fox-skill-vetterSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Install via ClawdBot CLI:
clawdbot install qinthqod/fox-skill-vetterGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Uses known external API (expected, informational)
api.github.comAudited Apr 17, 2026 · audit v1.0
Generated Oct 6, 2026
A developer browsing ClawdHub finds a trending skill that promises web scraping and automation. Before installing, they run the Fox Skill Vetter protocol to review the source, scan the code for red flags like curl-to-IP or credential access, and classify the risk level before allowing it into their agent workspace.
A platform team managing dozens of internal AI agents enforces a policy that no third-party skill reaches production without a vetting report. The Fox Skill Vetter output format becomes the standardized approval artifact attached to every skill merge request, feeding into a human approval workflow for HIGH and EXTREME risk items.
An agent that discovers skills shared by other autonomous agents uses Fox Skill Vetter as an automatic first-pass filter. Suspicious patterns like base64 decoding, MEMORY.md access, or obfuscated code trigger immediate rejection, while clean skills are queued for the human operator to review the generated vetting report.
A security researcher collects candidate malicious skills from public repos and runs them through the vetting protocol to rapidly triage which ones exhibit credential exfiltration or system modification behavior. The structured red-flag checklist speeds up documentation and disclosure.
A hosted agent provider requires customers to submit custom skills through a vetting pipeline before deployment. Fox Skill Vetter's permission scope and trust hierarchy sections let the provider enforce least-privilege skill access and route credential-requesting skills to mandatory human approval.
Offer the core Fox Skill Vetter checklist and manual report format for free, then charge for automated scanning that runs the protocol against GitHub repos and ClawdHub listings at scale. Paid tiers add CI/CD integration, historical audit logs, and team dashboards.
Bundle the vetter as part of a broader agent governance platform that enforces approval workflows, permission policies, and compliance reporting. The open vetting protocol drives adoption while the platform sells policy enforcement and auditability to security and platform teams.
Sell expert-led skill vetting engagements where human analysts apply and extend the Fox Skill Vetter protocol for organizations adopting third-party agent skills. Deliverables include risk classification reports, remediation guidance, and trust hierarchy policies tailored to the client.
💬 Integration Tip
Embed the vetting protocol as a mandatory pre-install step in your agent's skill-loading pipeline and persist each generated report as an audit artifact for future reference. For automation, chain the GitHub quick-vet curl commands into a CI check that blocks merges when red flags are detected.
Scored Oct 6, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...