skill-vetterSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Install via ClawdBot CLI:
clawdbot install spclaudehome/skill-vetterGrade Excellent — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Uses known external API (expected, informational)
api.github.comAudited Apr 16, 2026 · audit v1.0
Generated Mar 1, 2026
Developers vetting third-party skill packages from GitHub before integrating them into their AI agents to prevent malicious code injection. This ensures security when extending agent capabilities with community contributions.
IT security teams evaluating skills from marketplaces like ClawdHub before deployment in corporate AI assistants. This mitigates risks of data breaches or unauthorized system access in regulated environments.
Researchers vetting experimental skills from shared repositories to safely test new functionalities without compromising lab systems or sensitive data. This supports secure collaboration in AI studies.
Consultants vetting skills for client projects to ensure compliance with security standards and avoid liability from installing untrusted code. This builds trust when customizing AI solutions for businesses.
Support teams vetting skills that handle customer data or integrate with CRM systems to prevent privacy violations. This maintains compliance with data protection regulations like GDPR.
Offer a premium vetting service with automated scans and human reviews for AI skills, charging monthly fees per agent or skill package. Revenue comes from enterprises needing compliance and risk management.
Partner with skill marketplaces like ClawdHub to provide vetting as a built-in feature, earning commissions on verified skill sales or listing fees. This monetizes trust in third-party platforms.
Provide custom vetting protocols, security audits, and training workshops for organizations deploying AI agents. Revenue is generated through project-based contracts and certification programs.
💬 Integration Tip
Integrate vetting into CI/CD pipelines to automatically scan skills before deployment, using the provided curl commands for GitHub checks.
Scored Apr 19, 2026
Prompt injection defense. Detect and block malicious prompts, protect system instructions, sanitize user input.
Security check for ClawHub skills powered by Koi. Query the Clawdex API before installing any skill to verify it's safe.
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Security-first behavioral guidelines for cautious agent operation. Use this skill for ALL operations involving external resources, installations, credentials, or actions with external effects. Triggers on - any URL/link interaction, package installations, API key handling, sending emails/messages, social media posts, financial transactions, or any action that could expose data or have irreversible effects.
別駭我!基本安全檢測 — Security self-check for Clawdbot/Moltbot. Run a quick audit of your clawdbot.json to catch dangerous misconfigurations — exposed gateway, missing auth, open DM policy, weak tokens, loose file permissions. Auto-fix included. Invoke: "run a security check" or "幫我做安全檢查".
Command-line security analyzer for ClawHub skills. Run analyze-skill.sh to scan SKILL.md files for malicious patterns, credential leaks, and C2 infrastructure before installation. Includes threat intelligence database with 20+ detection patterns.