Skill Vetter
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... Skill: Skill Vetter Owner: asterisk622 Summary: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... Tags: latest:1.0.3 Version history: v1.0.3 | 2026-04-08T07:03:54.632Z | auto No changes detected in this version. - No file changes were made between versions 1.0.0 and 1.0.3. - The SKILL.md remains unchanged. -
Rank
62
Safety
84
Downloads
4.2k
Updated
Oct 9, 2026
Version
1.0.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 4.2K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 4.2K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.0.3release · observed Apr 8, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s173mcfqgv1rmb5wmeby2t2cfs83g23w:xiaoding-skill-vetter- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-asterisk622-xiaoding-skill-vetter/snapshot"
Documentation
CLAWHUB
15,687 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
--- name: skill-vetter version: 1.0.0 description: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns. --- # Skill Vetter 🔒 Security-first vetting protocol for AI agent skills. **Never install a skill without vetting it first.** ## When to Use - Before installing any skill from ClawdHub - Before running skills from GitHub repos - When evaluating skills shared by other agents - Anytime you're asked to install unknown code ## Vetting Protocol ### Step 1: Source Check ``` Questions to answer: - [ ] Where did this skill come from? - [ ] Is the author known/reputable? - [ ] How many downloads/stars does it have? - [ ] When was it last updated? - [ ] Are there reviews from other agents? ``` ### Step 2: Code Review (MANDATORY) Read ALL files in the skill. Check for these **RED FLAGS**: ``` 🚨 REJECT IMMEDIATELY IF YOU SEE: ───────────────────────────────────────── • curl/wget to unknown URLs • Sends data to external servers • Requests credentials/tokens/API keys • Reads ~/.ssh, ~/.aws, ~/.config without clear reason • Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md • Uses base64 decode on anything • Uses eval() or exec() with external input • Modifies system files outside workspace • Installs packages without listing them • Network calls to IPs instead of domains • Obfuscated code (compressed, encoded, minified) • Requests elevated/sudo permissions • Accesses browser cookies/sessions • Touches credential files ───────────────────────────────────────── ``` ### Step 3: Permission Scope ``` Evaluate: - [ ] What files does it need to read? - [ ] What files does it need to write? - [ ] What commands does it run? - [ ] Does it need network access? To where? - [ ] Is the scope minimal for its stated purpose? ``` ### Step 4: Risk Classification | Risk Level | Examples | Action | |------------|----------|--------| | 🟢 LOW | Notes, weather, formatting | Basic review, install OK | | 🟡 MEDIUM | File ops, browser, APIs | Full code review required | | 🔴 HIGH | Credentials, trading, system | Human approval required | | ⛔ EXTREME | Security configs, root access | Do NOT install | ## Output Format After vetting, produce this report: ``` SKILL VETTING REPORT ═══════════════════════════════════════ Skill: [name] Source: [ClawdHub / GitHub / other] Author: [username] Version: [version] ─────────────────────────────────────── METRICS: • Downloads/Stars: [count] • Last Updated: [date] • Files Reviewed: [count] ─────────────────────────────────────── RED FLAGS: [None / List them] PERMISSIONS NEEDED: • Files: [list or "None"] • Network: [list or "None"] • Commands: [list or "None"] ─────────────────────────────────────── RISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ EXTREME] VERDICT: [✅ SAFE TO INSTALL / ⚠️ INSTALL WITH CAUTION / ❌ DO NOT INSTALL] NOTES: [Any observations] ═══════════════════════════════════════ ``` ## Q
_meta.json
{
"ownerId": "kn799bx045t5rhs5ahf8fmpcc982hq1h",
"slug": "xiaoding-skill-vetter",
"version": "1.0.3",
"publishedAt": 1775631834632
}skill-card.md
## Description: Security-first skill vetting for AI agents before installing skills from ClawHub, GitHub, or other sources, checking for red flags, permission scope, and suspicious patterns. This skill is ready for commercial/non-commercial use. ## Publisher: [asterisk622](https://clawhub.ai/user/asterisk622) ### License/Terms of Use: MIT-0 ## Use Case: Developers and AI agent users use this skill to review unfamiliar agent skills before installation, checking source, permissions, red flags, and risk level. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The vetting report could contain incorrect or misleading security conclusions. Mitigation: Review the skill files and scanner evidence before acting on the verdict. Risk: Example GitHub curl commands could be pointed at an unintended repository or used with sensitive credentials. Mitigation: Confirm repository URLs before running commands and avoid pasting private tokens or credentials into the review process. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/asterisk622/skills/xiaoding-skill-vetter) ## Skill Output: **Output Type(s):** [Guidance, Markdown, Shell commands] **Output Format:** [Markdown checklist and vetting report with optional shell command examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Produces human-readable risk classification, verdict, permissions summary, and notes.] ## Skill Version(s): 1.0.3 (source: server release evidence; SKILL.md frontmatter lists 1.0.0) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/asterisk622/skills/xiaoding-skill-vetter",
"sourceUrl": "https://clawhub.ai/asterisk622/skills/xiaoding-skill-vetter",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T05:55:46.750Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-asterisk622-xiaoding-skill-vetter/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-asterisk622-xiaoding-skill-vetter/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T05:55:46.750Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "4.2K downloads",
"href": "https://clawhub.ai/asterisk622/xiaoding-skill-vetter",
"sourceUrl": "https://clawhub.ai/asterisk622/xiaoding-skill-vetter",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T05:55:46.750Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.0.3",
"href": "https://clawhub.ai/asterisk622/xiaoding-skill-vetter",
"sourceUrl": "https://clawhub.ai/asterisk622/xiaoding-skill-vetter",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-08T07:03:54.632Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-asterisk622-xiaoding-skill-vetter/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-asterisk622-xiaoding-skill-vetter/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.0.3",
"description": "No changes detected in this version. - No file changes were made between versions 1.0.0 and 1.0.3. - The SKILL.md remains unchanged. - No new features, fixes, or enhancements included.",
"href": "https://clawhub.ai/asterisk622/xiaoding-skill-vetter",
"sourceUrl": "https://clawhub.ai/asterisk622/xiaoding-skill-vetter",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-08T07:03:54.632Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
