Skill Security Vetting
Paste the following prompt into your AI chat to install this skill:
Please install @user_f12a44b7/clawhub-skill-vetter according to https://skillhub.cn/install/skillhub.md.
About this skill
Problem: Trust gaps before Skill installation
In AI Agent workflows, a Skill is not only a prompt fragment; it may also introduce tool calls, external links, environment variable access, and execution logic. Skills from ClawdHub, GitHub, or third-party repositories can look functionally similar, while their permission boundaries, triggers, and side effects differ significantly. Installing first and inspecting later can let an apparently harmless skill enter the execution path, exposing credentials, broadening access, or leaving hard-to-audit call traces.
How it works: move review before installation
Skill Security Vetting moves security checks ahead of the install action. It examines triggers, descriptions, file manifests, tool dependencies, and permission requests in a structured way, with focus on:
- Risk markers: requests for broad authorization, hidden triggers, access to sensitive directories or credentials
- Permission scope: whether network access, file writes, system commands, or third-party API calls exceed the stated need
- Suspicious patterns: vague descriptions, abnormal install scripts, obfuscated instructions, or behavior inconsistent with declared functionality
This produces a readable risk summary for engineers to decide whether to reject, restrict permissions, or proceed.
Boundaries
This skill is for pre-installation review and does not replace vulnerability scanning, dependency audits, or runtime sandboxing. For fully closed-source, dynamically loaded, or externally dependent Skills, combine it with source review and least-privilege controls.
Use Cases
- Review a ClawdHub skill's scope and triggers before pull.
- Check a submitted skill for system commands beyond its function.
- Audit a third-party skill's network and credential risks.
- Review a GitHub skill's files and vague descriptions.
Best For
- Agent platform engineers who need permission boundaries before launch.
- SREs who manage automation and need to check credential and network risks.
- Security engineers who review external contributions and need risk summaries.
- Ops leads who vet GitHub skills before adding them to production agents.
Related Skills
Detects child climbing, leaning out, or gripping window/balcony edges from surveillance video and outputs tiered alerts with historical reports.
A pre-release security auditor for Skills that statically checks injection, credentials, SSRF, CVEs, and permissions, with scored reports.
For independent developers, automates Git weekly reports, prioritized bug tickets, and project health checks into shareable Markdown.
Scan Windows caches, temporary files, and junk files, show space usage and risk levels, and clean selected items to free disk space.