AI Skill Security Vetter
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_e9b89846/skill-vetter-test.
About this skill
Problem
Before installing unknown skills from ClawdHub, GitHub repositories, or other agents, teams often lack a consistent security review process. A skill may request credentials, hidden network access, system commands, or configuration changes. Skill Vetter treats “vet before install” as a hard constraint and helps decide whether a skill should be loaded and what level of human approval it requires.
How it works
- Source check: evaluate trust first; official OpenClaw skills may use lower scrutiny but still require review, high-star repos and known authors get moderate review, and new or unverified sources receive maximum scrutiny.
- Code review: read all files in the skill and look for red flags such as data exfiltration, hidden network requests, credential access, security config changes, shell execution, or
rootaccess. - Permission scope: assess the required file, browser, API, system, or credential access to avoid over-authorization.
- Risk classification: classify the skill as
LOW,MEDIUM,HIGH, orEXTREME;LOWneeds basic review,MEDIUMrequires full code review,HIGHrequires human approval, andEXTREMEshould not be installed. - Vetting report: produce a structured conclusion that can be reused for audits and team discussion.
Caveat: this skill is best used as a pre-install security gate for unknown code from ClawdHub, GitHub, or other agents. The provided material does not include the full red-flag checklist or quick vet command details, so real use should still inspect the complete skill files, repository history, dependencies, and runtime environment. Skills requesting credentials, trading, system permissions, or root access should always be escalated to a human.
Use Cases
- Before installing a new skill from ClawdHub, check source, dependencies, and requested permissions for overreach
- Before onboarding an agent skill from GitHub, read all files and flag security red flags
- Review a skill shared by another agent and decide whether file, browser, or API access needs human approval
- When an unknown skill requests system, credential, or root access, output a block-install conclusion
Best For
- SRE owners of AI agent supply-chain security who need a pre-release gate for unknown skills
- Platform engineers onboarding ClawdHub or GitHub skills who need an auditable review report
- Architects managing multi-agent teams who need a consistent human approval flow for HIGH-risk skills
- Security engineers reviewing third-party code who need to flag credential, root, or system permission red flags
Related Skills
A lightweight wrapper and automation tool for Jaeger-related GitHub scenarios.
Vault Wrap is a wrapping skill for Vault and GitHub automation.
Port management, threat-intel audits, drift checks, and multi-node monitoring for self-hosted infrastructure.
Provides health checks for HTTP, TCP, Ping, and log sources with dynamic-threshold alerts, anomaly detection, and scheduled inspection reports.