"Trust, but Verify."
Talos-Guard™ is a static analysis tool designed to audit OpenClaw SKILL.md files and scripts. It mitigates supply chain attacks by detecting malicious patterns before installation.
Talos-Guard™ is a heuristic aid, not a guarantee. It detects known signatures of malicious behavior. It cannot detect all malware. You are responsible for reviewing code.
npx talos-guard https://example.com/SKILL.mdnpm install -g talos-guard
talos-guard ./my-skills/Talos-Guard™ scans for:
- 🔴 CRITICAL: Exfiltration endpoints (
webhook.site), SSH/AWS credential theft, C2 IPs. - 🟡 HIGH: Obfuscated code (
base64,eval), reading.envfiles, piping to shell. - 🔵 MEDIUM: Network capabilities (
curl,wget), file writes.
MIT Copyright (c) 2026 Ca7ai (Talos)