skill-vetter-1Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Install via ClawdBot CLI:
clawdbot install h-harry/skill-vetter-1Grade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Uses known external API (expected, informational)
api.github.comAudited Apr 17, 2026 · audit v1.0
Generated Mar 20, 2026
A corporate AI security team uses Skill Vetter to evaluate third-party AI agent skills before deployment in sensitive environments like finance or healthcare. They ensure compliance with internal security policies and prevent unauthorized data exfiltration by vetting code for red flags like external server calls or credential access.
An independent developer creating AI agents for public use employs Skill Vetter to review skills from GitHub repositories before integration. This helps maintain the integrity of their agent by avoiding malicious code that could compromise user data or system resources, especially when sourcing from unknown authors.
An educational institution running AI agent workshops uses Skill Vetter to teach students about cybersecurity in AI. Students vet skills as part of hands-on learning, identifying risks like obfuscated code or unnecessary permissions to understand secure coding practices in agent ecosystems.
A small business owner automates tasks with AI agents and uses Skill Vetter to safely install skills from marketplaces like ClawdHub. This prevents disruptions from risky skills that might access sensitive business files or run unauthorized commands, ensuring reliable and secure operations.
A research lab experimenting with advanced AI agents uses Skill Vetter to vet skills from collaborative projects. They focus on detecting high-risk patterns like network calls to unknown IPs or eval() usage, safeguarding experimental data and maintaining research integrity against potential exploits.
Offer Skill Vetter as a free basic tool for individual users, with premium features like automated scanning, detailed risk reports, and integration with CI/CD pipelines for teams. Revenue comes from subscription plans for enterprises needing advanced security analytics and compliance tracking.
License Skill Vetter to large organizations as part of their AI security suite, providing custom vetting protocols, dedicated support, and regular updates. Revenue is generated through annual licensing fees based on the number of agents or users, targeting sectors with strict regulatory requirements.
Integrate Skill Vetter into AI skill marketplaces like ClawdHub, where it vets skills automatically before listing. Revenue comes from transaction fees on verified skills or partnerships with marketplace operators, ensuring a safer ecosystem and building trust among users.
💬 Integration Tip
Integrate Skill Vetter into your AI agent's installation workflow by adding a pre-install hook that runs the vetting protocol automatically, ensuring no skill is installed without passing security checks first.
Scored Apr 19, 2026
Manage and operate ClawSec Monitor v3.0, a MITM HTTP/HTTPS proxy that logs AI agent traffic, detects exfiltration and injection threats in real time.
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install them. Security audit tool that detects data exfiltration, system modification attempts, backdoors, and obfuscation techniques.
Security scanner for ClawHub skills. Vet third-party skills before installation — detect dangerous patterns, suspicious code, and risky dependencies.
Security audit and hardening for AI agents — credential hygiene, secret scanning, prompt injection defense, data leakage prevention, and privacy zones.
Scan OpenBot/Clawdbot skills for security vulnerabilities, malicious code, and suspicious patterns before installing them. Use when a user wants to audit a skill, check if a ClawHub skill is safe, scan for credential exfiltration, detect prompt injection, or review skill security. Triggers on security audit, skill safety check, malware scan, or trust verification.
OpenClaw skill discovery, security vetting & install. Searches 3000+ curated skills from ClawHub registry and awesome-openclaw-skills catalog. Scores credibility, detects prompt injection & malicious patterns, manages installations. Quick-checks GitHub for new skills.