agentCLAWHUBUnverified

vettr

Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patte...

OpenClaw

Rank

62

Safety

84

Downloads

1.8k

Updated

Oct 10, 2026

Version

2.0.4

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.8K downloadsadoption · observed Oct 10, 2026
Latest release
2.0.4release · observed Jun 2, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s172xesqq5b1rv6mev9dafba8n83tdtk:vettr
  1. Install using `clawhub skill install s172xesqq5b1rv6mev9dafba8n83tdtk:vettr` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/britrik/vettr before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/snapshot"

Documentation

CLAWHUB

25,896 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

skill.md

---
name: vettr
description: "Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting skills from ClawHub or untrusted sources."
version: "2.0.3"
author: britrik
tags: ["security", "scanner", "vetting", "analysis", "static-analysis"]
metadata:
  openclaw:
    requires:
      env: []
      bins:
        - node
    envVars: []
    install:
      - kind: node
        package: "@openclaw/skill-vettr"
        bins: []
    emoji: "\U0001F6E1"
    homepage: https://github.com/britrik/skill-vettr
    notes: >
      Core /skill:vet command requires only node. The /skill:vet-url command
      additionally requires git, curl, and tar on PATH. The /skill:vet-clawhub
      command requires the clawhub CLI. These are runtime-optional — the skill
      loads and registers commands regardless of their presence.
---

# skill-vettr v2.0.3

Security scanner for third-party OpenClaw skills. Analyses source code, dependencies, and metadata before installation using tree-sitter AST parsing and regex pattern matching.

## Installation

```bash
npm install
```

This installs all Node.js dependencies, including tree-sitter `.wasm` grammar files required at runtime for AST-based analysis. The `.wasm` files are located in `node_modules` and must be present for the skill to function.

> ⚠️ **Install safety:** `npm install` runs dependency lifecycle scripts, which can execute arbitrary code. For stronger isolation, run `npm ci --ignore-scripts` — but note that tree-sitter native/WASM artifacts may not build, breaking AST analysis. Prefer installing inside a container or VM when possible.

## External Binaries

The `vet-url` and `vet-clawhub` commands invoke external binaries via `execSafe` (which uses `execFile` — no shell is spawned). Only the following commands are permitted:

| Binary | Used By | Purpose |
|--------|---------|---------|
| `git` | `vet-url` | Clone `.git` URLs (with hooks disabled) |
| `curl` | `vet-url` | Download archive URLs |
| `tar` | `vet-url` | Extract downloaded archives |
| `clawhub` | `vet-clawhub` | Fetch skills from ClawHub registry |

The `/skill:vet` command (local path vetting) requires only `node` and no external binaries.

## Commands

- `/skill:vet --path <directory>` — Vet a local skill directory
- `/skill:vet-url --url <https://...>` — Download and vet from URL
- `/skill:vet-clawhub --skill <slug>` — Fetch and vet from ClawHub

## Detection Categories

| Category | Method | Examples |
|----------|--------|----------|
| Code execution | AST | eval(), new Function(), vm.runInThisContext() |
| Shell injection | AST | exec(), execSync(), spawn("bash"), child_process imports |
| Dynamic require | AST | require(variable), require(templateString) |
| Prototype pollution | AST | __proto__ assignment |
| Prompt injection | Regex | Instruction override patterns, control tokens (in string literals) |
| Homo

readme.md

# skill-vettr v2.0.3

Static analysis security scanner for OpenClaw skills. Analyses code before installation to detect common threats.

## Quick Start

```bash
cd ~/.openclaw/skills/skill-scanner
npm install
npm run build
npm test
```

> ⚠️ `npm install` runs dependency lifecycle scripts (tree-sitter includes native builds). For stronger isolation, install inside a container or use `npm ci --ignore-scripts` (note: AST analysis may break without tree-sitter WASM artifacts).

