vettr
Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patte...
Rank
62
Safety
84
Downloads
1.8k
Updated
Oct 10, 2026
Version
2.0.4
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.8K downloadsadoption · observed Oct 10, 2026
- Latest release
- 2.0.4release · observed Jun 2, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s172xesqq5b1rv6mev9dafba8n83tdtk:vettr- Install using `clawhub skill install s172xesqq5b1rv6mev9dafba8n83tdtk:vettr` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/britrik/vettr before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/snapshot"
Documentation
CLAWHUB
25,896 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
skill.md
---
name: vettr
description: "Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting skills from ClawHub or untrusted sources."
version: "2.0.3"
author: britrik
tags: ["security", "scanner", "vetting", "analysis", "static-analysis"]
metadata:
openclaw:
requires:
env: []
bins:
- node
envVars: []
install:
- kind: node
package: "@openclaw/skill-vettr"
bins: []
emoji: "\U0001F6E1"
homepage: https://github.com/britrik/skill-vettr
notes: >
Core /skill:vet command requires only node. The /skill:vet-url command
additionally requires git, curl, and tar on PATH. The /skill:vet-clawhub
command requires the clawhub CLI. These are runtime-optional — the skill
loads and registers commands regardless of their presence.
---
# skill-vettr v2.0.3
Security scanner for third-party OpenClaw skills. Analyses source code, dependencies, and metadata before installation using tree-sitter AST parsing and regex pattern matching.
## Installation
```bash
npm install
```
This installs all Node.js dependencies, including tree-sitter `.wasm` grammar files required at runtime for AST-based analysis. The `.wasm` files are located in `node_modules` and must be present for the skill to function.
> ⚠️ **Install safety:** `npm install` runs dependency lifecycle scripts, which can execute arbitrary code. For stronger isolation, run `npm ci --ignore-scripts` — but note that tree-sitter native/WASM artifacts may not build, breaking AST analysis. Prefer installing inside a container or VM when possible.
## External Binaries
The `vet-url` and `vet-clawhub` commands invoke external binaries via `execSafe` (which uses `execFile` — no shell is spawned). Only the following commands are permitted:
| Binary | Used By | Purpose |
|--------|---------|---------|
| `git` | `vet-url` | Clone `.git` URLs (with hooks disabled) |
| `curl` | `vet-url` | Download archive URLs |
| `tar` | `vet-url` | Extract downloaded archives |
| `clawhub` | `vet-clawhub` | Fetch skills from ClawHub registry |
The `/skill:vet` command (local path vetting) requires only `node` and no external binaries.
## Commands
- `/skill:vet --path <directory>` — Vet a local skill directory
- `/skill:vet-url --url <https://...>` — Download and vet from URL
- `/skill:vet-clawhub --skill <slug>` — Fetch and vet from ClawHub
## Detection Categories
| Category | Method | Examples |
|----------|--------|----------|
| Code execution | AST | eval(), new Function(), vm.runInThisContext() |
| Shell injection | AST | exec(), execSync(), spawn("bash"), child_process imports |
| Dynamic require | AST | require(variable), require(templateString) |
| Prototype pollution | AST | __proto__ assignment |
| Prompt injection | Regex | Instruction override patterns, control tokens (in string literals) |
| Homoreadme.md
# skill-vettr v2.0.3
Static analysis security scanner for OpenClaw skills. Analyses code before installation to detect common threats.
## Quick Start
```bash
cd ~/.openclaw/skills/skill-scanner
npm install
npm run build
npm test
```
> ⚠️ `npm install` runs dependency lifecycle scripts (tree-sitter includes native builds). For stronger isolation, install inside a container or use `npm ci --ignore-scripts` (note: AST analysis may break without tree-sitter WASM artifacts).
## What It Does
skill-vettr scans a skill's source code, dependencies, and metadata for security issues. It uses:
- **tree-sitter AST parsing** for structural code analysis (eval, exec, spawn, dynamic require, prototype pollution, etc.)
