Domain Trust Check

Check any URL for phishing, malware and brand abuse before visiting

Security✓ SafeBeginnerv1.2.1
Last verified:March 2026

About

Domain Trust Check gives your OpenClaw agent the ability to verify any URL before visiting it — checking for phishing indicators, active malware, brand abuse and known scam patterns. As agents become more autonomous and browse the web on your behalf, the risk of visiting a malicious URL silently increases. This skill acts as a real-time safety layer querying multiple threat intelligence sources before your agent loads any external page.

Use Cases

  • Agent checks every URL in your inbox before clicking or summarising content
  • Web research tasks automatically skip flagged or suspicious domains
  • Monitor competitor or partner URLs and alert when any get flagged
  • Add a safety gate to any skill that fetches external content

What Domain Trust Check can access

Moderate access

Skim the SKILL.md before installing, and check which credentials it asks for against what it actually claims to do.

  • Reads your stored data

    It queries a database or persistent store. Prefer a read-only credential unless it genuinely needs to write.

    This skill's own description refers to "query"

  • Makes outbound network calls

    It contacts external services. Outbound calls are how data leaves your machine, so it is worth knowing where it connects.

    This skill's own description refers to "web"

These permissions are inferred from this listing — the credentials it declares, any maintainer warning, and the operations its own description mentions. ClawVault has not audited this skill's source code. Treat it as a starting point for your own review, not a substitute for one.

Installing Domain Trust Check on OpenClaw

An OpenClaw skill is a directory containing a SKILL.md file: Markdown with YAML frontmatter. At startup OpenClaw scans the eligible skill directories and injects a compressed description of each skill into its system prompt, so the agent knows what it can do and invokes a skill when a request matches.

  1. 1

    Find the skill in the registry

    openclaw skills search domain-trust-check

    ClawHub is the public registry for OpenClaw skills. Searching first gives you the exact owner-qualified reference, which is what the install command needs. Omit the query to browse the default feed.

  2. 2

    Check what it does and who published it

    openclaw skills verify @<owner>/domain-trust-check

    verify prints ClawHub's verification envelope, including its scan decision and, when available, a commit-pinned source URL. Add --card to read the generated Skill Card instead. Substitute the owner handle returned by the search above.

  3. 3

    Install it

    openclaw skills install @<owner>/domain-trust-check

    Native ClawHub skills use an @owner/slug reference. By default this installs into the active workspace skills/ directory; add --global to install into the shared managed directory instead. You can also install from Git with git:owner/repo, or from a local folder with ./path.

  4. 4

    Confirm the agent can see it

    openclaw skills check

    check reports which ready skills are actually visible to the agent's prompt surface, which is the quickest way to catch a skill that installed but did not load.

Commands follow the official OpenClaw documentation. Placeholders such as <owner> are filled in by the search step, because registry references are publisher-scoped.

Version & Updates

Current Version
1.2.1
Last Updated
March 5, 2026
What's New

Integrated VirusTotal API, improved domain reputation scoring, faster checks

Safety & verification

Listed as safe
No known issues reported for this skill in the OpenClaw ecosystem.

How OpenClaw screens skills

Since February 2026 ClawHub screens submitted skills with VirusTotal: each bundle is hashed and looked up, new bundles are scanned with Code Insight, and results drive an approve, warn or block decision with daily re-scanning. This materially reduces supply-chain risk but does not eliminate it, and independent research has found that different scanners frequently disagree about the same skill. Read the SKILL.md of anything you install, especially if it requests shell access or credentials.

Recommended

Running on a VPS?

Deploy OpenClaw, Hermes, or PicoClaw on Bluehost with the right template for the job.

Related Skills in Security