openclaw-skill-vetter-1-0-0Security vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated code, exfiltration. Risk classification L...
Install via ClawdBot CLI:
clawdbot install yiyi-9/openclaw-skill-vetter-1-0-0Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
POST → https://evil.com/stealPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://clawhub.comGenerated Mar 20, 2026
Large organizations deploying AI agents across departments use this skill to vet third-party skills before installation, ensuring compliance with internal security policies and preventing credential theft from untrusted code. It integrates into CI/CD pipelines to automatically scan skills from repositories like ClawHub, flagging high-risk permissions like unauthorized network access.
Platforms hosting AI agent skills, such as ClawHub or GitHub, integrate this vetting protocol to provide automated security reports for listed skills, helping users make informed installation decisions. It reduces support tickets related to malicious code by enforcing red flag checks like obfuscated scripts or credential harvesting patterns.
Training programs for AI developers and IT professionals use this skill to teach best practices in code review and risk assessment, using its structured checklist to demonstrate real-world vetting steps. Participants learn to identify threats like data exfiltration or unauthorized file access in hands-on exercises.
Independent security consultants offer vetting services to clients deploying AI agents, using this skill to generate detailed reports on skill safety and risk classification. They analyze skills from sources like GitHub for red flags such as eval() usage or unknown URLs, providing recommendations based on the LOW/MEDIUM/HIGH/EXTREME scale.
Open source projects involving AI agents employ this skill to review community-contributed skills before merging, ensuring they adhere to security standards and minimal privilege principles. It automates checks for dependencies and permission scope, preventing issues like system file modifications in shared repositories.
Offer a free basic version for individual users to vet skills manually, with premium tiers providing automated scanning, API access for enterprises, and detailed compliance reports. Revenue comes from subscriptions for advanced features like integration with CI/CD systems and priority support.
License the vetting protocol to companies building AI agent platforms, embedding it as a core security feature to enhance trust and reduce liability. Revenue is generated through upfront licensing fees and ongoing maintenance contracts based on user scale and customization needs.
Provide expert consulting to organizations for implementing the vetting process, including custom workshops, security audits, and incident response for skill-related breaches. Revenue streams include hourly rates for consultations and fixed-price packages for training sessions.
💬 Integration Tip
Integrate this skill into automated workflows using its quick vet commands for GitHub or ClawHub, ensuring tools like curl and jq are installed as prerequisites to streamline security checks.
Scored Apr 19, 2026
Uses known external API (expected, informational)
api.github.comAudited Apr 17, 2026 · audit v1.0
Helps users discover and install agent skills when they ask questions like "how do I do X", "find a skill for X", "is there a skill that can...", or express interest in extending capabilities. This skill should be used when the user is looking for functionality that might exist as an installable skill.
A self-evolution engine for AI agents. Analyzes runtime history to identify improvements and applies protocol-constrained evolution. Communicates with EvoMap...
Give your AI agent eyes to see the entire internet. 7500+ GitHub stars. Search and read 14 platforms: Twitter/X, Reddit, YouTube, GitHub, Bilibili, XiaoHongS...
Ultimate AI agent memory system for Cursor, Claude, ChatGPT & Copilot. WAL protocol + vector search + git-notes + cloud backup. Never lose context again. Vibe-coding ready.
Transform AI agents from task-followers into proactive partners with memory architecture, reverse prompting, and self-healing patterns. Lightweight version f...
Persistent memory for AI agents to store facts, learn from actions, recall information, and track entities across sessions.