{"id":"20c06e17-b561-40b4-9c28-f0a5b666be6a","entityType":"agent","slug":"clawhub-britrik-vettr","name":"vettr","canonicalUrl":"https://www.xpersona.co/agent/clawhub-britrik-vettr","canonicalPath":"/agent/clawhub-britrik-vettr","generatedAt":"2026-10-10T08:45:26.345Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T01:44:18.765Z","emptyReason":null},"description":"Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patte...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s172xesqq5b1rv6mev9dafba8n83tdtk:vettr","sourceUrl":"https://clawhub.ai/britrik/vettr","homepage":"https://clawhub.ai/britrik/skills/vettr","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/britrik/vettr","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/britrik/skills/vettr","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":65,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"vettr technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T01:44:18.765Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T01:44:18.765Z","emptyReason":null},"stars":null,"forks":null,"downloads":1798,"packageName":null,"latestVersion":"2.0.4","tractionLabel":"1.8K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T01:44:18.765Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T01:44:18.765Z","lastCrawledAt":"2026-10-10T01:44:18.765Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T01:44:18.765Z","lastVerifiedAt":null,"highlights":[{"version":"2.0.4","createdAt":"2026-06-02T00:26:03.136Z","changelog":"Clean republish without test fixtures — scanner for third-party OpenClaw skills","fileCount":19,"zipByteSize":33968}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s172xesqq5b1rv6mev9dafba8n83tdtk:vettr","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s172xesqq5b1rv6mev9dafba8n83tdtk:vettr` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/britrik/vettr before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T08:45:26.345Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-britrik-vettr/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T01:44:18.765Z","emptyReason":null},"readme":"Skill: vettr\n\nOwner: britrik\n\nSummary: Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patte...\n\nTags: latest:2.0.4\n\nVersion history:\n\nv2.0.4 | 2026-06-02T00:26:03.136Z | user\n\nClean republish without test fixtures — scanner for third-party OpenClaw skills\n\nArchive index:\n\nArchive v2.0.4: 19 files, 33968 bytes\n\nFiles: .github/workflows/ai-review.yml (3247b), package-lock.json (6529b), package.json (545b), readme.md (5489b), skill-card.md (2421b), skill.md (6385b), src/analyzers/ast-analyzer.ts (11498b), src/analyzers/dependency-analyzer.ts (3662b), src/analyzers/metadata-analyzer.ts (3399b), src/analyzers/pattern-analyzer.ts (8348b), src/index.ts (13086b), src/openclaw-sdk.d.ts (1641b), src/types.ts (2274b), src/utils/exec-safe.ts (1987b), src/utils/levenshtein.ts (878b), src/utils/sanitise.ts (2580b), src/utils/vettrignore.ts (3107b), src/vettr-engine.ts (13373b), _meta.json (124b)\n\nFile v2.0.4:skill.md\n\n---\nname: vettr\ndescription: \"Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting skills from ClawHub or untrusted sources.\"\nversion: \"2.0.3\"\nauthor: britrik\ntags: [\"security\", \"scanner\", \"vetting\", \"analysis\", \"static-analysis\"]\nmetadata:\n  openclaw:\n    requires:\n      env: []\n      bins:\n        - node\n    envVars: []\n    install:\n      - kind: node\n        package: \"@openclaw/skill-vettr\"\n        bins: []\n    emoji: \"\\U0001F6E1\"\n    homepage: https://github.com/britrik/skill-vettr\n    notes: >\n      Core /skill:vet command requires only node. The /skill:vet-url command\n      additionally requires git, curl, and tar on PATH. The /skill:vet-clawhub\n      command requires the clawhub CLI. These are runtime-optional — the skill\n      loads and registers commands regardless of their presence.\n---\n\n# skill-vettr v2.0.3\n\nSecurity scanner for third-party OpenClaw skills. Analyses source code, dependencies, and metadata before installation using tree-sitter AST parsing and regex pattern matching.\n\n## Installation\n\n```bash\nnpm install\n```\n\nThis installs all Node.js dependencies, including tree-sitter `.wasm` grammar files required at runtime for AST-based analysis. The `.wasm` files are located in `node_modules` and must be present for the skill to function.\n\n> ⚠️ **Install safety:** `npm install` runs dependency lifecycle scripts, which can execute arbitrary code. For stronger isolation, run `npm ci --ignore-scripts` — but note that tree-sitter native/WASM artifacts may not build, breaking AST analysis. Prefer installing inside a container or VM when possible.\n\n## External Binaries\n\nThe `vet-url` and `vet-clawhub` commands invoke external binaries via `execSafe` (which uses `execFile` — no shell is spawned). Only the following commands are permitted:\n\n| Binary | Used By | Purpose |\n|--------|---------|---------|\n| `git` | `vet-url` | Clone `.git` URLs (with hooks disabled) |\n| `curl` | `vet-url` | Download archive URLs |\n| `tar` | `vet-url` | Extract downloaded archives |\n| `clawhub` | `vet-clawhub` | Fetch skills from ClawHub registry |\n\nThe `/skill:vet` command (local path vetting) requires only `node` and no external binaries.