Claim this agent
agentCLAWHUBUnverified

Skill Vetter V2 0.0.6

Verification-guided review workflow for inspecting skill packages before use or publication. Classifies risk and flags claims that exceed evidence. Does not...

OpenClaw

Rank

62

Safety

84

Downloads

4.3k

Updated

Oct 9, 2026

Version

0.0.6

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 4.3K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
4.3K downloadsadoption · observed Oct 9, 2026
Latest release
0.0.6release · observed Jul 4, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s1727xn24msgdvsrzx31kvyn9d83jk5t:skill-vetter-v2
  1. Install using `clawhub skill install s1727xn24msgdvsrzx31kvyn9d83jk5t:skill-vetter-v2` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/nutstrut/skill-vetter-v2 before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/snapshot"

Documentation

CLAWHUB

85,998 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---

name: skill-vetter-v2
description: Verification-guided review workflow for inspecting skill packages before use or publication. Classifies risk and flags claims that exceed evidence. Does not itself perform cryptographic verification, emit receipts, or prove a skill is safe.
metadata:
---------

# Skill Vetter v2

Skill Vetter v2 is a verification-guided review skill for inspecting Claude/OpenClaw skill packages before use or publication.

It helps identify risky instructions, unclear authority boundaries, hidden assumptions, undeclared egress, provenance gaps, and claims that exceed evidence.

This skill does not itself perform cryptographic verification, emit Settlement Attestation Receipts, or prove that a skill is safe. It is a structured review workflow.

For actual receipt verification, use SettlementWitness or DefaultVerifier MCP verify_receipt.

Category: verifiability-guided workflow skill.

Boundary: Skill Vetter v2 reviews claims and risk signals; it does not certify, approve, execute, or cryptographically verify artifacts.

---

Analyze skills before installation or use. Classify capabilities, risks, and trust dependencies with structured local review. Optionally verify the completed report with SettlementWitness.

This is a **packaged vetting skill**, not a thin wrapper. It preserves local inspection as the primary decision path and adds an optional verification layer for auditability.

## Data handling and trust

This skill defines a **local review workflow** with an optional verification step for the final report.

* Perform capability analysis and risk classification locally
* Do **not** send secrets, credentials, private keys, seed phrases, personal data, or full private repositories to any external service
* If optional verification is used, send only the minimum structured task data needed to validate the report
* Verification does **not** decide whether a skill is safe to install; it only validates that the vetting report matches the stated evaluation spec
* Identity is optional; no wallet access, account access, or credentials are required

## Core Principle

Never outsource the safety decision.

External systems may help verify that a report was produced correctly, but the actual judgment about whether a skill should be trusted remains local and reviewable.

## Quick Reference

| Situation                                      | Action                                                         |
| ---------------------------------------------- | -------------------------------------------------------------- |
| New skill from unknown source                  | Run full local vetting workflow                                |
| Skill asks for secrets or credentials          | Escalate risk immediately                                      |
| Skill writes outside workspace                 | Mark as high risk unless clearly justified                     |
| Skill calls external services                  | Classify trust dependen

README.md

# Skill Vetter v2

**Know what a skill does before you trust it.**

Skill Vetter v2 is a packaged safety-review skill for evaluating agent skills before installation or use. It preserves a local, review-first workflow and adds optional SettlementWitness verification for the finished report.

## Why this exists

Most agent skills are installed based on a short description and a guess.

That creates avoidable risk:
- hidden file access
- undisclosed network behavior
- silent trust in opaque external services
- credential exposure or workspace exfiltration

Skill Vetter v2 makes those risks visible before a skill is trusted.

## What it analyzes

Every target skill is reviewed across four areas:

### 1. Purpose and scope
Does the actual package match the stated purpose?

### 2. Install-time behavior
Does it write files, register hooks, install packages, or modify environment state?

### 3. Runtime behavior
Does it execute commands, access sensitive files, call external services, or handle data broadly?

### 4. Trust dependency
Does it rely on narrow and understandable external systems, or on opaque services that require blind trust?

## Output

The skill produces a structured report with:
- capability inventory
- install-time risk
- runtime risk
- trust dependency classification
- warnings and recommendations
- final verdict: `safe`, `caution`, or `unsafe`

## SettlementWitness integration

This skill does **not** delegate the safety decision.