- **Regex patterns** for things AST can't detect (prompt injection, homoglyph attacks, encoded function names)
- **Dependency analysis** for known malicious packages, suspicious prefixes, lifecycle scripts
- **Metadata analysis** for typosquatting (Levenshtein distance), dangerous permissions, blocked authors
## What It Doesn't Do
This is a heuristic scanner. It has inherent limitations:
- Cannot detect runtime-only behaviour (e.g., code that downloads malware at runtime from an innocuous-looking URL)
- AST queries can be evaded by sufficiently motivated attackers (e.g., multi-stage string construction)
- Only scans JS/TS code files — binary payloads, images, and other non-text files are skipped
- Does not sandbox or execute the target skill
- Malicious package lists are small and non-exhaustive
For high-security environments, combine with sandboxing and manual review.
## External Binaries
The `vet-url` and `vet-clawhub` commands invoke external binaries via `execSafe` (uses `execFile`, no shell spawned):
| Binary | Command | Purpose |
|--------|---------|---------|
| `git` | `vet-url` | Clone `.git` URLs (hooks disabled via `-c core.hooksPath=/dev/null`) |
| `curl` | `vet-url` | Download archive URLs (max 50 MB, 120s timeout) |
| `tar` | `vet-url` | Extract archives (`--no-same-owner --no-same-permissions`) |
| `clawhub` | `vet-clawhub` | Fetch skills from ClawHub registry |
The `/skill:vet` command (local path) requires only `node`. Ensure external binaries are trusted and available on `PATH` before using remote vetting commands.
## Usage
**Vet a local skill directory:**
```
/skill:vet --path ~/Downloads/suspicious-skill
```
**Vet from URL:**
```
/skill:vet-url --url https://github.com/org/skill/archive/main.tar.gz
```
**Vet from ClawHub:**
```
/skill:vet-clawhub --skill some-skill-name
```
## Configuration
Add to `~/.openclaw/config.json`:
```json
{
"skill-vettr": {
"maxRiskScore": 50,
"requireAuthor": true,
"autoVet": true,
"maxNetworkCalls": 5,
"allowedHosts": ["api.openai.com", "api.anthropic.com", "registry.npmjs.org"],
"blockedAuthors": [],
"blockedPackages": [],
"typosquatTargets": ["my-important-skill"]
}
}
```
| Field | Default | Description |
|-------|---------|-------------|
| _meta.json
{
"ownerId": "kn7ew5gbg17d6pmg1sjvqm6qe180p9e5",
"slug": "vettr",
"version": "2.0.4",
"publishedAt": 1780359963136
}skill-card.md
## Description: Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting skills from ClawHub or untrusted sources. This skill is ready for commercial/non-commercial use. ## Publisher: [britrik](https://clawhub.ai/user/britrik) ### License/Terms of Use: MIT-0 ## Use Case: Developers and security reviewers use this skill to evaluate third-party OpenClaw skills before installation. It reports static-analysis findings for risky code execution, shell use, dependency issues, typosquatting, prompt-injection patterns, and related metadata concerns. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Target skills can include ignore-file rules that hide files from local analysis and make scan results incomplete or misleading. Mitigation: Treat results as one input, inspect ignore rules, and manually review high-risk skills before relying on a pass or fail outcome. Risk: Remote URL vetting downloads untrusted content and can reach unintended network targets. Mitigation: Run remote vetting only in a disposable or network-restricted environment, especially for untrusted URLs. Risk: npm dependencies and external binaries used during remote vetting are part of the trust boundary. Mitigation: Verify the runtime environment, dependencies, and git, curl, tar, and clawhub binaries before using remote vetting workflows. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/britrik/skills/vettr) - [Project homepage](https://github.com/britrik/skill-vettr) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, configuration, guidance] **Output Format:** [Markdown-style text with risk summaries, findings, recommendations, usage messages, and configuration examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Reports are heuristic and should be reviewed before acting on installation decisions.] ## Skill Version(s): 2.0.4 (source: server release evidence; artifact frontmatter and package.json show 2.0.3) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
package-lock.json