\n\n## Commands\n\n- `/skill:vet --path <directory>` — Vet a local skill directory\n- `/skill:vet-url --url <https://...>` — Download and vet from URL\n- `/skill:vet-clawhub --skill <slug>` — Fetch and vet from ClawHub\n\n## Detection Categories\n\n| Category | Method | Examples |\n|----------|--------|----------|\n| Code execution | AST | eval(), new Function(), vm.runInThisContext() |\n| Shell injection | AST | exec(), execSync(), spawn(\"bash\"), child_process imports |\n| Dynamic require | AST | require(variable), require(templateString) |\n| Prototype pollution | AST | __proto__ assignment |\n| Prompt injection | Regex | Instruction override patterns, control tokens (in string literals) |\n| Homoglyph attacks | Regex | Cyrillic/Greek lookalike characters in identifiers |\n| Encoded names | Regex | Unicode/hex-escaped \"eval\", \"exec\" |\n| Credential paths | Regex | Cloud and SSH credential directory references, system credential store access |\n| Network calls | AST | fetch() with literal URLs (checked against allowlist) |\n| Malicious deps | Config | Known bad packages, lifecycle scripts, git/http deps |\n| Typosquatting | Levenshtein | Skill names within edit distance 2 of targets |\n| Dangerous permissions | Config | shell:exec, credentials:read in SKILL.md |\n\n## Limitations\n\n> ⚠️ **This is a heuristic scanner with inherent limitations. It cannot guarantee safety.**\n\n- **Static analysis only** — Cannot detect runtime behaviour (e.g., code that fetches malware after install)\n- **Evasion possible** — Sophisticated obfuscation or multi-stage string construction can evade detection\n- **JS/TS only** — Binary payloads, images, and non-text files are skipped\n- **Limited network detection** — Only detects `fetch()` with literal URL strings; misses axios, http module, dynamic URLs\n- **No sandboxing** — Does not execute or isolate target code\n- **Comment scanning** — Prompt injection detection scans string literals, not comments\n- **Filesystem scope** — `vet-url` downloads and extracts remote archives into a temp directory; `vet` accepts paths under `os.tmpdir()`, `~/.openclaw`, and `~/Downloads` by default. Set `allowCwd: true` in config to also permit `process.cwd()` (see Configuration below)\n- **External binary trust** — `vet-url` and `vet-clawhub` invoke `git`, `curl`, `tar`, and `clawhub` via `execFile`. These binaries must be trusted and present on `PATH`\n\nFor high-security environments, combine with sandboxing, network isolation, and manual source review. Run inside a disposable container when vetting untrusted URLs.\n\n## Configuration\n\n### `allowCwd`\n\nBy default, `process.cwd()` is **not** included in the set of allowed vetting roots. The default allowed roots are:\n\n- `os.tmpdir()`\n- `~/.openclaw`\n- `~/Downloads`\n\nTo allow vetting paths under the current working directory, set `allowCwd: true` in your vetting config:\n\n```json\n{\n  \"allowCwd\": true\n}\n```\n\n> ⚠️ **Security implication:** Enabling `allowCwd` means the scanner will accept any path under the directory you launched it from. If you run from `/` or `$HOME`, this effectively grants access to your entire filesystem. Only enable this when running from a scoped project directory or inside a container.\n\n## `.vettrignore`\n\nPlace a `.vettrignore` file in the root of the skill directory being scanned to exclude files or directories from analysis. This is useful for excluding test fixtures that contain deliberate malicious patterns.\n\n### Format\n\n- One glob pattern per line\n- Lines starting with `#` are comments\n- Empty lines are ignored\n- Patterns ending with `/` match entire directories\n- `*` matches any sequence of non-separator characters\n- `**` matches any sequence including path separators (recursive)\n- `?` matches a single non-separator character\n\n### Example\n\n```\n# Exclude test fixtures containing deliberate prompt injection vectors\ntest/fixtures/\n\n# Exclude generated files\ndist/\n*.min.js\n```\n\nIf the `.vettrignore` file is unreadable or contains invalid UTF-8, the engine logs an INFO-level warning and proceeds with a full scan.\n\nFile v2.0.4:readme.md\n\n# skill-vettr v2.0.3\n\nStatic analysis security scanner for OpenClaw skills. Analyses code before installation to detect common threats.\n\n## Quick Start\n\n```bash\ncd ~/.openclaw/skills/skill-scanner\nnpm install\nnpm run build\nnpm test\n```\n\n> ⚠️ `npm install` runs dependency lifecycle scripts (tree-sitter includes native builds). For stronger isolation, install inside a container or use `npm ci --ignore-scripts` (note: AST analysis may break without tree-sitter WASM artifacts).\n\n## What It Does\n\nskill-vettr scans a skill's source code, dependencies, and metadata for security issues. It uses:\n\n- **tree-sitter AST parsing** for structural code analysis (eval, exec, spawn, dynamic require, prototype pollution, etc.)