skill-vetterSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Install via ClawdBot CLI:
clawdbot install spclaudehome/skill-vetterGrade Excellent — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Uses known external API (expected, informational)
api.github.comAudited Apr 16, 2026 · audit v1.0
Generated Mar 1, 2026
Developers vetting third-party skill packages from GitHub before integrating them into their AI agents to prevent malicious code injection. This ensures security when extending agent capabilities with community contributions.
IT security teams evaluating skills from marketplaces like ClawdHub before deployment in corporate AI assistants. This mitigates risks of data breaches or unauthorized system access in regulated environments.
Researchers vetting experimental skills from shared repositories to safely test new functionalities without compromising lab systems or sensitive data. This supports secure collaboration in AI studies.
Consultants vetting skills for client projects to ensure compliance with security standards and avoid liability from installing untrusted code. This builds trust when customizing AI solutions for businesses.
Support teams vetting skills that handle customer data or integrate with CRM systems to prevent privacy violations. This maintains compliance with data protection regulations like GDPR.
Offer a premium vetting service with automated scans and human reviews for AI skills, charging monthly fees per agent or skill package. Revenue comes from enterprises needing compliance and risk management.
Partner with skill marketplaces like ClawdHub to provide vetting as a built-in feature, earning commissions on verified skill sales or listing fees. This monetizes trust in third-party platforms.
Provide custom vetting protocols, security audits, and training workshops for organizations deploying AI agents. Revenue is generated through project-based contracts and certification programs.
💬 Integration Tip
Integrate vetting into CI/CD pipelines to automatically scan skills before deployment, using the provided curl commands for GitHub checks.
Scored Apr 19, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.