mikecavallo/ClawGuard Security Scanner

Scan AI agent skills for security threats — static analysis, dependency scanning, prompt injection detection

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Feb 16, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: mikecavallo/clawguard@ca722f64834eff289eefac8765c147b9d0dae918 # v1.0.2

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
pathPath to the skill directory to scanyes.
severity-thresholdMinimum severity to fail the action (critical, high, medium, low)nohigh
output-formatOutput format (md, json)nomd
semanticEnable LLM-powered semantic analysis (requires api-key)nofalse
api-keyAPI key for semantic analysis (use secrets!)no
node-versionNode.js version to useno20
namedescription
risk-levelRisk level (SAFE, LOW, MEDIUM, HIGH, CRITICAL)
risk-scoreRisk score (0-100)
findings-countTotal number of findings
reportFull scan report