\n- **Regex patterns** for things AST can't detect (prompt injection, homoglyph attacks, encoded function names)\n- **Dependency analysis** for known malicious packages, suspicious prefixes, lifecycle scripts\n- **Metadata analysis** for typosquatting (Levenshtein distance), dangerous permissions, blocked authors\n\n## What It Doesn't Do\n\nThis is a heuristic scanner. It has inherent limitations:\n\n- Cannot detect runtime-only behaviour (e.g., code that downloads malware at runtime from an innocuous-looking URL)\n- AST queries can be evaded by sufficiently motivated attackers (e.g., multi-stage string construction)\n- Only scans JS/TS code files — binary payloads, images, and other non-text files are skipped\n- Does not sandbox or execute the target skill\n- Malicious package lists are small and non-exhaustive\n\nFor high-security environments, combine with sandboxing and manual review.\n\n## External Binaries\n\nThe `vet-url` and `vet-clawhub` commands invoke external binaries via `execSafe` (uses `execFile`, no shell spawned):\n\n| Binary | Command | Purpose |\n|--------|---------|---------|\n| `git` | `vet-url` | Clone `.git` URLs (hooks disabled via `-c core.hooksPath=/dev/null`) |\n| `curl` | `vet-url` | Download archive URLs (max 50 MB, 120s timeout) |\n| `tar` | `vet-url` | Extract archives (`--no-same-owner --no-same-permissions`) |\n| `clawhub` | `vet-clawhub` | Fetch skills from ClawHub registry |\n\nThe `/skill:vet` command (local path) requires only `node`. Ensure external binaries are trusted and available on `PATH` before using remote vetting commands.\n\n## Usage\n\n**Vet a local skill directory:**\n```\n/skill:vet --path ~/Downloads/suspicious-skill\n```\n\n**Vet from URL:**\n```\n/skill:vet-url --url https://github.com/org/skill/archive/main.tar.gz\n```\n\n**Vet from ClawHub:**\n```\n/skill:vet-clawhub --skill some-skill-name\n```\n\n## Configuration\n\nAdd to `~/.openclaw/config.json`:\n\n```json\n{\n  \"skill-vettr\": {\n    \"maxRiskScore\": 50,\n    \"requireAuthor\": true,\n    \"autoVet\": true,\n    \"maxNetworkCalls\": 5,\n    \"allowedHosts\": [\"api.openai.com\", \"api.anthropic.com\", \"registry.npmjs.org\"],\n    \"blockedAuthors\": [],\n    \"blockedPackages\": [],\n    \"typosquatTargets\": [\"my-important-skill\"]\n  }\n}\n```\n\n| Field | Default | Description |\n|-------|---------|-------------|\n| `maxRiskScore` | 50 | Score at or above which installation is blocked |\n| `requireAuthor` | true | Warn if SKILL.md lacks an author field |\n| `autoVet` | false | Automatically vet skills on `skill:pre-install` hook |\n| `maxNetworkCalls` | 5 | Excess network calls beyond this add to risk score |\n| `allowedHosts` | (see above) | Hostnames that are allowed for network calls |\n| `blockedAuthors` | [] | Author names to block outright |\n| `blockedPackages` | [] | npm package names to block (merged with built-in list) |\n| `typosquatTargets` | [] | Skill names to check for typosquatting similarity |\n\n## Risk Levels\n\n| Level | Score | Recommendation |\n|-------|-------|----------------|\n| SAFE | 0 | INSTALL |\n| LOW | 1-19 | INSTALL |\n| MEDIUM | 20-39 | REVIEW |\n| HIGH | 40-69 | REVIEW or BLOCK |\n| CRITICAL | 70+ | BLOCK |\n\n## Testing\n\n```bash\nnpm run build\nnpm test\n```\n\nTests use Node's built-in test runner (`node:test`). The test suite covers each analyzer independently plus end-to-end integration tests against fixture skill directories.\n\n## Security Notes\n\nThe `vet` and `vet-url` commands allow paths under the current working directory (`process.cwd()`) as a convenience, so you can vet skills directly in your workspace without copying them elsewhere. The trade-off is that any path under `cwd` is accepted for vetting, which may be a broader scope than intended if you run the tool from a high-privilege or sensitive directory. In high-security environments, consider running skill-vettr from a dedicated, isolated directory to limit the allowed root scope.\n\nThe `vet-url` command downloads and extracts remote archives into a temporary directory. This is necessary for its purpose but means external binaries (`curl`, `tar`, `git`) touch the filesystem. The `vet-clawhub` command similarly invokes the `clawhub` CLI. Run these commands only against URLs and slugs you have reason to trust, and prefer running inside a disposable container or VM for untrusted sources.\n\nIf you enable the `autoVet` hook, review your configuration carefully — it will automatically invoke the vetting engine on every `skill:pre-install` event.\n\n## Publishing\n\nThe root directory of this repository is the publishable artifact. There is no separate build or packaging step required — publish directly from the repo root.\n\n## Licence\n\nMIT\n\n## Download History\n\n[![Download History](https://skill-history.com/chart/britrik/skill-vettr.svg)](https://skill-history.com/britrik/skill-vettr)\n\nFile v2.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn7ew5gbg17d6pmg1sjvqm6qe180p9e5\",\n  \"slug\": \"vettr\",\n  \"version\": \"2.0.4\",\n  \"publishedAt\": 1780359963136\n}\n\nFile v2.0.4:skill-card.md\n\n## Description:\n\nStatic analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting skills from ClawHub or untrusted sources.