Skill Vetter
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_6fc58c6f/skilljackwood.
About this skill
Problem
Agent skills are often installed as code packages that can read files, call APIs, access credentials, or modify system state. The risk is more subtle than running an unfamiliar dependency because the agent may invoke the skill repeatedly during later tasks.
How It Works
This skill provides a fixed pre-install review workflow: source check, mandatory code review, permission-scope assessment, and risk classification. The goal is not to replace security scanning, but to make suspicious behavior, permission boundaries, and human decision points explicit.
The reviewer should read every relevant file in the package, including SKILL.md, scripts, configs, and referenced resources, then look for red flags such as data exfiltration, credential access, persistence, or privilege escalation. For GitHub-hosted skills, it is useful to inspect repository trust and author history before doing file-level review.
Risk is then bucketed by capability:
- LOW: notes, weather, formatting; basic review may be enough
- MEDIUM: file operations, browser access, APIs; full code review is required
- HIGH: credentials, trading, system operations; human approval is required
- EXTREME: security configuration, root access; do not install by default
Trust also shapes review intensity. Official OpenClaw skills still need review; higher-profile repositories and known authors receive moderate scrutiny; new or unknown sources receive maximum scrutiny; any skill that requests credentials requires human approval. The final report should record the source, files reviewed, permissions, risk level, and recommended action.
Use Cases
- Before installing a third-party skill from ClawdHub, check its source, code, and permissions, then write a vetting conclusion.
- Evaluate an Agent skill from a GitHub repo for credential access, persistence, or exfiltration before deciding whether to install it.
- Create a team intake check for shared skills, separate LOW, MEDIUM, and HIGH risk, and flag items requiring human approval.
- Review a skill package that requests an API token, then determine whether its permission scope exceeds the task requirements.
Best For
- Agent security engineers who want a standard pre-install review process for unknown skills.
- Automation owners using ClawdHub who need to decide whether third-party skills can enter production.
- Platform teams maintaining shared skill libraries who need risk-tiered human-approval boundaries.
- SREs auditing third-party code who need documented file-level review findings and install refusals.
Related Skills
A lightweight wrapper and automation tool for Jaeger-related GitHub scenarios.
Vault Wrap is a wrapping skill for Vault and GitHub automation.
Port management, threat-intel audits, drift checks, and multi-node monitoring for self-hosted infrastructure.
Provides health checks for HTTP, TCP, Ping, and log sources with dynamic-threshold alerts, anomaly detection, and scheduled inspection reports.