skill-vetter-guideGuide for vetting third-party OpenClaw skills before installation using the Skill Vetter security protocol. Use when installing any third-party skill, auditi...
Install via ClawdBot CLI:
clawdbot install vibesparkingai/skill-vetter-guideGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Audited Apr 17, 2026 · audit v1.0
Generated Sep 29, 2026
An individual developer or IT admin spins up a fresh OpenClaw instance and wants to install productivity and automation skills. Using this guide, they vet each third-party skill before installation, review all files for red flags like outbound calls or credential access, and set up the Skill Vetter skill globally. This prevents supply chain compromises from the very first install.
A company rolling out OpenClaw across departments needs a governance process for third-party skills. The security team uses this guide to create a mandatory AGENTS.md rule, train employees on the vetting SOP, and enforce human approval for high-risk skills. This ensures company data and credentials are protected from untrusted skill code.
An ops engineer manages several OpenClaw instances with dozens of installed skills. They follow the guide's periodic audit workflow: a cron-based quick scan every four hours and a weekly full re-review, checking for changed code or new red flags. Timestamped audit reports provide an ongoing compliance trail.
A moderator of a skill-sharing community on ClawHub or GitHub wants to ensure submitted skills are safe. They apply the Skill Vetter protocol and report template to review submissions, assign risk levels, and publish vetting outcomes. This builds trust and reduces the chance of malicious skills spreading.
A freelance security consultant offers OpenClaw skill audits and hardening services to clients. Using the Skill Vetter guide's report templates, audit formats, and multi-instance recommendations, they deliver professional assessments with risk grades and remediation advice. This positions them as a trusted expert in AI agent security.
The Skill Vetter skill itself is free and open-source on ClawHub/GitHub, driving adoption. Enterprises pay for add-ons such as centralized audit dashboards, automated compliance reports, and priority support. Revenue comes from subscription tiers and enterprise licenses.
A provider runs scheduled Skill Vetter audits for clients' OpenClaw fleets, delivers vetting reports, and maintains audit trails across multiple machines. Clients outsource the recurring operational burden while retaining human approval for high-risk decisions. Revenue is charged per instance or per audit cycle.
An organization offers courses and certifications teaching the Skill Vetter SOP, red-flag detection, and secure AGENTS.md enforcement. Companies purchase team training to meet internal security compliance requirements. Revenue comes from course sales, certification exams, and corporate workshops.
💬 Integration Tip
Add the Skill Security Rule block to your AGENTS.md immediately so every agent enforces vet-before-install, and schedule the 4-hour quick scan via cron for continuous protection.
Scored Sep 29, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...