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[britrik](https://clawhub.ai/user/britrik)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to evaluate third-party OpenClaw skills before installation. It reports static-analysis findings for risky code execution, shell use, dependency issues, typosquatting, prompt-injection patterns, and related metadata concerns.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Target skills can include ignore-file rules that hide files from local analysis and make scan results incomplete or misleading.\n\nMitigation: Treat results as one input, inspect ignore rules, and manually review high-risk skills before relying on a pass or fail outcome.\n\nRisk: Remote URL vetting downloads untrusted content and can reach unintended network targets.\n\nMitigation: Run remote vetting only in a disposable or network-restricted environment, especially for untrusted URLs.\n\nRisk: npm dependencies and external binaries used during remote vetting are part of the trust boundary.\n\nMitigation: Verify the runtime environment, dependencies, and git, curl, tar, and clawhub binaries before using remote vetting workflows.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/britrik/skills/vettr)\n- [Project homepage](https://github.com/britrik/skill-vettr)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown-style text with risk summaries, findings, recommendations, usage messages, and configuration examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Reports are heuristic and should be reviewed before acting on installation decisions.]\n\n## Skill Version(s):\n\n2.0.4 (source: server release evidence; artifact frontmatter and package.json show 2.0.3)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v2.0.4:package-lock.json\n\n{\n  \"name\": \"@openclaw/skill-vettr\",\n  \"version\": \"2.0.3\",\n  \"lockfileVersion\": 3,\n  \"requires\": true,\n  \"packages\": {\n    \"\": {\n      \"name\": \"@openclaw/skill-vettr\",\n      \"version\": \"2.0.3\",\n      \"dependencies\": {\n        \"tree-sitter-javascript\": \"^0.25.0\",\n        \"tree-sitter-typescript\": \"^0.23.2\",\n        \"web-tree-sitter\": \"^0.26.0\",\n        \"yaml\": \"^2.4.0\"\n      },\n      \"devDependencies\": {\n        \"@types/node\": \"^20.0.0\",\n        \"fast-check\": \"^4.5.3\",\n        \"typescript\": \"^5.3.0\"\n      },\n      \"engines\": {\n        \"node\": \">=20.0.0\"\n      }\n    },\n    \"node_modules/@types/node\": {\n      \"version\": \"20.19.32\",\n      \"resolved\": \"https://registry.npmjs.org/@types/node/-/node-20.19.32.tgz\",\n      \"integrity\": \"sha512-Ez8QE4DMfhjjTsES9K2dwfV258qBui7qxUsoaixZDiTzbde4U12e1pXGNu/ECsUIOi5/zoCxAQxIhQnaUQ2VvA==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"undici-types\": \"~6.21.0\"\n      }\n    },\n    \"node_modules/fast-check\": {\n      \"version\": \"4.5.3\",\n      \"resolved\": \"https://registry.npmjs.org/fast-check/-/fast-check-4.5.3.tgz\",\n      \"integrity\": \"sha512-IE9csY7lnhxBnA8g/WI5eg/hygA6MGWJMSNfFRrBlXUciADEhS1EDB0SIsMSvzubzIlOBbVITSsypCsW717poA==\",\n      \"dev\": true,\n      \"funding\": [\n        {\n          \"type\": \"individual\",\n          \"url\": \"https://github.com/sponsors/dubzzz\"\n        },\n        {\n          \"type\": \"opencollective\",\n          \"url\": \"https://opencollective.com/fast-check\"\n        }\n      ],\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"pure-rand\": \"^7.0.0\"\n      },\n      \"engines\": {\n        \"node\": \">=12.17.0\"\n      }\n    },\n    \"node_modules/node-addon-api\": {\n      \"version\": \"8.5.0\",\n      \"resolved\": \"https://registry.npmjs.org/node-addon-api/-/node-addon-api-8.5.0.tgz\",\n      \"integrity\": \"sha512-/bRZty2mXUIFY/xU5HLvveNHlswNJej+RnxBjOMkidWfwZzgTbPG1E3K5TOxRLOR+5hX7bSofy8yf1hZevMS8A==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \"^18 || ^20 || >= 21\"\n      }\n    },\n    \"node_modules/node-gyp-build\": {\n      \"version\": \"4.8.4\",\n      \"resolved\": \"https://registry.npmjs.org/node-gyp-build/-/node-gyp-build-4.8.4.tgz\",\n      \"integrity\": \"sha512-LA4ZjwlnUblHVgq0oBF3Jl/6h/Nvs5fzBLwdEF4nuxnFdsfajde4WfxtJr3CaiH+F6ewcIB/q4jQ4UzPyid+CQ==\",\n      \"license\": \"MIT\",\n      \"bin\": {\n        \"node-gyp-build\": \"bin.js\",\n        \"node-gyp-build-optional\": \"optional.js\",\n        \"node-gyp-build-test\": \"build-test.js\"\n      }\n    },\n    \"node_modules/pure-rand\": {\n      \"version\": \"7.0.1\",\n      \"resolved\": \"https://registry.npmjs.org/pure-rand/-/pure-rand-7.0.1.tgz\",\n      \"integrity\": \"sha512-oTUZM/NAZS8p7ANR3SHh30kXB+zK2r2BPcEn/awJIbOvq82WoMN4p62AWWp3Hhw50G0xMsw1mhIBLqHw64EcNQ==\",\n      \"dev\": true,\n      \"funding\": [\n        {\n          \"type\": \"individual\",\n          \"url\": \"https://github.com/sponsors/dubzzz\"\n        },\n        {\n          \"type\": \"opencollective\",\n          \"url\": \"https://opencollective.com/fast-check\"\n        }\n      ],\n      \"license\": \"MIT\"\n    },\n    \"node_modules/tree-sitter-javascript\": {\n      \"version\": \"0.25.0\",\n      \"resolved\": \"https://registry.npmjs.org/tree-sitter-javascript/-/tree-sitter-javascript-0.25.0.tgz\",\n      \"integrity\": \"sha512-1fCbmzAskZkxcZzN41sFZ2br2iqTYP3tKls1b/HKGNPQUVOpsUxpmGxdN/wMqAk3jYZnYBR1dd/y/0avMeU7dw==\",\n      \"hasInstallScript\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"node-addon-api\": \"^8.3.1\",\n        \"node-gyp-build\": \"^4.8.4\"\n      },\n      \"peerDependencies\": {\n        \"tree-sitter\": \"^0.25.0\"\n      },\n      \"peerDependenciesMeta\": {\n        \"tree-sitter\": {\n          \"optional\": true\n        }\n      }\n    },\n    \"node_modules/tree-sitter-typescript\": {\n      \"version\": \"0.23.2\",\n      \"resolved\": \"https://registry.npmjs.org/tree-sitter-typescript/-/tree-sitter-typescript-0.23.2.tgz\",\n      \"integrity\": \"sha512-e04JUUKxTT53/x3Uq1zIL45DoYKVfHH4CZqwgZhPg5qYROl5nQjV+85ruFzFGZxu+QeFVbRTPDRnqL9UbU4VeA==\",\n      \"hasInstallScript\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"node-addon-api\": \"^8.2.2\",\n        \"node-gyp-build\": \"^4.8.2\",\n        \"tree-sitter-javascript\": \"^0.23.1\"\n      },\n      \"peerDependencies\": {\n        \"tree-sitter\": \"^0.21.0\"\n      },\n      \"peerDependenciesMeta\": {\n        \"tree-sitter\": {\n          \"optional\": true\n        }\n      }\n    },\n    \"node_modules/tree-sitter-typescript/node_modules/tree-sitter-javascript\": {\n      \"version\": \"0.23.1\",\n      \"resolved\": \"https://registry.npmjs.org/tree-sitter-javascript/-/tree-sitter-javascript-0.23.1.tgz\",\n      \"integrity\": \"sha512-/bnhbrTD9frUYHQTiYnPcxyHORIw157ERBa6dqzaKxvR/x3PC4Yzd+D1pZIMS6zNg2v3a8BZ0oK7jHqsQo9fWA==\",\n      \"hasInstallScript\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"node-addon-api\": \"^8.2.2\",\n        \"node-gyp-build\": \"^4.8.2\"\n      },\n      \"peerDependencies\": {\n        \"tree-sitter\": \"^0.21.1\"\n      },\n      \"peerDependenciesMeta\": {\n        \"tree-sitter\": {\n          \"optional\": true\n        }\n      }\n    },\n    \"node_modules/typescript\": {\n      \"version\": \"5.9.3\",\n      \"resolved\": \"https://registry.npmjs.org/typescript/-/typescript-5.9.3.tgz\",\n      \"integrity\": \"sha512-jl1vZzPDinLr9eUt3J/t7V6FgNEw9QjvBPdysz9KfQDD41fQrC2Y4vKQdiaUpFT4bXlb1RHhLpp8wtm6M5TgSw==\",\n      \"dev\": true,\n      \"license\": \"Apache-2.0\",\n      \"bin\": {\n        \"tsc\": \"bin/tsc\",\n        \"tsserver\": \"bin/tsserver\"\n      },\n      \"engines\": {\n        \"node\": \">=14.17\"\n      }\n    },\n    \"node_modules/undici-types\": {\n      \"version\": \"6.21.0\",\n      \"resolved\": \"https://registry.npmjs.org/undici-types/-/undici-types-6.21.0.tgz\",\n      \"integrity\": \"sha512-iwDZqg0QAGrg9Rav5H4n0M64c3mkR59cJ6wQp+7C4nI0gsmExaedaYLNO44eT4AtBBwjbTiGPMlt2Md0T9H9JQ==\",\n      \"dev\": true,\n      \"license\": \"MIT\"\n    },\n    \"node_modules/web-tree-sitter\": {\n      \"version\": \"0.26.5\",\n      \"resolved\": \"https://registry.npmjs.org/web-tree-sitter/-/web-tree-sitter-0.26.5.tgz\",\n      \"integrity\": \"sha512-u9sl+q21VSKX2T8dhpQw8bMGGqNfwaIyuoYE3kdOQGVDrOqrmcS9GmaQoCS602iaFnuokn3WCHW374c7GAnuaQ==\",\n      \"license\": \"MIT\"\n    },\n    \"node_modules/yaml\": {\n      \"version\": \"2.8.2\",\n      \"resolved\": \"https://registry.npmjs.org/yaml/-/yaml-2.8.2.tgz\",\n      \"integrity\": \"sha512-mplynKqc1C2hTVYxd0PU2xQAc22TI1vShAYGksCCfxbn/dFwnHTNi1bvYsBTkhdUNtGIf5xNOg938rrSSYvS9A==\",\n      \"license\": \"ISC\",\n      \"bin\": {\n        \"yaml\": \"bin.mjs\"\n      },\n      \"engines\": {\n        \"node\": \">= 14.6\"\n      },\n      \"funding\": {\n        \"url\": \"https://github.com/sponsors/eemeli\"\n      }\n    }\n  }\n}\n\nFile v2.0.4:package.json\n\n{\n  \"name\": \"@openclaw/skill-vettr\",\n  \"version\": \"2.0.3\",\n  \"type\": \"module\",\n  \"main\": \"dist/index.js\",\n  \"scripts\": {\n    \"build\": \"tsc\",\n    \"dev\": \"tsc --watch\",\n    \"test\": \"node --test dist/__tests__/**/*.test.js\"\n  },\n  \"dependencies\": {\n    \"tree-sitter-javascript\": \"^0.25.0\",\n    \"tree-sitter-typescript\": \"^0.23.2\",\n    \"web-tree-sitter\": \"^0.26.0\",\n    \"yaml\": \"^2.4.0\"\n  },\n  \"devDependencies\": {\n    \"@types/node\": \"^20.0.0\",\n    \"fast-check\": \"^4.5.3\",\n    \"typescript\": \"^5.3.0\"\n  },\n  \"engines\": {\n    \"node\": \">=20.0.0\"\n  }\n}\n\nFile v2.0.4:.github/workflows/ai-review.yml\n\nname: AI PR Review\n\non:\n  pull_request:\n    types: [opened, synchronize, reopened]\n    branches: [main]\n\npermissions:\n  pull-requests: write\n  contents: read\n\njobs:\n  review:\n    runs-on: ubuntu-latest\n    if: github.event.pull_request.head.repo.full_name == github.repository\n\n    steps:\n      - uses: actions/checkout@v4\n        with:\n          fetch-depth: 0\n\n      - name: Build diff\n        run: |\n          git diff origin/${{ github.base_ref }}...HEAD \\\n            -- '*.ts' '*.tsx' '*.js' '*.css' '*.json' '*.yml' '*.yaml' '*.md' \\\n            ':!package-lock.json' ':!dist/**' ':!*.min.js' \\\n            | head -c 40000 > pr.diff\n\n      - name: Post AI review\n        env:\n          GLM_API_KEY: ${{ secrets.GLM_API_KEY }}\n          GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}\n          PR_NUMBER: ${{ github.event.pull_request.number }}\n          PR_TITLE: ${{ github.event.pull_request.title }}\n        run: |\n          python3 << 'PYEOF'\nimport os, json, urllib.request, urllib.error, subprocess, sys\n\ndiff = open('pr.diff').read().strip()\nif not diff:\n    print(\"No reviewable diff - skipping.