Skill Security Vetter
Paste the following prompt into your AI chat to install this skill:
Please install @user_647f88ca/zy-skill1 using the official guide at https://skillhub.cn/install/skillhub.md.
About this skill
Problem
When agents install third-party skills, unknown code may run as if it were a normal extension. A SKILL.md description can hide credential reads, system commands, browser automation, or risky API calls. Skill Vetter turns install-or-not into a reviewable security check instead of a heuristic decision.
How It Works
- Source check: Identify whether the skill comes from ClawdHub, a GitHub repo, another agent, or an unknown source, then adjust scrutiny by trust level.
- Mandatory code review: Read all files in the skill and look for red flags such as credential handling, external requests, file operations, permission expansion, and unsafe system access.
- Permission-scope assessment: Check whether requested
file,browser,API, orsystempermissions match the stated functionality. - Risk classification: Use
LOW,MEDIUM,HIGH, andEXTREMElevels to recommend install, human approval, or rejection; credentials, trading, system, security configs, and root access require stricter handling. - Vetting report: Produce a documented conclusion for future review and audit.
Boundaries
It is useful as a pre-install gate for third-party agent capabilities, especially GitHub-hosted or shared skills. It is not a runtime sandbox, dependency scanner, or network-isolation solution. High-risk skills still need human approval and a retained vetting record.
Use Cases
- Before pulling an unknown skill from GitHub, read all files, flag credential and system-permission risks, and issue an install verdict.
- When evaluating skills shared by other agents, apply trust-level-based code review and permission-scope checks.
- For skills involving trading, system configuration, or credentials, require HIGH / EXTREME risk classification and human approval guidance.
- Turn a pre-install skill security review into a recheckable report for later team audit.
Best For
- Engineers adding third-party agent extensions, who want to confirm whether code requests permissions beyond its stated function.
- Maintainers of ClawdHub or GitHub skill repositories, who want a consistent security review for candidate skills.
- Ops engineers managing AI agent permissions in production, who want to avoid unknown code accessing systems, browsers, or credentials.
- Security leads reviewing outsourced agent code, who want the pre-install review process to leave an auditable record.
Related Skills
A lightweight wrapper and automation tool for Jaeger-related GitHub scenarios.
Vault Wrap is a wrapping skill for Vault and GitHub automation.
Port management, threat-intel audits, drift checks, and multi-node monitoring for self-hosted infrastructure.
Provides health checks for HTTP, TCP, Ping, and log sources with dynamic-threshold alerts, anomaly detection, and scheduled inspection reports.