skill-guard
skill-guard stages and scans ClawHub skills before installing using `./scripts/safe-install.sh`, `clawhub install`, and `uvx mcp-scan@latest`, and installs into `~/.openclaw/workspace/skills`. The content executes shell commands and performs network fetches (e.g., `clawhub install`, `uvx mcp-scan@latest`, `curl https://astral.sh/uv/install.sh`), which is purpose-aligned.