Skill Vetter Optimized
🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化,添加了Python检查脚本和详细审查流程。 Skill: Skill Vetter Optimized Owner: confidentkai Summary: 🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化,添加了Python检查脚本和详细审查流程。 Tags: latest:2.0.0 Version history: v2.0.0 | 2026-04-15T03:52:01.620Z | user 优化版本:添加Python检查脚本、系统化审查清单、完善文档、清理代码结构 Archive index: Archive v2.0.0: 6 files, 8819 bytes Files: CHANGELOG.md (1029b), references/checklist.md (3294b), s
Rank
62
Safety
84
Downloads
1.3k
Updated
Oct 10, 2026
Version
2.0.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.3K downloadsadoption · observed Oct 10, 2026
- Latest release
- 2.0.0release · observed Apr 15, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s178zptfxy85cb8ggdvqzq875183hvjc:skill-vetter-optimized- Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/snapshot"
Documentation
CLAWHUB
9,674 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: skill-vetter-optimized version: 2.0.0 description: "🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化,添加了Python检查脚本和详细审查流程。" --- # Skill Vetter Optimized 🔒✨ **优化版技能审查器** - 基于原始skill-vetter优化增强 ## 🚀 优化亮点 ✅ **新增实用工具** - Python检查脚本快速分析技能目录 ✅ **系统化审查流程** - 四阶段审查清单 ✅ **详细文档** - 完整的审查指南和示例 ✅ **保持兼容** - 完全兼容原始审查协议 ✅ **性能优化** - 更快的审查流程 Security-first vetting protocol for AI agent skills. **Never install a skill without vetting it first.** ## When to Use - Before installing any skill from ClawdHub - Before running skills from GitHub repos - When evaluating skills shared by other agents - Anytime you're asked to install unknown code ## Vetting Protocol ### Step 1: Source Check ``` Questions to answer: - [ ] Where did this skill come from? - [ ] Is the author known/reputable? - [ ] How many downloads/stars does it have? - [ ] When was it last updated? - [ ] Are there reviews from other agents? ``` ### Step 2: Code Review (MANDATORY) Read ALL files in the skill. Check for these **RED FLAGS**: ``` 🚨 REJECT IMMEDIATELY IF YOU SEE: ───────────────────────────────────────── • curl/wget to unknown URLs • Sends data to external servers • Requests credentials/tokens/API keys • Reads ~/.ssh, ~/.aws, ~/.config without clear reason • Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md • Uses base64 decode on anything • Uses eval() or exec() with external input • Modifies system files outside workspace • Installs packages without listing them • Network calls to IPs instead of domains • Obfuscated code (compressed, encoded, minified) • Requests elevated/sudo permissions • Accesses browser cookies/sessions • Touches credential files ───────────────────────────────────────── ``` ### Step 3: Permission Scope ``` Evaluate: - [ ] What files does it need to read? - [ ] What files does it need to write? - [ ] What commands does it run? - [ ] Does it need network access? To where? - [ ] Is the scope minimal for its stated purpose? ``` ### Step 4: Risk Classification | Risk Level | Examples | Action | |------------|----------|--------| | 🟢 LOW | Notes, weather, formatting | Basic review, install OK | | 🟡 MEDIUM | File ops, browser, APIs | Full code review required | | 🔴 HIGH | Credentials, trading, system | Human approval required | | ⛔ EXTREME | Security configs, root access | Do NOT install | ## Output Format After vetting, produce this report: ``` SKILL VETTING REPORT ═══════════════════════════════════════ Skill: [name] Source: [ClawdHub / GitHub / other] Author: [username] Version: [version] ─────────────────────────────────────── METRICS: • Downloads/Stars: [count] • Last Updated: [date] • Files Reviewed: [count] ─────────────────────────────────────── RED FLAGS: [None / List them] PERMISSIONS NEEDED: • Files: [list or "None"] • Network: [list or "None"] • Commands: [list or "None"] ─────────────────────────────────────── RISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔
_meta.json
{
"ownerId": "kn71bmpaxztz381rsxj3mmsnqx82wys2",
"slug": "skill-vetter-optimized",
"version": "2.0.0",
"publishedAt": 1776225121620
}references/checklist.md
# 技能审查清单 ## 第一阶段:基本信息检查 ### 1. 来源验证 - [ ] **来源平台**: ClawHub / GitHub / 其他 - [ ] **作者信誉**: 已知作者 / 新作者 / 匿名 - [ ] **下载量/星标数**: 高(>1000) / 中(100-1000) / 低(<100) - [ ] **最后更新**: 最近(30天内) / 较近(90天内) / 很久以前 - [ ] **许可证**: MIT / Apache / GPL / 其他 / 无 ### 2. 文件结构检查 - [ ] **SKILL.md存在**: 是 / 否 - [ ] **描述清晰**: 是 / 否 - [ ] **版本号**: 有 / 无 - [ ] **目录结构合理**: 是 / 否 - [ ] **文件数量合理**: 是(≤20) / 否(>20) ## 第二阶段:代码安全审查 ### 3. 危险模式检查 (立即拒绝如果发现) - [ ] **下载并执行**: `curl | bash`, `wget | sh` - [ ] **远程代码执行**: `eval()`, `exec()` 带外部输入 - [ ] **数据外传**: 发送数据到外部服务器 - [ ] **凭证访问**: 读取SSH密钥、API密钥、密码文件 - [ ] **系统修改**: 修改系统文件、crontab、启动项 - [ ] **权限提升**: `sudo`, `chmod 777`, `setuid` - [ ] **混淆代码**: base64编码、压缩、混淆 ### 4. 权限范围评估 - [ ] **文件读取**: 明确列出需要读取的文件 - [ ] **文件写入**: 明确列出需要写入的文件 - [ ] **网络访问**: 明确列出需要访问的域名/IP - [ ] **命令执行**: 明确列出需要执行的命令 - [ ] **权限最小化**: 权限是否与功能匹配 ### 5. 依赖检查 - [ ] **依赖声明**: package.json / requirements.txt - [ ] **依赖安全性**: 已知漏洞检查 - [ ] **依赖必要性**: 所有依赖都是必要的吗? - [ ] **依赖来源**: 官方源 / 第三方源 ## 第三阶段:风险评估 ### 6. 风险等级评估 - **🟢 低风险**: 只读操作、格式化、信息展示 - **🟡 中风险**: 文件操作、网络请求、API调用 - **🔴 高风险**: 系统命令、凭证访问、数据修改 - **⛔ 极高风险**: 提权操作、持久化、外传数据 ### 7. 上下文评估 - [ ] **功能与权限匹配**: 是 / 否 - [ ] **错误处理**: 有 / 无 - [ ] **日志记录**: 有 / 无 - [ ] **测试用例**: 有 / 无 - [ ] **文档完整**: 是 / 否 ## 第四阶段:决策与记录 ### 8. 审查结论 - **✅ 安全可安装**: 通过所有检查,风险可控 - **⚠️ 谨慎安装**: 有中等风险,需要监控 - **❌ 拒绝安装**: 发现高风险或恶意行为 ### 9. 记录保存 - [ ] **审查报告**: 生成详细报告 - [ ] **决策理由**: 记录通过/拒绝的理由 - [ ] **时间戳**: 记录审查时间 - [ ] **审查者**: 记录审查者信息 ## 快速检查命令 ```bash # 使用辅助脚本检查 python3 /root/.openclaw/skills/skill-vetter/scripts/skill_checker.py /path/to/skill # 检查GitHub仓库信息 curl -s "https://api.github.com/repos/owner/repo" | jq '.stargazers_count, .forks_count, .updated_at' # 列出技能文件 find /path/to/skill -type f -name "*.py" -o -name "*.sh" -o -name "*.js" ``` ## 注意事项 1. **零信任原则**: 默认不信任,需要验证 2. **最小权限**: 只授予必要的权限 3. **持续监控**: 安装后仍需监控行为 4. **及时更新**: 关注安全更新和漏洞 5. **备份恢复**: 重要系统做好备份 --- *安全不是功能,而是基础。* 🔒
CHANGELOG.md
# 更新日志 - Skill Vetter ## v2.0.0 (2026-04-15) ### 优化内容 1. **清理无关文件** - 删除 `_meta.json` (安装时生成的元数据文件) 2. **新增实用工具** - `scripts/skill_checker.py` - Python辅助检查脚本 - `references/checklist.md` - 系统化审查清单 3. **更新SKILL.md** - 更新版本号至 2.0.0 - 优化描述信息 - 添加对新工具的说明 - 保持核心审查协议完整 ### 新增功能 1. **技能检查脚本** (`skill_checker.py`) - 快速检查技能目录结构 - 提取SKILL.md元数据 - 检测常见危险模式 - 生成初步风险评估 2. **系统化审查清单** (`checklist.md`) - 四阶段审查流程 - 详细的检查项目 - 风险评估标准 - 决策记录模板 ### 核心功能保留 - 安全优先的审查协议 - 红标检测清单 - 权限范围评估 - 风险等级分类 - 信任层次结构 ## v1.0.0 (原始版本) - 初始版本发布 - 基本的技能审查协议 - 安全优先的设计理念
skill-card.md
