Free: 2 scans/month — full report
From $99/mo: 10+ scans
Fast: minutes to start

Audit your OpenClaw skills in minutes.

ClawAudit finds permission risk, secrets exposure, data-flow issues, and supply-chain weaknesses. Every scan delivers a full professional report — free or paid. Upgrade for more scans, not more quality.

Built for OpenClaw

Audits focus on skills: configs, tool permissions, dependencies, and code patterns specific to agent deployments.

Actionable findings

Prioritized issues with clear remediation guidance so you can ship confidently and faster.

Client-ready output

Paid tiers deliver a structured report you can hand to customers, stakeholders, or reviewers.

Link → Scan → Download report

Three steps. Clear output. Upgrade only when you're ready.

Calculate ROI from this demo

Use the demo results (42 issues found) to estimate your potential savings.

1

Upload / Link

Share your repo URL (private OK) or deliver a package. We confirm scope + expectations.

  • Repo URL
  • Zip package
  • NDA on request
2

Scan & Review

Automated checks plus manual review depending on tier. We triage risk and validate findings.

  • Permissions & tools
  • Secrets & logs
  • Dependencies & CVEs
3

Download

Free: full report for 2 scans/month. Paid: unlimited scans with full reports and priority support.

  • Client-ready format
  • Severity ranking
  • Remediation guidance

See ClawAudit in Action

Watch a 60-second scan of a malicious skill — from upload to critical findings to PDF report.

Watch: 60-second scan of a malicious skill → Score 100/100 Critical

Click to play

🔍

42 security checks in 60 seconds

Our engine runs 64 rules across permissions, secrets, data flow, and dependencies — fast enough for every commit.

🛡️

Detected: crypto miner, data exfiltration, supply chain attack

Real threats hiding in a "harmless" Wordle game. ClawAudit flags what manual review misses.

📊

Professional PDF report with remediation steps

Every finding includes file paths, severity, evidence, and step-by-step fixes. Client-ready from day one.

Real Attack Detected: Hidden in Plain Sight

How ClawAudit uncovered severe security risks in a seemingly harmless Wordle game skill.

100/100

Risk Score - CRITICAL

A Wordle game skill claimed "offline only, no telemetry" but ClawAudit detected TLS bypass, secret exfiltration, and obfuscated payloads.

🔴 TLS Verification Disabled

Critical Finding

Explicitly disabled TLS protections with process.env.NODE_TLS_REJECT_UNAUTHORIZED = '0', enabling man-in-the-middle attacks.

🔴 Secret Exfiltration

High Severity

Read AWS_SECRET_ACCESS_KEY from environment and transmitted it to an external webhook endpoint.

See the Full Analysis

Complete findings with evidence, code samples, and remediation guidance from a real-world security audit.

See Demo in Action

Watch how ClawAudit detects malicious code in seconds. 60-second interactive preview.

🔒

Security Scan

Target: monad-wordle-game.zip

Ready
📦

Drop your skill package

Simulating upload of monad-wordle-game.zip (2.3 MB)

Auto-play simulation
~60 seconds

Calculate the cost of NOT scanning

See how much you could save by catching security issues before deployment.

Same quality. More scans.

Every tier gets the same professional report — full findings, evidence, and remediation steps. The only difference is how many skills you can audit.

Free Try it
$0
Full-quality report. See exactly what ClawAudit finds — no watermarks, no truncation.
  • 2 scans / month
  • Full professional report
  • All findings + evidence
  • Risk score + remediation steps
  • Community support
Try Free →
Starter Popular
$99 / month
For builders and small teams running multiple skills in production.
  • 10 scans / month
  • Full professional report
  • All findings + evidence
  • Remediation recommendations
  • Email support
Contact Us →
Enterprise Custom
Custom
For MSPs and organizations managing multiple clients or large skill portfolios.
  • Unlimited + multi-org
  • White-label reports
  • Custom pricing & SLA
  • Dedicated support
  • Expert review add-on
Contact Us →

Not sure which tier makes sense? Estimate your savings first.

Calculate Your Audit ROI →

Compare Plans

Plan Scans / Month Full Report Support Price
Free 2 ✓ (full) Community Free
Starter 10 ✓ (full) Email $99/mo
Pro Unlimited ✓ (full) Priority $299/mo
Enterprise Custom ✓ (custom) SLA Contact

Every tier gets the full report

We don't hide findings or water down free reports. Every scan — free or paid — delivers the same professional-grade audit: risk score, all findings with evidence (files & lines), severity ranking, and actionable remediation steps. Upgrade when you need more scans, not more quality.

Full findings

Every finding with file paths, line numbers, and severity — nothing hidden, nothing truncated.

Actionable fixes

Clear remediation steps for each issue. Know exactly what to change and why.

Scale when ready

Start with 2 free scans/month. Need more? Upgrade in seconds — no re-onboarding.

Try a free scan (2 scans/month)

Enter your email + a GitHub repo URL (or upload a .zip). Results appear below instantly.

Or email us: audits@gesys.ai

Sample outputs and real-world use

Use the sample deliverables to see the structure, tone, and depth.

"We built ClawAudit to make OpenClaw skill security easy to understand and easy to fix - without slowing teams down."
Gesys SolutionsOperator team

Sample report

See an example report structure: executive summary → findings → remediation.

Why it matters

Skills touch tools, files, APIs, and secrets. A single misconfiguration becomes an attack surface. ClawAudit prioritizes least privilege + data flow clarity.