## What It Does

skill-vettr scans a skill's source code, dependencies, and metadata for security issues. It uses:

- **tree-sitter AST parsing** for structural code analysis (eval, exec, spawn, dynamic require, prototype pollution, etc.)
- **Regex patterns** for things AST can't detect (prompt injection, homoglyph attacks, encoded function names)
- **Dependency analysis** for known malicious packages, suspicious prefixes, lifecycle scripts
- **Metadata analysis** for typosquatting (Levenshtein distance), dangerous permissions, blocked authors

## What It Doesn't Do

This is a heuristic scanner. It has inherent limitations:

- Cannot detect runtime-only behaviour (e.g., code that downloads malware at runtime from an innocuous-looking URL)
- AST queries can be evaded by sufficiently motivated attackers (e.g., multi-stage string construction)
- Only scans JS/TS code files — binary payloads, images, and other non-text files are skipped
- Does not sandbox or execute the target skill
- Malicious package lists are small and non-exhaustive

For high-security environments, combine with sandboxing and manual review.

## External Binaries

The `vet-url` and `vet-clawhub` commands invoke external binaries via `execSafe` (uses `execFile`, no shell spawned):

| Binary | Command | Purpose |
|--------|---------|---------|
| `git` | `vet-url` | Clone `.git` URLs (hooks disabled via `-c core.hooksPath=/dev/null`) |
| `curl` | `vet-url` | Download archive URLs (max 50 MB, 120s timeout) |
| `tar` | `vet-url` | Extract archives (`--no-same-owner --no-same-permissions`) |
| `clawhub` | `vet-clawhub` | Fetch skills from ClawHub registry |

The `/skill:vet` command (local path) requires only `node`. Ensure external binaries are trusted and available on `PATH` before using remote vetting commands.

## Usage

**Vet a local skill directory:**
```
/skill:vet --path ~/Downloads/suspicious-skill
```

**Vet from URL:**
```
/skill:vet-url --url https://github.com/org/skill/archive/main.tar.gz
```

**Vet from ClawHub:**
```
/skill:vet-clawhub --skill some-skill-name
```

## Configuration

Add to `~/.openclaw/config.json`:

```json
{
  "skill-vettr": {
    "maxRiskScore": 50,
    "requireAuthor": true,
    "autoVet": true,
    "maxNetworkCalls": 5,
    "allowedHosts": ["api.openai.com", "api.anthropic.com", "registry.npmjs.org"],
    "blockedAuthors": [],
    "blockedPackages": [],
    "typosquatTargets": ["my-important-skill"]
  }
}
```

| Field | Default | Description |
|-------|---------|-------------|
| 

_meta.json

{
  "ownerId": "kn7ew5gbg17d6pmg1sjvqm6qe180p9e5",
  "slug": "vettr",
  "version": "2.0.4",
  "publishedAt": 1780359963136
}

skill-card.md

## Description:

Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting skills from ClawHub or untrusted sources.

This skill is ready for commercial/non-commercial use.

## Publisher:

[britrik](https://clawhub.ai/user/britrik)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and security reviewers use this skill to evaluate third-party OpenClaw skills before installation. It reports static-analysis findings for risky code execution, shell use, dependency issues, typosquatting, prompt-injection patterns, and related metadata concerns.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Target skills can include ignore-file rules that hide files from local analysis and make scan results incomplete or misleading.

Mitigation: Treat results as one input, inspect ignore rules, and manually review high-risk skills before relying on a pass or fail outcome.

Risk: Remote URL vetting downloads untrusted content and can reach unintended network targets.

Mitigation: Run remote vetting only in a disposable or network-restricted environment, especially for untrusted URLs.

Risk: npm dependencies and external binaries used during remote vetting are part of the trust boundary.

Mitigation: Verify the runtime environment, dependencies, and git, curl, tar, and clawhub binaries before using remote vetting workflows.

## Reference(s):

- [ClawHub skill page](https://clawhub.ai/britrik/skills/vettr)
- [Project homepage](https://github.com/britrik/skill-vettr)

## Skill Output:

**Output Type(s):** [text, markdown, shell commands, configuration, guidance]

**Output Format:** [Markdown-style text with risk summaries, findings, recommendations, usage messages, and configuration examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Reports are heuristic and should be reviewed before acting on installation decisions.]

