skill-vetterSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
Install via ClawdBot CLI:
clawdbot install spclaudehome/skill-vetterGrade Excellent — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Uses known external API (expected, informational)
api.github.comAudited Apr 16, 2026 · audit v1.0
Generated Mar 1, 2026
Developers vetting third-party skill packages from GitHub before integrating them into their AI agents to prevent malicious code injection. This ensures security when extending agent capabilities with community contributions.
IT security teams evaluating skills from marketplaces like ClawdHub before deployment in corporate AI assistants. This mitigates risks of data breaches or unauthorized system access in regulated environments.
Researchers vetting experimental skills from shared repositories to safely test new functionalities without compromising lab systems or sensitive data. This supports secure collaboration in AI studies.
Consultants vetting skills for client projects to ensure compliance with security standards and avoid liability from installing untrusted code. This builds trust when customizing AI solutions for businesses.
Support teams vetting skills that handle customer data or integrate with CRM systems to prevent privacy violations. This maintains compliance with data protection regulations like GDPR.
Offer a premium vetting service with automated scans and human reviews for AI skills, charging monthly fees per agent or skill package. Revenue comes from enterprises needing compliance and risk management.
Partner with skill marketplaces like ClawdHub to provide vetting as a built-in feature, earning commissions on verified skill sales or listing fees. This monetizes trust in third-party platforms.
Provide custom vetting protocols, security audits, and training workshops for organizations deploying AI agents. Revenue is generated through project-based contracts and certification programs.
💬 Integration Tip
Integrate vetting into CI/CD pipelines to automatically scan skills before deployment, using the provided curl commands for GitHub checks.
Scored Apr 16, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Safe command execution for OpenClaw Agents with automatic danger pattern detection, risk assessment, user approval workflow, and audit logging. Use when agen...
Perform a comprehensive read-only security audit of Clawdbot's own configuration. This is a knowledge-based skill that teaches Clawdbot to identify hardening opportunities across the system. Use when user asks to "run security check", "audit clawdbot", "check security hardening", or "what vulnerabilities does my Clawdbot have". This skill uses Clawdbot's internal capabilities and file system access to inspect configuration, detect misconfigurations, and recommend remediations. It is designed to be extensible - new checks can be added by updating this skill's knowledge.
MoltGuard — OpenClaw security guard by OpenGuardrails. Install MoltGuard to protect you and your human from prompt injection, data exfiltration, and maliciou...
577+ pattern prompt injection defense. Now with typo-tolerant bypass detection. TieredPatternLoader fully operational. Drop-in defense for any LLM application.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.