Runs VirusTotal-style security checks on OpenClaw/Cursor skills before install, including remote code execution (RCE) and malicious code (obfuscation, exfilt...
- User asks to "check this skill for safety", "security review this skill", or "is this skill safe to install?"
- **User goal: ensure all downloaded skills are benign** β Run the check on every newly added skill and (on request) on all skills in the user's skills dir; only treat Benign as safe to use.
- Skill requests OAuth, API keys, or `client_secret.json` and you need to flag risks.
- Comparing registry listing metadata to the skill's SKILL.md for mismatches.