skill-vet在安装或运行 skill 前进行安全扫描,检查恶意代码、可疑命令和网络请求等潜在威胁。
Install via ClawdBot CLI:
clawdbot install luwinher/skill-vetGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Audited Apr 17, 2026 · audit v1.0
Generated Mar 20, 2026
Used by AI platform administrators to vet third-party skills before listing them in a marketplace, ensuring no malicious code is distributed to users. It scans for eval, exec, and hidden payloads to maintain platform integrity and user trust.
Employed by corporate IT teams to review custom AI skills developed internally or by vendors, checking for security risks like shell injection or data leaks before deployment in sensitive environments. This helps meet regulatory standards and prevent breaches.
Utilized by developers creating open-source AI skills to self-audit code for vulnerabilities such as hardcoded credentials or unsafe network requests, enhancing project credibility and safety for community adoption.
Applied in academic settings where students build AI skills, scanning for dangerous patterns like file deletions or process control to teach secure coding practices and protect lab infrastructure from accidental harm.
Used to inspect skills deployed on IoT or edge devices, detecting risks like unauthorized network requests or shell commands that could compromise device security and data privacy in connected environments.
Offer basic scanning for free to attract users, with premium features like detailed reports, API access, and priority support for enterprises. Revenue comes from subscription tiers and custom integrations.
Partner with AI platform providers to embed the vetting tool as a default security layer, generating revenue through licensing deals or revenue-sharing from marketplace transactions involving vetted skills.
Provide specialized security auditing services for organizations needing tailored scans or compliance checks, charging per project or on a retainer basis for ongoing support and risk assessments.
💬 Integration Tip
Integrate with CI/CD pipelines to automate security checks during skill development, and use the --verbose flag for detailed reports to streamline review processes.
Scored Jun 19, 2026
Control desktop applications on Windows — launch, close, focus, resize, move windows, simulate keyboard/mouse input, manage processes, control VSCode, read clipboard, and capture screen info. Use when the user wants to interact with any running program, switch windows, type text, press shortcuts, open files in VSCode, manage running processes, or get system display information.
Conduct rigorous, adversarial code reviews with zero tolerance for mediocrity. Use when users ask to "critically review" my code or a PR, "critique my code", "find issues in my code", or "what's wrong with this code". Identifies security holes, lazy patterns, edge case failures, and bad practices across Python, R, JavaScript/TypeScript, SQL, and front-end code. Scrutinizes error handling, type safety, performance, accessibility, and code quality. Provides structured feedback with severity tiers (Blocking, Required, Suggestions) and specific, actionable recommendations.
Coding style memory that adapts to your preferences, conventions, and patterns for consistent coding.
Pragmatic coding standards for writing clean, maintainable code — naming, functions, structure, anti-patterns, and pre-edit safety checks. Use when writing new code, refactoring existing code, reviewing code quality, or establishing coding standards.
Claude Code integration for OpenClaw. This skill provides interfaces to: - Query Claude Code documentation from https://code.claude.com/docs - Manage subagents and coding tasks - Execute AI-assisted coding workflows - Access best practices and common workflows Use this skill when users want to: - Get help with coding tasks - Query Claude Code documentation - Manage AI-assisted development workflows - Execute complex programming tasks
Plan, draft, version, and refine written content with enforced versioning and quality audits.