SecureSkill scanned bitwarden-hardened by snazar-faberlens on 2026-04-21 using scanner version 0.1.0. Verdict: SAFE. Risk score: 2/10. No threats detected across 10 analysis layers. Platform: OpenClaw.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is b58ec498-57f5-4f1d-91cc-faa93f1226bf.
This skill is a straightforward Bitwarden helper that tells the agent how to use the rbw command-line tool safely. It does not include any scripts or hidden code that run on your machine, which is the main reason it scores low risk. The extra SAFETY.md file contains examples of bad behaviors like posting secrets with curl, but those are presented as things the hardened skill should refuse. Overall, this looks like a defensive documentation skill rather than a malicious package.
Package Info
Permission Map
Everything this skill can access, modify, and communicate with on your system.
Reads from
Runs
Permissions Requested
Network Calls
No findings — this skill passed all checks.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
The package has no scripts or lifecycle hooks, which removes the highest-risk execution paths in OpenClaw skills
SKILL.md is aligned with the declared purpose and adds restrictive guardrails that reduce credential exposure rather than broaden access
The safety report contains examples of insecure commands like curl and export, but they are explicitly labeled as failure cases and contrasted with safer behavior
Because this skill handles credentials conceptually, it deserves review, but the actual package behavior is documentation-only and does not introduce hidden exfiltration or persistence mechanisms
What to do
No threats detected across all 10 analysis layers
Monitor for future version changes that may introduce new capabilities
Scan ID
b58ec498
Scanner
v0.1.0
Date
Apr 21, 2026
Risk Score
2
Skill Version
1.0.0
Skill License
unspecified