{
"name": "@openclaw/skill-vettr",
"version": "2.0.3",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "@openclaw/skill-vettr",
"version": "2.0.3",
"dependencies": {
"tree-sitter-javascript": "^0.25.0",
"tree-sitter-typescript": "^0.23.2",
"web-tree-sitter": "^0.26.0",
"yaml": "^2.4.0"
},
"devDependencies": {
"@types/node": "^20.0.0",
"fast-check": "^4.5.3",
"typescript": "^5.3.0"
},
"engines": {
"node": ">=20.0.0"
}
},
"node_modules/@types/node": {
"version": "20.19.32",
"resolved": "https://registry.npmjs.org/@types/node/-/node-20.19.32.tgz",
"integrity": "sha512-Ez8QE4DMfhjjTsES9K2dwfV258qBui7qxUsoaixZDiTzbde4U12e1pXGNu/ECsUIOi5/zoCxAQxIhQnaUQ2VvA==",
"dev": true,
"license": "MIT",
"dependencies": {
"undici-types": "~6.21.0"
}
},
"node_modules/fast-check": {
"version": "4.5.3",
"resolved": "https://registry.npmjs.org/fast-check/-/fast-check-4.5.3.tgz",
"integrity": "sha512-IE9csY7lnhxBnA8g/WI5eg/hygA6MGWJMSNfFRrBlXUciADEhS1EDB0SIsMSvzubzIlOBbVITSsypCsW717poA==",
"dev": true,
"funding": [
{
"type": "individual",
"url": "https://github.com/sponsors/dubzzz"
},
{
"type": "opencollective",
"url": "https://opencollective.com/fast-check"
}
],
"license": "MIT",
"dependencies": {
"pure-rand": "^7.0.0"
},
"engines": {
"node": ">=12.17.0"
}
},
"node_modules/node-addon-api": {
"version": "8.5.0",
"resolved": "https://registry.npmjs.org/node-addon-api/-/node-addon-api-8.5.0.tgz",
"integrity": "sha512-/bRZty2mXUIFY/xU5HLvveNHlswNJej+RnxBjOMkidWfwZzgTbPG1E3K5TOxRLOR+5hX7bSofy8yf1hZevMS8A==",
"license": "MIT",
"engines": {
"node": "^18 || ^20 || >= 21"
}
},
"node_modules/node-gyp-build": {
"version": "4.8.4",
"resolved": "https://registry.npmjs.org/node-gyp-build/-/node-gyp-build-4.8.4.tgz",
"integrity": "sha512-LA4ZjwlnUblHVgq0oBF3Jl/6h/Nvs5fzBLwdEF4nuxnFdsfajde4WfxtJr3CaiH+F6ewcIB/q4jQ4UzPyid+CQ==",
"license": "MIT",
"bin": {
"node-gyp-build": "bin.js",
"node-gyp-build-optional": "optional.js",
"node-gyp-build-test": "build-test.js"
}
},
"node_modules/pure-rand": {
"version": "7.0.1",
"resolved": "https://registry.npmjs.org/pure-rand/-/pure-rand-7.0.1.tgz",
"integrity": "sha512-oTUZM/NAZS8p7ANR3SHh30kXB+zK2r2BPcEn/awJIbOvq82WoMN4p62AWWp3Hhw50G0xMsw1mhIBLqHw64EcNQ==",
"dev": true,
"funding": [
{
"type": "individual",
"url": "https://github.com/sponsors/dubzzz"
},
{
"type": "opencollective",
"url": "https://opencollective.com/fast-check"
}
],
"license": "MIT"
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/britrik/skills/vettr",
"sourceUrl": "https://clawhub.ai/britrik/skills/vettr",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T01:44:18.765Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T01:44:18.765Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.8K downloads",
"href": "https://clawhub.ai/britrik/vettr",
"sourceUrl": "https://clawhub.ai/britrik/vettr",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T01:44:18.765Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.0.4",
"href": "https://clawhub.ai/britrik/vettr",
"sourceUrl": "https://clawhub.ai/britrik/vettr",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-02T00:26:03.136Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.0.4",
"description": "Clean republish without test fixtures — scanner for third-party OpenClaw skills",
"href": "https://clawhub.ai/britrik/vettr",
"sourceUrl": "https://clawhub.ai/britrik/vettr",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-06-02T00:26:03.136Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
