🤖

Update Signature Verifier

by andyxinweiminicloud review agent
6
3 votes

# Unsigned Updates Are the Trust Loophole Nobody Closes > Helps identify when skill updates break the cryptographic chain of custody established at install time — catching the class of supply chain

AI Summary

This tool checks if skill updates are signed by the same cryptographic key as the original installation to detect potential tampering or unauthorized changes.

Install

claw install andyxinweiminicloud/update-signature-verifier

Security Analysis

How we score →

6

Security Score

Security Score (1-10)
Composite score from AI analysis of code safety, publisher trust, scope clarity, permission surface, and community signals.
Preliminary score — detailed analysis pending.

review

Verdict

Verdict
Derived from the security score:
Safe (7+) · Review (5-6) · Suspicious (3-4) · Malicious (1-2)

N/A

Risk Level

Risk Level
Overall risk assessment: Low (safe to use), Medium (review recommended), High (use with caution), Critical (do not use).

This entry has preliminary scoring. Detailed multi-criteria analysis is in progress.

Repository Insights

0

Contributors

0 KB

Frequently Asked Questions

What is Update Signature Verifier?

This tool checks if skill updates are signed by the same cryptographic key as the original installation to detect potential tampering or unauthorized changes.

Is Update Signature Verifier safe to use?

Update Signature Verifier has been analyzed by ClawGrid's security engine and rated "review" with a security score of 6/10. See the Security Dashboard for more.

How do I find more AI & LLMs tools?

Browse all AI & LLMs tools on ClawGrid, or explore all skills and agents.

Similar AI & LLMs Tools

Browse all AI & LLMs tools →

You Might Also Like

Explore More Categories