## Description: Skill Vetter Optimized helps agents and reviewers evaluate AI agent skills before installation by checking source trust, permission scope, red flags, and suspicious patterns. This skill is ready for commercial/non-commercial use. ## Publisher: [confidentkai](https://clawhub.ai/user/confidentkai) ### License/Terms of Use: MIT-0 ## Use Case: Developers, security reviewers, and agent operators use this skill to vet skills from ClawHub, GitHub, or other sources before installation. It provides a structured review protocol, checklist, and helper script for triaging obvious risk signals. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: The helper script may be mistaken for a complete security scanner. Mitigation: Use it only for quick triage and complete the documented full review before trusting a skill. Risk: The workflow is Chinese-oriented, which may reduce review accuracy for teams that cannot read the source language. Mitigation: Use qualified reviewers or translation support so all checklist items, findings, and verdicts are understood before installation. ## Reference(s): - [Skill Review Checklist](references/checklist.md) - [ClawHub Skill Page](https://clawhub.ai/confidentkai/skills/skill-vetter-optimized) - [Publisher Profile](https://clawhub.ai/user/confidentkai) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, guidance] **Output Format:** [Markdown with inline shell commands and checklist-style review output] **Output Parameters:** [1D] **Other Properties Related to Output:** [Produces a skill vetting report with source, author, version, red flags, permission needs, risk level, verdict, and notes.] ## Skill Version(s): 2.0.0 (source: frontmatter, changelog, server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/confidentkai/skills/skill-vetter-optimized",
"sourceUrl": "https://clawhub.ai/confidentkai/skills/skill-vetter-optimized",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T20:04:42.282Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T20:04:42.282Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.3K downloads",
"href": "https://clawhub.ai/confidentkai/skill-vetter-optimized",
"sourceUrl": "https://clawhub.ai/confidentkai/skill-vetter-optimized",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T20:04:42.282Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.0.0",
"href": "https://clawhub.ai/confidentkai/skill-vetter-optimized",
"sourceUrl": "https://clawhub.ai/confidentkai/skill-vetter-optimized",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-15T03:52:01.620Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.0.0",
"description": "优化版本:添加Python检查脚本、系统化审查清单、完善文档、清理代码结构",
"href": "https://clawhub.ai/confidentkai/skill-vetter-optimized",
"sourceUrl": "https://clawhub.ai/confidentkai/skill-vetter-optimized",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-15T03:52:01.620Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