\")\n    sys.exit(0)\n\nif len(diff) > 36000:\n    diff = diff[:36000] + \"\\n\\n[diff truncated]\"\n\npr_title = os.environ['PR_TITLE']\napi_key = os.environ.get('GLM_API_KEY', '').strip()\n\nif not api_key:\n    print(\"GLM_API_KEY secret not set - skipping AI review.\")\n    sys.exit(0)\n\nprompt = (\n    \"You are reviewing a PR. Focus on:\\n\"\n    \"1. PRIVACY - Does any code send user content to an external URL?\\n\"\n    \"2. SECURITY - Unsanitized HTML? XSS risk? Input validation?\\n\"\n    \"3. CORRECTNESS - Logic bugs, TypeScript errors, unhandled edge cases?\\n\"\n    \"4. TESTS - New logic without tests?\\n\"\n    \"5. NOTES - Anything else worth mentioning\\n\\n\"\n    \"Ignore: whitespace, style, lock files, generated files.\\n\\n\"\n    f\"PR: {pr_title}\\n\\n\"\n    \"```diff\\n\"\n    f\"{diff}\\n\"\n    \"```\\n\\n\"\n    \"Reply in exactly this format:\\n\"\n    \"## AI Review\\n\"\n    \"### Summary\\n\"\n    \"[1-2 sentences]\\n\"\n    \"### Findings\\n\"\n    \"[Bullet list. Omit section if nothing to flag.]\\n\"\n    \"### Verdict\\n\"\n    \"[Exactly one of: Looks good | Minor issues, author's call | Needs changes]\"\n)\n\npayload = json.dumps({\n    \"model\": \"glm-5-turbo\",\n    \"messages\": [{\"role\": \"user\", \"content\": prompt}],\n    \"max_tokens\": 4096,\n    \"temperature\": 0.2,\n}).encode()\n\nreq = urllib.request.Request(\n    \"https://api.z.ai/api/coding/paas/v4/chat/completions\",\n    data=payload,\n    headers={\n        \"Authorization\": f\"Bearer {api_key}\",\n        \"Content-Type\": \"application/json\",\n    },\n)\n\ntry:\n    with urllib.request.urlopen(req, timeout=60) as resp:\n        data = json.loads(resp.read())\nexcept urllib.error.HTTPError as e:\n    body = e.read().decode('utf-8', errors='replace')\n    print(f\"GLM API HTTP {e.code} error: {body}\")\n    sys.exit(0)\nexcept Exception as e:\n    print(f\"GLM API error: {e}\")\n    sys.exit(0)\n\nmsg = data[\"choices\"][0][\"message\"]\nreview = (msg.get(\"content\") or msg.get(\"reasoning_content\") or \"\").strip()\nif not review:\n    print(\"GLM returned empty content - skipping comment.\")\n    print(f\"Full response: {json.dumps(data)}\")\n    sys.exit(0)\nsubprocess.run(\n    [\"gh\", \"pr\", \"comment\", os.environ[\"PR_NUMBER\"], \"--body\", review],\n    check=True,\n)\nPYEOF","readmeExcerpt":"Skill: vettr Owner: britrik Summary: Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patte... Tags: latest:2.0.4 Version history: v2.0.4 | 2026-06-02T00:26:03.136Z | user Clean republish without test fixtures — scanner for third-party OpenClaw skills Archive index: Archive v2.0.4: 19 files, 33968 bytes Files: .gith","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"npm install"},{"language":"json","snippet":"{\n  \"allowCwd\": true\n}"},{"language":"text","snippet":"# Exclude test fixtures containing deliberate prompt injection vectors\ntest/fixtures/\n\n# Exclude generated files\ndist/\n*.min.js"},{"language":"bash","snippet":"cd ~/.openclaw/skills/skill-scanner\nnpm install\nnpm run build\nnpm test"},{"language":"text","snippet":"/skill:vet --path ~/Downloads/suspicious-skill"},{"language":"text","snippet":"/skill:vet-url --url https://github.com/org/skill/archive/main.tar.gz"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"skill.md","content":"---\nname: vettr\ndescription: \"Static analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting skills from ClawHub or untrusted sources.\"\nversion: \"2.0.3\"\nauthor: britrik\ntags: [\"security\", \"scanner\", \"vetting\", \"analysis\", \"static-analysis\"]\nmetadata:\n  openclaw:\n    requires:\n      env: []\n      bins:\n        - node\n    envVars: []\n    install:\n      - kind: node\n        package: \"@openclaw/skill-vettr\"\n        bins: []\n    emoji: \"\\U0001F6E1\"\n    homepage: https://github.com/britrik/skill-vettr\n    notes: >\n      Core /skill:vet command requires only node. The /skill:vet-url command\n      additionally requires git, curl, and tar on PATH. The /skill:vet-clawhub\n      command requires the clawhub CLI. These are runtime-optional — the skill\n      loads and registers commands regardless of their presence.\n---\n\n# skill-vettr v2.0.3\n\nSecurity scanner for third-party OpenClaw skills. Analyses source code, dependencies, and metadata before installation using tree-sitter AST parsing and regex pattern matching.\n\n## Installation\n\n```bash\nnpm install\n```\n\nThis installs all Node.js dependencies, including tree-sitter `.wasm` grammar files required at runtime for AST-based analysis. The `.wasm` files are located in `node_modules` and must be present for the skill to function.\n\n> ⚠️ **Install safety:** `npm install` runs dependency lifecycle scripts, which can execute arbitrary code. For stronger isolation, run `npm ci --ignore-scripts` — but note that tree-sitter native/WASM artifacts may not build, breaking AST analysis. Prefer installing inside a container or VM when possible.