Claude
Skills
Sign in
โ† Back

360Guard

Included with Lifetime
$97 forever

360-degree comprehensive security review Skill. Use before installing any Skill from ClawHub, GitHub, or other sources. Performs full security scans including all Skill Vetter checks plus extended system/privacy/behavior checks and automated scanning scripts. Supports static analysis, behavior detection, dependency auditing.

Securityscripts

What this skill does


# 360Guard ๐Ÿ›ก๏ธ

> 360-degree comprehensive security review โ€” Like antivirus for your Skills

## 1. When to Use

- Before installing any Skill from ClawHub
- Before installing any Skill from GitHub or other sources
- When evaluating code shared by other Agents
- Any time you're asked to install unknown code
- Periodic audit of installed Skills (recommended monthly)
- Before running high-risk Skills for second verification

## 2. Core Principles

```
โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  ๐Ÿ›‘ Security Layer Priority                                 โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  โ›” EXTREME โ†’ Absolutely refuse to install                  โ”‚
โ”‚  ๐Ÿ”ด HIGH    โ†’ Requires human approval                       โ”‚
โ”‚  ๐ŸŸก MEDIUM  โ†’ Full code review + limited permissions        โ”‚
โ”‚  ๐ŸŸข LOW     โ†’ Basic review OK                               โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
```

## 3. Security Checklist

### 3.1 Base Red Flags (from Skill Vetter)

```
๐Ÿšจ Reject immediately if you see:
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
โ€ข curl/wget to unknown URLs
โ€ข Sends data to external servers
โ€ข Requests credentials/tokens/API keys
โ€ข Reads ~/.ssh, ~/.aws, ~/.config without clear reason
โ€ข Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md
โ€ข Uses base64 decode on anything
โ€ข Uses eval() or exec() with external input
โ€ข Modifies system files outside workspace
โ€ข Installs packages without listing them
โ€ข Network calls to IPs instead of domains
โ€ข Obfuscated code (compressed, encoded, minified)
โ€ข Requests elevated/sudo permissions
โ€ข Accesses browser cookies/sessions
โ€ข Touches credential files
โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€
```

### 3.2 Extended Red Flags (New)

#### 3.2.1 Persistence & Auto-start

```
๐Ÿ”ด Persistence check:
โ€ข Creates cron job / systemd service
โ€ข Modifies ~/.ssh/authorized_keys
โ€ข Writes to /etc/hosts
โ€ข Adds Login Items / Startup Items
โ€ข Modifies .bashrc / .zshrc / profile
โ€ข Registers LaunchAgent (macOS)
โ€ข Installs systemd user service
```

#### 3.2.2 Monitoring & Eavesdropping

```
๐Ÿ”ด Monitoring permissions check:
โ€ข Requests screen capture/recording (screencapture)
โ€ข Requests audio recording permission
โ€ข Keyloggers
โ€ข Accesses microphone/camera
โ€ข File system monitoring (fswatch/inotify)
```

#### 3.2.3 Data & Privacy

```
๐Ÿ”ด Data theft check:
โ€ข Reads clipboard (pbpaste)
โ€ข Reads environment variables (especially API_, SECRET, TOKEN)
โ€ข Accesses browser history/bookmarks
โ€ข Accesses macOS Keychain
โ€ข Accesses iMessage/SMS
โ€ข Accesses contacts/calendar
โ€ข Accesses photo library
```

#### 3.2.4 Network & Communication

```
๐Ÿ”ด Network anomaly check:
โ€ข Initiates reverse shell (nc -e / bash -i)
โ€ข Uses Tor proxy
โ€ข DNS queries to suspicious domains
โ€ข WebSocket long connections
โ€ข IRC connections
โ€ข Non-standard ports (>65535 or <1024 unusual)
โ€ข Hardcoded IP addresses (non-local)
```

#### 3.2.5 Code Execution (Advanced)

```
๐Ÿ”ด Dynamic execution check:
โ€ข Dynamic import (importlib.import_module)
โ€ข __import__() dynamic loading
โ€ข compile() dynamic compilation
โ€ข xmlrpc / jsonrpc remote calls
โ€ข pickle / yaml / marshal deserialization
โ€ข exec() / eval() any string
โ€ข subprocess shell=True
```

#### 3.2.6 File System

```
๐ŸŸก File operation check:
โ€ข Writes to executable paths outside /tmp
โ€ข Modifies /usr/local/bin
โ€ข Writes .dmg/.pkg installers
โ€ข Creates .hidden files/directories
โ€ข File permission modification (chmod +x)
โ€ข Symbolic links (pointing external)
โ€ข Contains binary files (.so/.dylib/.exe/.bin)
```

#### 3.2.7 Dependencies & Supply Chain

```
๐ŸŸก Supply chain check:
โ€ข Dependency version range too wide (>1.0.0 not ^1.0.0)
โ€ข Dependencies from private/unknown sources
โ€ข Dependencies on deprecated packages
โ€ข Silent additional dependency downloads
โ€ข References other unvetted Skills
โ€ข Uses git submodule (may point to malicious repo)
```

