Skill Vetter
Paste the following prompt into your AI chat to install this skill:
Please install @user_ecf8fbc6/skill--vetter according to https://skillhub.cn/install/skillhub.md.
About this skill
Installing AI agent skills without vetting can introduce security vulnerabilities such as data breaches or system compromises. Skill Vetter is a security-first vetting protocol designed to systematically assess skill risks before deployment.
Problem Context
AI skill platforms (e.g., ClawdHub or GitHub) offer a wide range of shared skills, but sources vary in quality. Directly installing unknown skills may lead to credential theft, permission abuse, or malicious code execution, increasing operational and security burdens. Traditional installation flows often skip proactive checks, leaving risks unaddressed.
Core Capabilities and Workflow
Skill Vetter implements comprehensive vetting through structured steps:
- Source Check: Verify publisher reputation and repository status, such as prioritizing official skills or high-star repos (1000+ Stars).
- Code Review (Mandatory): Read all skill files, checking for red flags like accessing credentials, modifying system configs, or involving trading operations.
- Permission Scope: Analyze requested permissions to ensure minimal privilege and avoid over-authorization.
- Risk Classification: Determine actions based on risk levels (🟢 LOW, 🟡 MEDIUM, 🔴 HIGH, ⛔ EXTREME), with high-risk skills requiring human approval.
After vetting, a standardized report is generated with risk levels and recommendations. The protocol also defines a trust hierarchy to guide scrutiny intensity from official skills to unknown sources.
Applicability and Considerations
Skill Vetter is applicable for pre-installation security assessments but is not a universal defense:
- When risks are uncertain, seek human decisions to avoid auto-installing high-risk skills (e.g., those involving security configs or root access).
- Vetting records aid future reference but may need adjustment for specific environments.
- The protocol emphasizes: no skill is worth compromising security—when in doubt, do not install.
Use Cases
- When downloading new skills from ClawdHub, use Skill Vetter for source verification and code scanning to ensure no malicious behavior before installation.
- Before deploying skills to production, run Skill Vetter to check requested permission scopes, preventing over-authorization and potential data leaks.
- When encountering high-risk skills (e.g., involving system configs), generate a vetting report and request team human approval to comply with security protocols.
- Periodically audit installed AI skills with Skill Vetter to update risk classification, ensuring ongoing security compliance.
Best For
- DevOps Engineer: Needs to vet AI skills installed by the team to prevent security vulnerabilities and system instability.
- AI Developer: Uses the vetting protocol to self-check code security and permission settings before publishing custom skills.
- Security Administrator: Responsible for evaluating high-risk skill installation requests based on vetting reports for approval decisions.
- Project Manager: Requires security reviews when introducing new AI tools to meet company compliance standards and reduce risks.
Related Skills
Comprehensive network engineering skill covering fault troubleshooting, technical consulting, and architecture design across routing and switching, wireless, security, cloud computing, and optical transport.
Provides 9 application modules based on GB/T 33000-2025 and DuPont safety methodologies for diagnosing, standardizing, and building culture in enterprise safety management systems.
Automatically scans skill packages before and after installation to block malicious or non-compliant code, acting as a security gatekeeper for skill platforms.
An independent tool risk query layer for evaluating the security risks of Chinese Agent tools before installation, providing information on permission transparency, privacy direction, and author reputation.