\n\n## External Binaries\n\nThe `vet-url` and `vet-clawhub` commands invoke external binaries via `execSafe` (which uses `execFile` — no shell is spawned). Only the following commands are permitted:\n\n| Binary | Used By | Purpose |\n|--------|---------|---------|\n| `git` | `vet-url` | Clone `.git` URLs (with hooks disabled) |\n| `curl` | `vet-url` | Download archive URLs |\n| `tar` | `vet-url` | Extract downloaded archives |\n| `clawhub` | `vet-clawhub` | Fetch skills from ClawHub registry |\n\nThe `/skill:vet` command (local path vetting) requires only `node` and no external binaries.\n\n## Commands\n\n- `/skill:vet --path <directory>` — Vet a local skill directory\n- `/skill:vet-url --url <https://...>` — Download and vet from URL\n- `/skill:vet-clawhub --skill <slug>` — Fetch and vet from ClawHub\n\n## Detection Categories\n\n| Category | Method | Examples |\n|----------|--------|----------|\n| Code execution | AST | eval(), new Function(), vm.runInThisContext() |\n| Shell injection | AST | exec(), execSync(), spawn(\"bash\"), child_process imports |\n| Dynamic require | AST | require(variable), require(templateString) |\n| Prototype pollution | AST | __proto__ assignment |\n| Prompt injection | Regex | Instruction override patterns, control tokens (in string literals) |\n| Homo"},{"path":"readme.md","content":"# skill-vettr v2.0.3\n\nStatic analysis security scanner for OpenClaw skills. Analyses code before installation to detect common threats.\n\n## Quick Start\n\n```bash\ncd ~/.openclaw/skills/skill-scanner\nnpm install\nnpm run build\nnpm test\n```\n\n> ⚠️ `npm install` runs dependency lifecycle scripts (tree-sitter includes native builds). For stronger isolation, install inside a container or use `npm ci --ignore-scripts` (note: AST analysis may break without tree-sitter WASM artifacts).\n\n## What It Does\n\nskill-vettr scans a skill's source code, dependencies, and metadata for security issues. It uses:\n\n- **tree-sitter AST parsing** for structural code analysis (eval, exec, spawn, dynamic require, prototype pollution, etc.)\n- **Regex patterns** for things AST can't detect (prompt injection, homoglyph attacks, encoded function names)\n- **Dependency analysis** for known malicious packages, suspicious prefixes, lifecycle scripts\n- **Metadata analysis** for typosquatting (Levenshtein distance), dangerous permissions, blocked authors\n\n## What It Doesn't Do\n\nThis is a heuristic scanner. It has inherent limitations:\n\n- Cannot detect runtime-only behaviour (e.g., code that downloads malware at runtime from an innocuous-looking URL)\n- AST queries can be evaded by sufficiently motivated attackers (e.g., multi-stage string construction)\n- Only scans JS/TS code files — binary payloads, images, and other non-text files are skipped\n- Does not sandbox or execute the target skill\n- Malicious package lists are small and non-exhaustive\n\nFor high-security environments, combine with sandboxing and manual review.\n\n## External Binaries\n\nThe `vet-url` and `vet-clawhub` commands invoke external binaries via `execSafe` (uses `execFile`, no shell spawned):\n\n| Binary | Command | Purpose |\n|--------|---------|---------|\n| `git` | `vet-url` | Clone `.git` URLs (hooks disabled via `-c core.hooksPath=/dev/null`) |\n| `curl` | `vet-url` | Download archive URLs (max 50 MB, 120s timeout) |\n| `tar` | `vet-url` | Extract archives (`--no-same-owner --no-same-permissions`) |\n| `clawhub` | `vet-clawhub` | Fetch skills from ClawHub registry |\n\nThe `/skill:vet` command (local path) requires only `node`. Ensure external binaries are trusted and available on `PATH` before using remote vetting commands.\n\n## Usage\n\n**Vet a local skill directory:**\n```\n/skill:vet --path ~/Downloads/suspicious-skill\n```\n\n**Vet from URL:**\n```\n/skill:vet-url --url https://github.com/org/skill/archive/main.tar.gz\n```\n\n**Vet from ClawHub:**\n```\n/skill:vet-clawhub --skill some-skill-name\n```\n\n## Configuration\n\nAdd to `~/.openclaw/config.json`:\n\n```json\n{\n  \"skill-vettr\": {\n    \"maxRiskScore\": 50,\n    \"requireAuthor\": true,\n    \"autoVet\": true,\n    \"maxNetworkCalls\": 5,\n    \"allowedHosts\": [\"api.openai.com\", \"api.anthropic.com\", \"registry.npmjs.org\"],\n    \"blockedAuthors\": [],\n    \"blockedPackages\": [],\n    \"typosquatTargets\": [\"my-important-skill\"]\n  }\n}\n```\n\n| Field | Default | Description |\n|-------|---------|-------------|\n| "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7ew5gbg17d6pmg1sjvqm6qe180p9e5\",\n  \"slug\": \"vettr\",\n  \"version\": \"2.0.4\",\n  \"publishedAt\": 1780359963136\n}"},{"path":"skill-card.md","content":"## Description:\n\nStatic analysis security scanner for third-party OpenClaw skills. Detects eval/spawn risks, malicious dependencies, typosquatting, and prompt injection patterns before installation. Use when vetting skills from ClawHub or untrusted sources.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[britrik](https://clawhub.ai/user/britrik)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to evaluate third-party OpenClaw skills before installation. It reports static-analysis findings for risky code execution, shell use, dependency issues, typosquatting, prompt-injection patterns, and related metadata concerns.