","engines":{"node":">=20.0.0"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"gitHead":"3e6af856eabbc1bce4a1d32eddb58b5fe84aeebe","scripts":{"dev":"tsx src/index.ts","test":"vitest run","build":"tsup src/index.ts --format cjs,esm --dts --clean","clean":"rm -rf dist","typecheck":"tsc --noEmit"},"_npmUser":{"name":"hshdevhub","email":"hsh.devhub@gmail.com"},"repository":{"url":"git+https://github.com/hshdevhub/clawsentinel.git","type":"git","directory":"packages/clawhub-scanner"},"_npmVersion":"10.9.2","description":"Pre-install skill scanner and supply chain protection — ClawSentinel Module 4","directories":{},"_nodeVersion":"22.16.0","dependencies":{"chokidar":"^3.6.0","node-cron":"^3.0.3","better-sqlite3":"^9.4.0","@clawsentinel/core":"^0.7.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.7.0","tsup":"^8.0.0","vitest":"^1.4.0","typescript":"^5.4.0","@types/node":"^20.0.0","@types/better-sqlite3":"^7.6.0"},"_npmOperationalInternal":{"tmp":"tmp/clawhub-scanner_0.7.0_1772295840387_0.4427125014817148","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"@clawsentinel/clawhub-scanner","version":"0.7.1","description":"Pre-install skill scanner and supply chain protection — ClawSentinel Module 4","license":"Elastic-2.0","author":{"name":"hshdevhub"},"homepage":"https://clawsentinel.dev","repository":{"type":"git","url":"git+https://github.com/hshdevhub/clawsentinel.git","directory":"packages/clawhub-scanner"},"keywords":["clawsentinel","openclaw","ai-security","supply-chain","skill-scanner","static-analysis"],"engines":{"node":">=20.0.0"},"publishConfig":{"access":"public"},"main":"./dist/index.js","module":"./dist/index.mjs","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.mjs","require":"./dist/index.js"}},"scripts":{"build":"tsup src/index.ts --format cjs,esm --dts --clean","dev":"tsx src/index.ts","test":"vitest run","typecheck":"tsc --noEmit","clean":"rm -rf dist"},"dependencies":{"@clawsentinel/core":"^0.7.0","better-sqlite3":"^9.4.0","chokidar":"^3.6.0","node-cron":"^3.0.3"},"devDependencies":{"@types/better-sqlite3":"^7.6.0","@types/node":"^20.0.0","typescript":"^5.4.0","tsup":"^8.0.0","tsx":"^4.7.0","vitest":"^1.4.0"},"_id":"@clawsentinel/clawhub-scanner@0.7.1","gitHead":"14e9fa0aa873df728044019600326fa7fe09ad9d","bugs":{"url":"https://github.com/hshdevhub/clawsentinel/issues"},"_nodeVersion":"22.16.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-WedulbAzmB4kOTNkQibHOdfLrssj9fQK+tcl1oh5hdsyVNpb//Owx8kY+T9iZEuikJAnOEekirohUQ0mxrU1LA==","shasum":"9bf3fe193b30c55c23b00ca13bf5d53c85084e5c","tarball":"https://registry.npmjs.org/@clawsentinel/clawhub-scanner/-/clawhub-scanner-0.7.1.tgz","fileCount":6,"unpackedSize":78753,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIE+OGGTQ6k5XjJxsI7iLmCVXjVAloBUjHMC+QNPGEROjAiEAswuX/Eqxbem1NAH6Ia727giFE9Kfd61MOdruHYVhm1Q="}]},"_npmUser":{"name":"hshdevhub","email":"hsh.devhub@gmail.com"},"directories":{},"maintainers":[{"name":"hshdevhub","email":"hsh.devhub@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/clawhub-scanner_0.7.1_1772296261339_0.6238522232168033"},"_hasShrinkwrap":false}},"time":{"created":"2026-02-28T16:24:00.310Z","modified":"2026-02-28T16:31:01.626Z","0.7.0":"2026-02-28T16:24:00.560Z","0.7.1":"2026-02-28T16:31:01.502Z"},"bugs":{"url":"https://github.com/hshdevhub/clawsentinel/issues"},"author":{"name":"hshdevhub"},"license":"Elastic-2.0","homepage":"https://clawsentinel.dev","keywords":["clawsentinel","openclaw","ai-security","supply-chain","skill-scanner","static-analysis"],"repository":{"type":"git","url":"git+https://github.com/hshdevhub/clawsentinel.git","directory":"packages/clawhub-scanner"},"description":"Pre-install skill scanner and supply chain protection — ClawSentinel Module 4","maintainers":[{"name":"hshdevhub","email":"hsh.devhub@gmail.com"}],"readme":"# @clawsentinel/clawhub-scanner\n\nPre-install skill scanner for the ClawSentinel security platform. Intercepts `openclaw skill install` commands and scans skill YAML source for supply chain threats before anything is installed.\n\n> This is an internal package. Install [`clawsentinel`](https://www.npmjs.com/package/clawsentinel) to use the full platform.\n\n## What it does\n\nClawHub Scanner hooks into the OpenClaw skill install lifecycle and runs a static analysis pipeline on every skill before it executes:\n\n| Check | What it catches |\n|---|---|\n| **Shell execution** | `exec()`, `spawn()`, `execSync()`, `child_process` usage |\n| **Reverse shell** | `/bin/bash`, `netcat`, `mkfifo`, piped shell patterns |\n| **Code evaluation** | `eval()`, `new Function()`, obfuscated dynamic execution |\n| **Credential access** | Reads from `~/.ssh`, `~/.aws`, `~/.openclaw/config`, `process.env.*_KEY` |\n| **Embedded injection** | Prompt injection payloads hard-coded into skill `systemPrompt` fields |\n| **Outbound HTTP** | Calls to non-allowlisted domains (flagged as warn) |\n| **SSRF** | Internal/loopback HTTP calls (`127.0.0.1`, `192.168.x.x`, `localhost`) |\n| **Persistence** | `crontab`, `launchctl`, `systemctl enable` — skills that survive reboots |\n| **Tamper detection** | SHA-256 hash verification — flags skills modified after initial scan |\n\n## Verdict levels\n\n| Score | Verdict | Action |\n|---|---|---|\n| 0 block findings | ✅ Safe | Install proceeds |\n| 1+ warn findings | ⚠️ Review | User prompted to confirm |\n| 1+ block findings | 🔴 Blocked | Install halted |\n\n## Usage (via CLI)\n\n```bash\n# Scan a skill before installing\nclawsentinel scan <skill-id>\n\n# Scan from a local YAML file\nclawsentinel scan ./my-skill.yaml\n```\n\n## Threat addressed\n\n**T2 — Supply Chain Attack**: A malicious skill published to ClawHub runs with full OpenClaw permissions. ClawHub Scanner catches the attack before the skill ever executes.\n\n## Links\n\n- [ClawSentinel Platform](https://clawsentinel.dev)\n- [GitHub](https://github.com/hshdevhub/clawsentinel)\n- [License: Elastic-2.0](https://www.elastic.co/licensing/elastic-license)\n","readmeFilename":"README.md"}