Claim this agent
agentCLAWHUBUnverified

Skill Vetter

Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns. Skill: Skill Vetter Owner: spclaudehome Summary: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns. Tags: latest:1.0.0 Version history: v1.0.0 | 2026-01-31T12:43:49.632Z | user Initial release - Security-first skill vetting for AI agents Archive index: Archive v1.0.0: 3 files, 3425 bytes

OpenClaw

Rank

62

Safety

84

Downloads

252k

Updated

Jun 1, 2026

Version

1.0.0

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 252.2K downloads reported by the source. Last updated 6/1/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Adoption signal
252.2K downloadsadoption · observed Jun 1, 2026
Vendor
Clawhubvendor · observed May 30, 2026
Protocol compatibility
OpenClawcompatibility · observed May 30, 2026
Adoption signal
251K downloadsadoption · observed May 30, 2026
Latest release
1.0.0release · observed Jan 31, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install publishers:spclaudehome:skill-vetter
  1. Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-spclaudehome-skill-vetter/snapshot"

Documentation

CLAWHUB

6,748 characters of source documentation, loaded on request.

Extracted files

3 files captured from the source.

SKILL.md

---
name: skill-vetter
version: 1.0.0
description: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
---

# Skill Vetter 🔒

Security-first vetting protocol for AI agent skills. **Never install a skill without vetting it first.**

## When to Use

- Before installing any skill from ClawdHub
- Before running skills from GitHub repos
- When evaluating skills shared by other agents
- Anytime you're asked to install unknown code

## Vetting Protocol

### Step 1: Source Check

```
Questions to answer:
- [ ] Where did this skill come from?
- [ ] Is the author known/reputable?
- [ ] How many downloads/stars does it have?
- [ ] When was it last updated?
- [ ] Are there reviews from other agents?
```

### Step 2: Code Review (MANDATORY)

Read ALL files in the skill. Check for these **RED FLAGS**:

```
🚨 REJECT IMMEDIATELY IF YOU SEE:
─────────────────────────────────────────
• curl/wget to unknown URLs
• Sends data to external servers
• Requests credentials/tokens/API keys
• Reads ~/.ssh, ~/.aws, ~/.config without clear reason
• Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md
• Uses base64 decode on anything
• Uses eval() or exec() with external input
• Modifies system files outside workspace
• Installs packages without listing them
• Network calls to IPs instead of domains
• Obfuscated code (compressed, encoded, minified)
• Requests elevated/sudo permissions
• Accesses browser cookies/sessions
• Touches credential files
─────────────────────────────────────────
```

### Step 3: Permission Scope

```
Evaluate:
- [ ] What files does it need to read?
- [ ] What files does it need to write?
- [ ] What commands does it run?
- [ ] Does it need network access? To where?
- [ ] Is the scope minimal for its stated purpose?
```

### Step 4: Risk Classification

| Risk Level | Examples | Action |
|------------|----------|--------|
| 🟢 LOW | Notes, weather, formatting | Basic review, install OK |
| 🟡 MEDIUM | File ops, browser, APIs | Full code review required |
| 🔴 HIGH | Credentials, trading, system | Human approval required |
| ⛔ EXTREME | Security configs, root access | Do NOT install |

## Output Format

After vetting, produce this report:

```
SKILL VETTING REPORT
═══════════════════════════════════════
Skill: [name]
Source: [ClawdHub / GitHub / other]
Author: [username]
Version: [version]
───────────────────────────────────────
METRICS:
• Downloads/Stars: [count]
• Last Updated: [date]
• Files Reviewed: [count]
───────────────────────────────────────
RED FLAGS: [None / List them]

PERMISSIONS NEEDED:
• Files: [list or "None"]
• Network: [list or "None"]  
• Commands: [list or "None"]
───────────────────────────────────────
RISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ EXTREME]

VERDICT: [✅ SAFE TO INSTALL / ⚠️ INSTALL WITH CAUTION / ❌ DO NOT INSTALL]

NOTES: [Any observations]
═══════════════════════════════════════
```

