openclaw-skill-vetter-1-0-0Security vetting protocol before installing any AI agent skill. Red flag detection for credential theft, obfuscated code, exfiltration. Risk classification L...
Install via ClawdBot CLI:
clawdbot install yiyi-9/openclaw-skill-vetter-1-0-0Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
POST → https://evil.com/stealPotentially destructive shell commands in tool definitions
eval(Calls external URL not in known-safe list
https://clawhub.comGenerated Mar 20, 2026
Large organizations deploying AI agents across departments use this skill to vet third-party skills before installation, ensuring compliance with internal security policies and preventing credential theft from untrusted code. It integrates into CI/CD pipelines to automatically scan skills from repositories like ClawHub, flagging high-risk permissions like unauthorized network access.
Platforms hosting AI agent skills, such as ClawHub or GitHub, integrate this vetting protocol to provide automated security reports for listed skills, helping users make informed installation decisions. It reduces support tickets related to malicious code by enforcing red flag checks like obfuscated scripts or credential harvesting patterns.
Training programs for AI developers and IT professionals use this skill to teach best practices in code review and risk assessment, using its structured checklist to demonstrate real-world vetting steps. Participants learn to identify threats like data exfiltration or unauthorized file access in hands-on exercises.
Independent security consultants offer vetting services to clients deploying AI agents, using this skill to generate detailed reports on skill safety and risk classification. They analyze skills from sources like GitHub for red flags such as eval() usage or unknown URLs, providing recommendations based on the LOW/MEDIUM/HIGH/EXTREME scale.
Open source projects involving AI agents employ this skill to review community-contributed skills before merging, ensuring they adhere to security standards and minimal privilege principles. It automates checks for dependencies and permission scope, preventing issues like system file modifications in shared repositories.
Offer a free basic version for individual users to vet skills manually, with premium tiers providing automated scanning, API access for enterprises, and detailed compliance reports. Revenue comes from subscriptions for advanced features like integration with CI/CD systems and priority support.
License the vetting protocol to companies building AI agent platforms, embedding it as a core security feature to enhance trust and reduce liability. Revenue is generated through upfront licensing fees and ongoing maintenance contracts based on user scale and customization needs.
Provide expert consulting to organizations for implementing the vetting process, including custom workshops, security audits, and incident response for skill-related breaches. Revenue streams include hourly rates for consultations and fixed-price packages for training sessions.
💬 Integration Tip
Integrate this skill into automated workflows using its quick vet commands for GitHub or ClawHub, ensuring tools like curl and jq are installed as prerequisites to streamline security checks.
Scored Apr 19, 2026
Uses known external API (expected, informational)
api.github.comAudited Apr 17, 2026 · audit v1.0
Transform AI agents from task-followers into proactive partners that anticipate needs and continuously improve. Now with WAL Protocol, Working Buffer, Autonomous Crons, and battle-tested patterns. Part of the Hal Stack 🦞
Clawdbot documentation expert with decision tree navigation, search scripts, doc fetching, version tracking, and config snippets for all Clawdbot features
Display and control HTML content on connected Mac, iOS, or Android nodes via a web-based canvas with live reload and remote actions.
Backup and restore OpenClaw data. Use when user asks to create backups, set up automatic backup schedules, restore from backup, or manage backup rotation. Handles ~/.openclaw directory archiving with proper exclusions.
Use the ClawdHub CLI to search, install, update, and publish agent skills from clawdhub.com. Use when you need to fetch new skills on the fly, sync installed skills to latest or a specific version, or publish new/updated skill folders with the npm-installed clawdhub CLI.
Vet ClawHub skills for security and utility before installation. Use when considering installing a ClawHub skill, evaluating third-party code, or assessing w...