xiaopi-skill-vetterSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Install via ClawdBot CLI:
clawdbot install a-din/xiaopi-skill-vetterGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Uses known external API (expected, informational)
api.github.comAudited Apr 16, 2026 · audit v1.0
Generated Oct 10, 2026
A developer discovers a popular AI agent skill on GitHub with 500 stars and wants to install it into their OpenClaw environment. They use the Skill Vetter to systematically review the skill's source, check for red flags like external network calls or credential access, and classify the risk before installing. This prevents supply-chain attacks and data exfiltration.
A platform operator responsible for curating a ClawdHub marketplace uses Skill Vetter to screen every submitted skill before it goes live. The vetting report provides a consistent risk score and permission breakdown, helping the operator enforce security policies and reject malicious submissions.
A security team at a financial institution mandates that any AI agent skill used internally must pass a vetting protocol. They use Skill Vetter to produce audit-ready reports, ensuring compliance with regulations and preventing skills that access sensitive files like ~/.ssh or trading APIs.
In a multi-agent system, one agent receives a skill recommendation from another agent. Before using it, the receiving agent runs Skill Vetter to verify the source, inspect the code for obfuscation, and check permission scope. This builds trust and prevents rogue skills from spreading.
Maintainers of an open-source AI skill repository integrate Skill Vetter into their CI/CD pipeline to automatically scan pull requests for dangerous patterns. Any skill requesting sudo or base64 decoding is flagged for human review, reducing maintainer workload and improving community safety.
Offer a basic version of Skill Vetter for free to individual developers, with core red-flag checks and risk classification. A premium tier provides automated scanning, detailed reports, and integration with CI/CD pipelines for teams.
Bundle Skill Vetter with other AI security tools (e.g., runtime monitoring, policy enforcement) as an enterprise-grade platform. Sell to organizations that need governance, audit trails, and compliance for AI agent deployments.
Partner with AI skill marketplaces (like ClawdHub) to provide official vetting and certification. Skills that pass the vetting receive a trusted badge, and the marketplace pays a fee per verified skill or a revenue share.
💬 Integration Tip
Integrate Skill Vetter as a pre-installation hook in your agent framework, and consider adding automated file fetching and parsing to streamline the code review steps.
Scored Oct 10, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...