#### 3.2.8 Social Engineering

```
๐ŸŸก Social engineering check:
โ€ข Mimics popular Skill names (e.g., "github", "weather-ai")
โ€ข README overpromises ("one-click to do everything...")
โ€ข No source code, only compiled binaries
โ€ข Author has no history
โ€ข Downloads vs stars ratio suspicious (fake reviews)
```

---

## 4. Risk Classification

| Risk Level | Example Checks | Action |
|------------|----------------|--------|
| ๐ŸŸข LOW | Text processing, weather, note formatting | Basic review, OK to install |
| ๐ŸŸก MEDIUM | File I/O, browser control, API calls | Full review + limited permissions |
| ๐Ÿ”ด HIGH | Credential access, Keychain, network requests | Human approval + sandbox test |
| โ›” EXTREME | Persistence, root access, keylogging, reverse shell | **Refuse** |

---

## 5. Trust Hierarchy

| Source | Review Level | Recommendation |
|--------|--------------|----------------|
| Official OpenClaw Skills | Low (still review) | Basic check |
| High-star Repo (1000+) | Medium | Standard check |
| Known Authors | Medium | Standard check |
| Unknown Sources | High | Full check |
| Requests credentials | Extreme | **Refuse** |
| Modifies system files | Extreme | **Refuse** |

---

## 6. Automated Scanning Scripts

### 6.1 Quick Scan (quick-scan.sh)

```bash
#!/bin/bash
# Usage: ./quick-scan.sh /path/to/skill
# Output: Quick risk assessment report

SKILL_PATH=$1
echo "๐Ÿ” 360Guard Quick Scan: $SKILL_PATH"
echo "================================"

# Check dangerous functions
echo -e "\n๐Ÿ“ก Network request check:"
grep -r "curl\|wget\|fetch\|http\.\|https\.\|socket" "$SKILL_PATH" --include="*.sh" --include="*.js" --include="*.py" | head -5

# Check sensitive file access
echo -e "\n๐Ÿ”‘ Sensitive path check:"
grep -r "~/.ssh\|~/.aws\|~/.config\|/etc/hosts\|authorized_keys" "$SKILL_PATH" --include="*.sh" --include="*.js" --include="*.py"

# Check dangerous commands
echo -e "\nโš ๏ธ Dangerous command check:"
grep -r "eval\|exec\|shell=True\|base64 -d\|openssl" "$SKILL_PATH" --include="*.sh" --include="*.js" --include="*.py"

echo -e "\nโœ… Quick scan complete"
```

### 6.2 Full Scan (full-scan.sh)

```bash
#!/bin/bash
# Usage: ./full-scan.sh /path/to/skill
# Output: Complete security assessment report

SKILL_PATH=$1
REPORT="$SKILL_PATH/360guard-report.txt"

echo "๐Ÿ›ก๏ธ 360Guard Full Scan: $SKILL_PATH" | tee "$REPORT"
echo "========================================" | tee -a "$REPORT"

# 1. File structure check
echo -e "\n๐Ÿ“ File structure:" | tee -a "$REPORT"
find "$SKILL_PATH" -type f | head -20 | tee -a "$REPORT"

# 2. Dangerous function scan
echo -e "\nโš ๏ธ Dangerous function scan:" | tee -a "$REPORT"
for pattern in "eval(" "exec(" "shell=True" "base64" "subprocess" "importlib" "__import__" "pickle" "yaml.load" "xmlrpc" "socket.create_connection"; do
  result=$(grep -r "$pattern" "$SKILL_PATH" --include="*.sh" --include="*.js" --include="*.py" 2>/dev/null)
  if [ -n "$result" ]; then
    echo "  โŒ Found: $pattern" | tee -a "$REPORT"
    echo "$result" | head -3 | tee -a "$REPORT"
  fi
done

# 3. Sensitive path scan
echo -e "\n๐Ÿ”‘ Sensitive path scan:" | tee -a "$REPORT"
for pattern in "~/.ssh" "~/.aws" "~/.config" "/etc/hosts" "authorized_keys" "keychain" "credentials" ".env"; do
  result=$(grep -r "$pattern" "$SKILL_PATH" --include="*.sh" --include="*.js" --include="*.py" 2>/dev/null)
  if [ -n "$result" ]; then
    echo "  โš ๏ธ Warning: $pattern" | tee -a "$REPORT"
  fi
done

# 4. Network request scan
echo -e "\n๐ŸŒ Network request scan:" | tee -a "$REPORT"
grep -r "http://\|https://\|wget\|curl\|fetch" "$SKILL_PATH" --include="*.sh" --include="*.js" --include="*.py" | grep -v "^#" | head -10 | tee -a "$REPORT"

# 5. Persistence check
echo -e "\nโฐ Persistence check:" | tee -a "$REPORT"
for pattern in "cron" "systemd" "launchd" "login item" "startup" "autostart"; do
  result=$(grep -ri "$pattern" "$SKILL_PATH" --include="*.sh" --include="*.js" --include="*.py" 2>/dev/null)
  if [ -n "$result" ]; then
    echo "  ๐Ÿ”ด High risk: $pattern" | tee -a "$REPORT"
  fi
done

# 6. Dependency check
echo -e "\n๐Ÿ“ฆ Dependency check:" | tee -a "$REPORT"
if [ -f "$SKILL_PATH

Related in Security