## Skill Version(s):

2.0.4 (source: server release evidence; artifact frontmatter and package.json show 2.0.3)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.

package-lock.json

{
  "name": "@openclaw/skill-vettr",
  "version": "2.0.3",
  "lockfileVersion": 3,
  "requires": true,
  "packages": {
    "": {
      "name": "@openclaw/skill-vettr",
      "version": "2.0.3",
      "dependencies": {
        "tree-sitter-javascript": "^0.25.0",
        "tree-sitter-typescript": "^0.23.2",
        "web-tree-sitter": "^0.26.0",
        "yaml": "^2.4.0"
      },
      "devDependencies": {
        "@types/node": "^20.0.0",
        "fast-check": "^4.5.3",
        "typescript": "^5.3.0"
      },
      "engines": {
        "node": ">=20.0.0"
      }
    },
    "node_modules/@types/node": {
      "version": "20.19.32",
      "resolved": "https://registry.npmjs.org/@types/node/-/node-20.19.32.tgz",
      "integrity": "sha512-Ez8QE4DMfhjjTsES9K2dwfV258qBui7qxUsoaixZDiTzbde4U12e1pXGNu/ECsUIOi5/zoCxAQxIhQnaUQ2VvA==",
      "dev": true,
      "license": "MIT",
      "dependencies": {
        "undici-types": "~6.21.0"
      }
    },
    "node_modules/fast-check": {
      "version": "4.5.3",
      "resolved": "https://registry.npmjs.org/fast-check/-/fast-check-4.5.3.tgz",
      "integrity": "sha512-IE9csY7lnhxBnA8g/WI5eg/hygA6MGWJMSNfFRrBlXUciADEhS1EDB0SIsMSvzubzIlOBbVITSsypCsW717poA==",
      "dev": true,
      "funding": [
        {
          "type": "individual",
          "url": "https://github.com/sponsors/dubzzz"
        },
        {
          "type": "opencollective",
          "url": "https://opencollective.com/fast-check"
        }
      ],
      "license": "MIT",
      "dependencies": {
        "pure-rand": "^7.0.0"
      },
      "engines": {
        "node": ">=12.17.0"
      }
    },
    "node_modules/node-addon-api": {
      "version": "8.5.0",
      "resolved": "https://registry.npmjs.org/node-addon-api/-/node-addon-api-8.5.0.tgz",
      "integrity": "sha512-/bRZty2mXUIFY/xU5HLvveNHlswNJej+RnxBjOMkidWfwZzgTbPG1E3K5TOxRLOR+5hX7bSofy8yf1hZevMS8A==",
      "license": "MIT",
      "engines": {
        "node": "^18 || ^20 || >= 21"
      }
    },
    "node_modules/node-gyp-build": {
      "version": "4.8.4",
      "resolved": "https://registry.npmjs.org/node-gyp-build/-/node-gyp-build-4.8.4.tgz",
      "integrity": "sha512-LA4ZjwlnUblHVgq0oBF3Jl/6h/Nvs5fzBLwdEF4nuxnFdsfajde4WfxtJr3CaiH+F6ewcIB/q4jQ4UzPyid+CQ==",
      "license": "MIT",
      "bin": {
        "node-gyp-build": "bin.js",
        "node-gyp-build-optional": "optional.js",
        "node-gyp-build-test": "build-test.js"
      }
    },
    "node_modules/pure-rand": {
      "version": "7.0.1",
      "resolved": "https://registry.npmjs.org/pure-rand/-/pure-rand-7.0.1.tgz",
      "integrity": "sha512-oTUZM/NAZS8p7ANR3SHh30kXB+zK2r2BPcEn/awJIbOvq82WoMN4p62AWWp3Hhw50G0xMsw1mhIBLqHw64EcNQ==",
      "dev": true,
      "funding": [
        {
          "type": "individual",
          "url": "https://github.com/sponsors/dubzzz"
        },
        {
          "type": "opencollective",
          "url": "https://opencollective.com/fast-check"
        }
      ],
      "license": "MIT"
   
Github ReposUpdated 12h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/britrik/skills/vettr",
      "sourceUrl": "https://clawhub.ai/britrik/skills/vettr",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T01:44:18.765Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T01:44:18.765Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.8K downloads",
      "href": "https://clawhub.ai/britrik/vettr",
      "sourceUrl": "https://clawhub.ai/britrik/vettr",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T01:44:18.765Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.0.4",
      "href": "https://clawhub.ai/britrik/vettr",
      "sourceUrl": "https://clawhub.ai/britrik/vettr",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-02T00:26:03.136Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.0.4",
      "description": "Clean republish without test fixtures — scanner for third-party OpenClaw skills",
      "href": "https://clawhub.ai/britrik/vettr",
      "sourceUrl": "https://clawhub.ai/britrik/vettr",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-06-02T00:26:03.136Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to vettr and adjacent AI workflows.