Optional verification is used only after local review is complete.
It can validate that the final report matches a deterministic spec and provide receipt metadata for auditability.

Use it conservatively:
- send only structured report data
- never send secrets, credentials, personal data, or full private repositories
- treat PASS as evidence that the report matches the spec, not as a substitute for judgment

## Included package structure

```text
skill-vetter-v2/
├── SKILL.md
├── README.md
├── _meta.json
├── .learnings/
├── assets/
├── hooks/
├── references/
└── scripts/
```

## Scripts

### `scripts/scan-skill.sh`
Local helper that inventories a skill directory and flags suspicious patterns such as:
- credential access attempts
- network calls
- package installs
- obfuscated execution
- writes outside expected scope

### `scripts/activator.sh`
Reminder hook content for prompting a vetting pass before a skill is trusted.

### `scripts/error-detector.sh`
Reminder that suspicious outputs or failures discovered during review should be captured in the final report.

## Hook

The OpenClaw hook injects a short reminder during bootstrap:
- review the full package, not just `SKILL.md`
- classify risk before installation
- keep verdict decisions local
- optionally verify the final report

## Best use cases

- reviewing third-party skills before install
- auditing internal packaged skills
- comparing multiple skills that solve the same task
- enforcing trust boundaries in autonomous agent environments

## Design rules

_meta.json

{
  "ownerId": "kn71nqqcxyxyst7f2s3f2nzz0h80jf78",
  "slug": "skill-vetter-v2",
  "version": "0.0.6",
  "publishedAt": 1783148062918
}

references/examples.md

# Examples

## Example verdict: safe

A formatting skill that only reads local markdown files and rewrites output style.

- install risk: low
- runtime risk: low
- trust dependency: none
- verdict: safe

## Example verdict: caution

A deployment helper that writes config files, installs a package, and calls a documented API.

- install risk: medium
- runtime risk: medium
- trust dependency: transparent
- verdict: caution

## Example verdict: unsafe

A skill that requests credentials, reads memory files without explanation, and sends prompts to an opaque external service.

- install risk: high
- runtime risk: extreme
- trust dependency: opaque
- verdict: unsafe

## Verification example

After local review, define a deterministic verification spec such as:
- all required report fields present
- verdict supported by listed warnings
- prohibited data absent

Only verify the structured report payload.

references/openclaw-integration.md

# OpenClaw Integration

Skill Vetter v2 works as a normal packaged skill in OpenClaw.

## Install

```bash
clawdhub install skill-vetter-v2
```

Or copy manually:

```bash
cp -r skill-vetter-v2 ~/.openclaw/skills/
```

## Optional hook

```bash
cp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2
openclaw hooks enable skill-vetter-v2
```

## Suggested workflow

1. Open the target skill folder
2. Read `SKILL.md`, `README.md`, scripts, hooks, references, and metadata
3. Run the local helper:
   ```bash
   bash scripts/scan-skill.sh /path/to/target-skill
   ```
4. Write the structured report
5. Optionally verify the final report

## Design intent

The hook is advisory. It does not install, execute, or approve the target skill.
The verdict remains local.
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/nutstrut/skills/skill-vetter-v2",
      "sourceUrl": "https://clawhub.ai/nutstrut/skills/skill-vetter-v2",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T05:34:33.669Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T05:34:33.669Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "4.3K downloads",
      "href": "https://clawhub.ai/nutstrut/skill-vetter-v2",
      "sourceUrl": "https://clawhub.ai/nutstrut/skill-vetter-v2",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T05:34:33.669Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.0.6",
      "href": "https://clawhub.ai/nutstrut/skill-vetter-v2",
      "sourceUrl": "https://clawhub.ai/nutstrut/skill-vetter-v2",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-07-04T06:54:22.918Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.0.6",
      "description": "Claim precision correction: clarified skill is a verifiability-guided workflow aid. Does not perform cryptographic verification, emit Settlement Attestation Receipts, or prove skills are safe. Removed placeholder install URL. Added boundary, category, and claim-precision note sections.",
      "href": "https://clawhub.ai/nutstrut/skill-vetter-v2",
      "sourceUrl": "https://clawhub.ai/nutstrut/skill-vetter-v2",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-07-04T06:54:22.918Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to Skill Vetter V2 0.0.6 and adjacent AI workflows.