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Target skills can include ignore-file rules that hide files from local analysis and make scan results incomplete or misleading.\n\nMitigation: Treat results as one input, inspect ignore rules, and manually review high-risk skills before relying on a pass or fail outcome.\n\nRisk: Remote URL vetting downloads untrusted content and can reach unintended network targets.\n\nMitigation: Run remote vetting only in a disposable or network-restricted environment, especially for untrusted URLs.\n\nRisk: npm dependencies and external binaries used during remote vetting are part of the trust boundary.\n\nMitigation: Verify the runtime environment, dependencies, and git, curl, tar, and clawhub binaries before using remote vetting workflows.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/britrik/skills/vettr)\n- [Project homepage](https://github.com/britrik/skill-vettr)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown-style text with risk summaries, findings, recommendations, usage messages, and configuration examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Reports are heuristic and should be reviewed before acting on installation decisions.]\n\n## Skill Version(s):\n\n2.0.4 (source: server release evidence; artifact frontmatter and package.json show 2.0.3)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"package-lock.json","content":"{\n  \"name\": \"@openclaw/skill-vettr\",\n  \"version\": \"2.0.3\",\n  \"lockfileVersion\": 3,\n  \"requires\": true,\n  \"packages\": {\n    \"\": {\n      \"name\": \"@openclaw/skill-vettr\",\n      \"version\": \"2.0.3\",\n      \"dependencies\": {\n        \"tree-sitter-javascript\": \"^0.25.0\",\n        \"tree-sitter-typescript\": \"^0.23.2\",\n        \"web-tree-sitter\": \"^0.26.0\",\n        \"yaml\": \"^2.4.0\"\n      },\n      \"devDependencies\": {\n        \"@types/node\": \"^20.0.0\",\n        \"fast-check\": \"^4.5.3\",\n        \"typescript\": \"^5.3.0\"\n      },\n      \"engines\": {\n        \"node\": \">=20.0.0\"\n      }\n    },\n    \"node_modules/@types/node\": {\n      \"version\": \"20.19.32\",\n      \"resolved\": \"https://registry.npmjs.org/@types/node/-/node-20.19.32.tgz\",\n      \"integrity\": \"sha512-Ez8QE4DMfhjjTsES9K2dwfV258qBui7qxUsoaixZDiTzbde4U12e1pXGNu/ECsUIOi5/zoCxAQxIhQnaUQ2VvA==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"undici-types\": \"~6.21.0\"\n      }\n    },\n    \"node_modules/fast-check\": {\n      \"version\": \"4.5.3\",\n      \"resolved\": \"https://registry.npmjs.org/fast-check/-/fast-check-4.5.3.tgz\",\n      \"integrity\": \"sha512-IE9csY7lnhxBnA8g/WI5eg/hygA6MGWJMSNfFRrBlXUciADEhS1EDB0SIsMSvzubzIlOBbVITSsypCsW717poA==\",\n      \"dev\": true,\n      \"funding\": [\n        {\n          \"type\": \"individual\",\n          \"url\": \"https://github.com/sponsors/dubzzz\"\n        },\n        {\n          \"type\": \"opencollective\",\n          \"url\": \"https://opencollective.com/fast-check\"\n        }\n      ],\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"pure-rand\": \"^7.0.0\"\n      },\n      \"engines\": {\n        \"node\": \">=12.17.0\"\n      }\n    },\n    \"node_modules/node-addon-api\": {\n      \"version\": \"8.5.0\",\n      \"resolved\": \"https://registry.npmjs.org/node-addon-api/-/node-addon-api-8.5.0.tgz\",\n      \"integrity\": \"sha512-/bRZty2mXUIFY/xU5HLvveNHlswNJej+RnxBjOMkidWfwZzgTbPG1E3K5TOxRLOR+5hX7bSofy8yf1hZevMS8A==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \"^18 || ^20 || >= 21\"\n      }\n    },\n    \"node_modules/node-gyp-build\": {\n      \"version\": \"4.8.4\",\n      \"resolved\": \"https://registry.npmjs.org/node-gyp-build/-/node-gyp-build-4.8.4.tgz\",\n      \"integrity\": \"sha512-LA4ZjwlnUblHVgq0oBF3Jl/6h/Nvs5fzBLwdEF4nuxnFdsfajde4WfxtJr3CaiH+F6ewcIB/q4jQ4UzPyid+CQ==\",\n      \"license\": \"MIT\",\n      \"bin\": {\n        \"node-gyp-build\": \"bin.js\",\n        \"node-gyp-build-optional\": \"optional.js\",\n        \"node-gyp-build-test\": \"build-test.js\"\n      }\n    },\n    \"node_modules/pure-rand\": {\n      \"version\": \"7.0.1\",\n      \"resolved\": \"https://registry.npmjs.org/pure-rand/-/pure-rand-7.0.1.tgz\",\n      \"integrity\": \"sha512-oTUZM/NAZS8p7ANR3SHh30kXB+zK2r2BPcEn/awJIbOvq82WoMN4p62AWWp3Hhw50G0xMsw1mhIBLqHw64EcNQ==\",\n      \"dev\": true,\n      \"funding\": [\n        {\n          \"type\": \"individual\",\n          \"url\": \"https://github.com/sponsors/dubzzz\"\n        },\n        {\n          \"type\": \"opencollective\",\n          \"url\": \"https://opencollective.com/fast-check\"\n        }\n      ],\n      \"license\": \"MIT\"\n   "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1605,"uniquenessScore":44,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T01:44:18.765Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T01:44:18.765Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:45:26.345Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}