VerifyClaw continuously scans, scores & verifies the OpenClaw skill ecosystem — 80k+ skills graded and graphed, MCP servers tested against SAFE-MCP.
⚡ Near-real-time skill sync🕸️ Graph visualization🔎 Semantic discovery🧠 IntelligenceiIntelligence — the Skill Architect. Describe a goal and it composes a deployable agent from real registry skills, and surfaces ecosystem gaps, emerging trends, and an audit of best / duplicate / abandoned skills.📋 25 grammar-based threat patterns🧬 SAFE-MCP 86-check MCP test
Registry Skills
—
Total Scans
—
Threats Found
—
Authors
—
Patterns
—
signatures
📊 Registry Overview
🕸️ Graph
🔍 Scan
📋 Patterns
👤 Authors
🏆 Rankings
🔥 Popular
🧠 Intelligence
💬 Discovery
🧬 MCP Test
🗄 MCP Registry
MCP Test · SAFE-MCP battery
Paste an MCP server's Git link and run the full SAF-MCP coverage battery — 73 published SAF-MCP techniques plus 13 ClawScan extensions, across 14 ATT&CK-aligned tactics. Static signature, sandboxed-live, and auth-aware checks roll up into a per-tactic resistance matrix and a trust score.
33 of 86 techniques have static detectors and run on a bare git link. The remaining 53 need a live Morph Cloud sandbox pass, an OAuth/token flow, or a Claude semantic-analysis pass — reported as pending, and never scored as a pass. Every run is saved to the public 🗄 MCP Registry.
86
73 SAF-MCP + 13 ext
33
static detectors
53
pending (sandbox/auth/LLM)
Coverage by tactic
Framework: SAF-MCP — Linux Foundation / OpenSSF, MITRE ATT&CK-aligned. Upstream renamed SAFE-MCP → SAF-MCP (SAFE-T → SAF-T, numbers unchanged). 73 of these are canonical SAF-MCP techniques; 13 are ClawScan extensions, not official.
🗄 MCP Registry
Every MCP server run through MCP Test is saved here — public and free. Trust score, pass/fail counts, and the full SAF-MCP report for anyone to reference.
Tested MCP Servers
MCP Server
Trust Score
Passed
Failed
Pending
Last Tested
Report
Loading…
Risk Distribution iOnly flagged skills appear in these bars. Skills are bucketed by risk score \u2014 CRITICAL \u226575, HIGH 50\u201374, MEDIUM 25\u201349, LOW 1\u201324. A skill that declares no risk-bearing capability scores 0 and is not shown, so LOW = 0 means nothing scored 1\u201324 \u2014 not that there are no safe skills. The safe majority sits at score 0 (see the note below the bars).
Categories
🔬 Deep Skill Test iTop-downloaded skills tested with full Claude semantic analysis — catches hidden tool-description instructions, disguised credential harvesting, and social engineering that grammar-based static analysis misses. Incremental: already-tested skills are skipped and cost nothing on rerun.
Loading…
#
Skill
Downloads
Grammar
Deep
Risk
Summary
Tested
🏆 Top Rated Skills
Rankings not generated yet
🛑 Top Risky Skills
Skill
Author
Risk
Findings
Category
🕸️ Registry Skill Graph
CRITICALHIGHLOWPublisherThreat
Drag · Scroll to zoom · Hover for details
SKILL.md Content
Tier:
🛡️
Paste a SKILL.md and click scan
Threat Patterns
Author Risk Profiles
Reach is per-skill, not per-author yet. The current crawl returns no publisher handle, so these authors (from earlier crawls) aren't linked to the freshly-downloaded skills \u2014 Downloads and Exposure read 0/\u2014 until owner attribution is restored. Real download reach lives in the per-skill Exposure ranking. Published mirrors scanned Skills (publisher-profile counts aren't crawled).
Author
Skills
Published
Downloads
Exposure
Avg Risk
Max Risk
Critical
Findings
Kind
🔥 Most Popular Skills
Ranked by active downloads from the live ClawHub catalog, with ClawScan risk and the marketplace verdict side by side. A red gap in Agreement means our scanner flags the skill while ClawHub still lists it clean \u2014 the moderation gap, weighted by reach.
#
Skill
Author
Downloads
Risk
ClawHub
Agreement
Exposure
Loading\u2026
⚡ Utility Distribution
📂 Top Categories
🏆 Top Rated Skills
#
Skill
Author
Utility
Category
Description
Risk
No rankings yet.
📡 Ranking Status
🧠 Skill Architect AI-powered
Describe what you want your agent to do. The Architect will select the best skills from 10K+ in the registry and design an optimal pipeline.