pangshu-skill-vetterSecurity vetting for agent skills before installation. Scans skill code for dangerous Bash commands, sensitive file access, network exfiltration, obfuscated...
Install via ClawdBot CLI:
clawdbot install hjshysst-dot/pangshu-skill-vetterGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
/etc/passwdPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
/etc/cronAudited Apr 17, 2026 · audit v1.0
Generated May 6, 2026
An enterprise deploys a custom AI agent skill marketplace for internal use. Before any employee installs a skill from the marketplace, the Skill Vetter automatically scans the code for critical security threats like disk wipe or SSH key deletion, blocking installation if found. This ensures all internal skills meet security standards before reaching end users.
A cloud AI platform hosts a public skill store where developers submit skills. The platform integrates Skill Vetter into the submission pipeline to automatically check each skill for obfuscated code, credential access, and network exfiltration. Skills with medium-level warnings are flagged for manual review, while critical issues cause immediate rejection.
A developer manually installs a skill from an open-source repository on their local AI agent. They run the Skill Vetter's manual scanning command to inspect the code for dangerous bash commands, unauthorized file writes, and suspicious network calls. The tool provides a clear verdict with warnings, allowing informed installation decisions.
A devops team builds an AI assistant for their company's support team. They integrate Skill Vetter as a pre-commit hook in their CI/CD pipeline for skill repositories. Any code change that introduces a critical severity finding blocks the build, ensuring all skill updates are security-vetted before deployment.
Offer Skill Vetter as a premium add-on for enterprise AI platforms that require pre-installation skill security scanning. Revenue is generated through annual licensing per agent or per seat, with tiered pricing based on number of skills scanned per month.
Provide the Skill Vetter as an API service for AI skill marketplaces to integrate into their submission pipeline. Revenue is based on per-scan pricing or a monthly flat fee for unlimited scans, plus a success fee for each skill that passes critical checks and gets published.
Offer a basic version with manual scanning and warning-only mode for free, while advanced features like automatic blocking, CI/CD integration, detailed audit logs, and custom blacklist patterns are available in a paid Pro tier. Revenue comes from monthly or yearly Pro subscriptions.
💬 Integration Tip
Integrate Skill Vetter as a pre-install hook in your AI agent framework's configuration (e.g., OpenClaw hooks) to automatically scan all skill installations and updates
Scored May 6, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...