## Q

_meta.json

{
  "ownerId": "kn71j6xbmpwfvx4c6y1ez8cd718081mg",
  "slug": "skill-vetter",
  "version": "1.0.0",
  "publishedAt": 1769863429632
}

skill-card.md

## Description: <br>
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns. <br>

This skill is ready for commercial/non-commercial use. <br>

## Publisher: <br>
[spclaudehome](https://clawhub.ai/user/spclaudehome) <br>

### License/Terms of Use: <br>


## Use Case: <br>
Developers and agent users use this skill to review unknown or third-party agent skills before installation, checking source reputation, file behavior, permissions, and suspicious patterns. <br>

### Deployment Geography for Use: <br>
Global <br>

## Known Risks and Mitigations: <br>
Risk: The skill includes example commands for fetching repository metadata and skill files from GitHub. <br>
Mitigation: Only run fetch commands against repositories you intend to review, verify placeholders before execution, and treat downloaded skill text as untrusted content. <br>
Risk: Manual vetting can miss suspicious behavior if reviewers skip files or rely on incomplete source information. <br>
Mitigation: Review every skill file, document permissions and red flags, and require human approval for high-risk behaviors such as credential access, elevated permissions, or system changes. <br>


## Reference(s): <br>
- [ClawHub Skill Page](https://clawhub.ai/spclaudehome/skill-vetter) <br>


## Skill Output: <br>
**Output Type(s):** [Text, Markdown, Shell commands, Guidance] <br>
**Output Format:** [Markdown checklist and vetting report with optional shell command examples] <br>
**Output Parameters:** [1D] <br>
**Other Properties Related to Output:** [Produces a structured security review with risk level, verdict, permissions, red flags, and notes.] <br>

## Skill Version(s): <br>
1.0.0 (source: frontmatter and server release evidence) <br>

## Ethical Considerations: <br>
Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>
Github OpenclewUpdated 4mo agoRank 65

@x1pay/langchain

LangChain/LangGraph tools for AI agent x402 payments on X1

OPENCLAW
Github OpenclewUpdated 4mo agoRank 65

oceanbus-langchain

LangChain tools for OceanBus — give your LangChain and CrewAI agents a global identity, encrypted messaging, and Yellow Pages service discovery with a single import.

OPENCLAWoceanbuslangchainlangchain-tools

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "252.2K downloads",
      "href": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceUrl": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-06-01T00:29:02.500Z",
      "isPublic": true
    },
    {
      "factKey": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "category": "vendor",
      "href": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceUrl": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-05-30T06:43:51.340Z",
      "isPublic": true,
      "metadata": {}
    },
    {
      "factKey": "protocols",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "category": "compatibility",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-spclaudehome-skill-vetter/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-spclaudehome-skill-vetter/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-05-30T06:43:51.340Z",
      "isPublic": true,
      "metadata": {}
    },
    {
      "factKey": "traction",
      "label": "Adoption signal",
      "value": "251K downloads",
      "category": "adoption",
      "href": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceUrl": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-05-30T06:43:51.340Z",
      "isPublic": true,
      "metadata": {}
    },
    {
      "factKey": "latest_release",
      "label": "Latest release",
      "value": "1.0.0",
      "category": "release",
      "href": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceUrl": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-01-31T12:43:49.632Z",
      "isPublic": true,
      "metadata": {}
    },
    {
      "factKey": "handshake_status",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "category": "security",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-spclaudehome-skill-vetter/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-spclaudehome-skill-vetter/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true,
      "metadata": {}
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 1.0.0",
      "description": "Initial release - Security-first skill vetting for AI agents",
      "href": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceUrl": "https://clawhub.ai/spclaudehome/skill-vetter",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-01-31T12:43:49.632Z",
      "isPublic": true,
      "metadata": {}
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to Skill Vetter and adjacent AI workflows.