vivi-skill-vetterSecurity-first skill vetting for AI agents. Use BEFORE installing any skill from ClawHub, GitHub, or other sources. Checks for red flags, dangerous patterns,...
Install via ClawdBot CLI:
clawdbot install misscrx/vivi-skill-vetterGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
POST → https://evil.com/collectPotentially destructive shell commands in tool definitions
rm -rf /Accesses system directories or attempts privilege escalation
sudo rmGenerated Mar 16, 2026
Security teams use this skill to vet third-party skills before deployment in enterprise AI agents, ensuring compliance with security policies and preventing supply chain attacks. It automates detection of malicious code patterns like remote execution or data exfiltration, reducing manual review time.
Platforms like ClawHub integrate this skill to automatically scan user-submitted skills for safety, blocking harmful ones before they reach users. It helps maintain trust by providing security reports and flagging suspicious patterns in code repositories.
Educational institutions deploy this skill to vet skills used in student AI projects, preventing exposure to dangerous code and teaching secure coding practices. It allows instructors to review flagged items and explain risks in a controlled learning environment.
Open-source communities use this skill to screen contributions for AI agent skills, ensuring they don't contain hidden malware or privilege escalation attempts. It supports collaborative vetting workflows and maintains project integrity across distributed teams.
Offer this skill as part of a subscription-based security platform for AI agents, providing continuous updates and advanced scanning features. Revenue comes from monthly or annual licenses for teams and enterprises needing automated vetting.
Provide a free basic version of the skill with limited scans, and charge for premium features like detailed reports, API access, or integration with CI/CD pipelines. Revenue is generated from upgrades and enterprise support contracts.
Sell consulting services to customize the skill for specific industries or compliance needs, such as adding custom red flags or integrating with internal tools. Revenue comes from one-time project fees and ongoing maintenance agreements.
💬 Integration Tip
Integrate this skill into CI/CD pipelines to automatically vet skills during development, and use it as a pre-installation hook in AI agent platforms to block unsafe skills before execution.
Scored Jun 14, 2026
Calls external URL not in known-safe list
https://example.com/script.shUses known external API (expected, informational)
api.github.comAI Analysis
The skill definition explicitly lists patterns for credential harvesting (e.g., accessing ~/.ssh/id_rsa) and data exfiltration (e.g., sending data to external endpoints like https://evil.com/collect) as part of its 'Critical Red Flags' and 'Warning Patterns' categories. While the skill's stated purpose is security vetting, the detailed inclusion of these attack vectors as examples could serve as instructional material for malicious intent or be misapplied.
Audited Apr 18, 2026 · audit v1.0
Meta-skill for AI agent self-improvement. Analyzes runtime logs to detect error patterns, regressions, and inefficiencies, then generates structured improvem...
Stop waiting for prompts. Keep working.
Turn OpenClaw into a learning-loop agent with seeded workspace rules, skill promotion, reflective memory, and proactive maintenance.
Meta-agent skill for orchestrating complex tasks through autonomous sub-agents. Decomposes macro tasks into subtasks, spawns specialized sub-agents with dynamically generated SKILL.md files, coordinates file-based communication, consolidates results, and dissolves agents upon completion. MANDATORY TRIGGERS: orchestrate, multi-agent, decompose task, spawn agents, sub-agents, parallel agents, agent coordination, task breakdown, meta-agent, agent factory, delegate tasks
Complete toolkit for creating autonomous AI agents and managing Discord channels for OpenClaw. Use when setting up multi-agent systems, creating new agents, or managing Discord channel organization.
Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentic...