{"id":"a0f7e6dc-3a46-47d9-8ab0-790532629198","entityType":"agent","slug":"clawhub-confidentkai-skill-vetter-optimized","name":"Skill Vetter Optimized","canonicalUrl":"https://www.xpersona.co/agent/clawhub-confidentkai-skill-vetter-optimized","canonicalPath":"/agent/clawhub-confidentkai-skill-vetter-optimized","generatedAt":"2026-10-10T23:46:32.546Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T20:04:42.282Z","emptyReason":null},"description":"🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化，添加了Python检查脚本和详细审查流程。 Skill: Skill Vetter Optimized Owner: confidentkai Summary: 🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化，添加了Python检查脚本和详细审查流程。 Tags: latest:2.0.0 Version history: v2.0.0 | 2026-04-15T03:52:01.620Z | user 优化版本：添加Python检查脚本、系统化审查清单、完善文档、清理代码结构 Archive index: Archive v2.0.0: 6 files, 8819 bytes Files: CHANGELOG.md (1029b), references/checklist.md (3294b), s","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s178zptfxy85cb8ggdvqzq875183hvjc:skill-vetter-optimized","sourceUrl":"https://clawhub.ai/confidentkai/skill-vetter-optimized","homepage":"https://clawhub.ai/confidentkai/skills/skill-vetter-optimized","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/confidentkai/skill-vetter-optimized","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/confidentkai/skills/skill-vetter-optimized","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化，添加了Python检查脚本和详细审查流程。 Skill: Skill Vetter Optimize"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T20:04:42.282Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T20:04:42.282Z","emptyReason":null},"stars":null,"forks":null,"downloads":1272,"packageName":null,"latestVersion":"2.0.0","tractionLabel":"1.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T20:04:42.281Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T20:04:42.282Z","lastCrawledAt":"2026-10-10T20:04:42.281Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T20:04:42.281Z","lastVerifiedAt":null,"highlights":[{"version":"2.0.0","createdAt":"2026-04-15T03:52:01.620Z","changelog":"优化版本：添加Python检查脚本、系统化审查清单、完善文档、清理代码结构","fileCount":6,"zipByteSize":8819}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s178zptfxy85cb8ggdvqzq875183hvjc:skill-vetter-optimized","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T23:46:32.546Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-confidentkai-skill-vetter-optimized/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T20:04:42.282Z","emptyReason":null},"readme":"Skill: Skill Vetter Optimized\n\nOwner: confidentkai\n\nSummary: 🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化，添加了Python检查脚本和详细审查流程。\n\nTags: latest:2.0.0\n\nVersion history:\n\nv2.0.0 | 2026-04-15T03:52:01.620Z | user\n\n优化版本：添加Python检查脚本、系统化审查清单、完善文档、清理代码结构\n\nArchive index:\n\nArchive v2.0.0: 6 files, 8819 bytes\n\nFiles: CHANGELOG.md (1029b), references/checklist.md (3294b), scripts/skill_checker.py (5113b), skill-card.md (2075b), SKILL.md (5463b), _meta.json (141b)\n\nFile v2.0.0:SKILL.md\n\n---\nname: skill-vetter-optimized\nversion: 2.0.0\ndescription: \"🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化，添加了Python检查脚本和详细审查流程。\"\n---\n\n# Skill Vetter Optimized 🔒✨\n\n**优化版技能审查器** - 基于原始skill-vetter优化增强\n\n## 🚀 优化亮点\n\n✅ **新增实用工具** - Python检查脚本快速分析技能目录  \n✅ **系统化审查流程** - 四阶段审查清单  \n✅ **详细文档** - 完整的审查指南和示例  \n✅ **保持兼容** - 完全兼容原始审查协议  \n✅ **性能优化** - 更快的审查流程  \n\nSecurity-first vetting protocol for AI agent skills. **Never install a skill without vetting it first.**\n\n## When to Use\n\n- Before installing any skill from ClawdHub\n- Before running skills from GitHub repos\n- When evaluating skills shared by other agents\n- Anytime you're asked to install unknown code\n\n## Vetting Protocol\n\n### Step 1: Source Check\n\n```\nQuestions to answer:\n- [ ] Where did this skill come from?\n- [ ] Is the author known/reputable?\n- [ ] How many downloads/stars does it have?\n- [ ] When was it last updated?\n- [ ] Are there reviews from other agents?\n```\n\n### Step 2: Code Review (MANDATORY)\n\nRead ALL files in the skill. Check for these **RED FLAGS**:\n\n```\n🚨 REJECT IMMEDIATELY IF YOU SEE:\n─────────────────────────────────────────\n• curl/wget to unknown URLs\n• Sends data to external servers\n• Requests credentials/tokens/API keys\n• Reads ~/.ssh, ~/.aws, ~/.config without clear reason\n• Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md\n• Uses base64 decode on anything\n• Uses eval() or exec() with external input\n• Modifies system files outside workspace\n• Installs packages without listing them\n• Network calls to IPs instead of domains\n• Obfuscated code (compressed, encoded, minified)\n• Requests elevated/sudo permissions\n• Accesses browser cookies/sessions\n• Touches credential files\n─────────────────────────────────────────\n```\n\n### Step 3: Permission Scope\n\n```\nEvaluate:\n- [ ] What files does it need to read?\n- [ ] What files does it need to write?\n- [ ] What commands does it run?\n- [ ] Does it need network access? To where?\n- [ ] Is the scope minimal for its stated purpose?\n```\n\n### Step 4: Risk Classification\n\n| Risk Level | Examples | Action |\n|------------|----------|--------|\n| 🟢 LOW | Notes, weather, formatting | Basic review, install OK |\n| 🟡 MEDIUM | File ops, browser, APIs | Full code review required |\n| 🔴 HIGH | Credentials, trading, system | Human approval required |\n| ⛔ EXTREME | Security configs, root access | Do NOT install |\n\n## Output Format\n\nAfter vetting, produce this report:\n\n```\nSKILL VETTING REPORT\n═══════════════════════════════════════\nSkill: [name]\nSource: [ClawdHub / GitHub / other]\nAuthor: [username]\nVersion: [version]\n───────────────────────────────────────\nMETRICS:\n• Downloads/Stars: [count]\n• Last Updated: [date]\n• Files Reviewed: [count]\n───────────────────────────────────────\nRED FLAGS: [None / List them]\n\nPERMISSIONS NEEDED:\n• Files: [list or \"None\"]\n• Network: [list or \"None\"]  \n• Commands: [list or \"None\"]\n───────────────────────────────────────\nRISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ EXTREME]\n\nVERDICT: [✅ SAFE TO INSTALL / ⚠️ INSTALL WITH CAUTION / ❌ DO NOT INSTALL]\n\nNOTES: [Any observations]\n═══════════════════════════════════════\n```\n\n## 实用工具\n\n### 1. 技能检查脚本\n\n使用内置的Python脚本快速检查技能目录：\n\n```bash\n# 检查技能目录的基本信息和安全风险\npython3 /root/.openclaw/skills/skill-vetter/scripts/skill_checker.py /path/to/skill\n```\n\n### 2. GitHub仓库检查\n\n对于GitHub托管的技能：\n```bash\n# 检查仓库统计信息\ncurl -s \"https://api.github.com/repos/OWNER/REPO\" | jq '{stars: .stargazers_count, forks: .forks_count, updated: .updated_at}'\n\n# 列出技能文件\ncurl -s \"https://api.github.com/repos/OWNER/REPO/contents/skills/SKILL_NAME\" | jq '.[].name'\n\n# 获取并审查SKILL.md\ncurl -s \"https://raw.githubusercontent.com/OWNER/REPO/main/skills/SKILL_NAME/SKILL.md\"\n```\n\n### 3. 使用审查清单\n\n参考 `references/checklist.md` 进行系统化的技能审查。\n\n## Trust Hierarchy\n\n1. **Official OpenClaw skills** → Lower scrutiny (still review)\n2. **High-star repos (1000+)** → Moderate scrutiny\n3. **Known authors** → Moderate scrutiny\n4. **New/unknown sources** → Maximum scrutiny\n5. **Skills requesting credentials** → Human approval always\n\n## Remember\n\n- No skill is worth compromising security\n- When in doubt, don't install\n- Ask your human for high-risk decisions\n- Document what you vet for future reference\n\n---\n\n*Paranoia is a feature.* 🔒🦀\n\nFile v2.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn71bmpaxztz381rsxj3mmsnqx82wys2\",\n  \"slug\": \"skill-vetter-optimized\",\n  \"version\": \"2.0.0\",\n  \"publishedAt\": 1776225121620\n}\n\nFile v2.0.0:references/checklist.md\n\n# 技能审查清单\n\n## 第一阶段：基本信息检查\n\n### 1. 来源验证\n- [ ] **来源平台**: ClawHub / GitHub / 其他\n- [ ] **作者信誉**: 已知作者 / 新作者 / 匿名\n- [ ] **下载量/星标数**: 高(>1000) / 中(100-1000) / 低(<100)\n- [ ] **最后更新**: 最近(30天内) / 较近(90天内) / 很久以前\n- [ ] **许可证**: MIT / Apache / GPL / 其他 / 无\n\n### 2. 文件结构检查\n- [ ] **SKILL.md存在**: 是 / 否\n- [ ] **描述清晰**: 是 / 否\n- [ ] **版本号**: 有 / 无\n- [ ] **目录结构合理**: 是 / 否\n- [ ] **文件数量合理**: 是(≤20) / 否(>20)\n\n## 第二阶段：代码安全审查\n\n### 3. 危险模式检查 (立即拒绝如果发现)\n- [ ] **下载并执行**: `curl | bash`, `wget | sh`\n- [ ] **远程代码执行**: `eval()`, `exec()` 带外部输入\n- [ ] **数据外传**: 发送数据到外部服务器\n- [ ] **凭证访问**: 读取SSH密钥、API密钥、密码文件\n- [ ] **系统修改**: 修改系统文件、crontab、启动项\n- [ ] **权限提升**: `sudo`, `chmod 777`, `setuid`\n- [ ] **混淆代码**: base64编码、压缩、混淆\n\n### 4. 权限范围评估\n- [ ] **文件读取**: 明确列出需要读取的文件\n- [ ] **文件写入**: 明确列出需要写入的文件\n- [ ] **网络访问**: 明确列出需要访问的域名/IP\n- [ ] **命令执行**: 明确列出需要执行的命令\n- [ ] **权限最小化**: 权限是否与功能匹配\n\n### 5. 依赖检查\n- [ ] **依赖声明**: package.json / requirements.txt\n- [ ] **依赖安全性**: 已知漏洞检查\n- [ ] **依赖必要性**: 所有依赖都是必要的吗？\n- [ ] **依赖来源**: 官方源 / 第三方源\n\n## 第三阶段：风险评估\n\n### 6. 风险等级评估\n- **🟢 低风险**: 只读操作、格式化、信息展示\n- **🟡 中风险**: 文件操作、网络请求、API调用\n- **🔴 高风险**: 系统命令、凭证访问、数据修改\n- **⛔ 极高风险**: 提权操作、持久化、外传数据\n\n### 7. 上下文评估\n- [ ] **功能与权限匹配**: 是 / 否\n- [ ] **错误处理**: 有 / 无\n- [ ] **日志记录**: 有 / 无\n- [ ] **测试用例**: 有 / 无\n- [ ] **文档完整**: 是 / 否\n\n## 第四阶段：决策与记录\n\n### 8. 审查结论\n- **✅ 安全可安装**: 通过所有检查，风险可控\n- **⚠️ 谨慎安装**: 有中等风险，需要监控\n- **❌ 拒绝安装**: 发现高风险或恶意行为\n\n### 9. 记录保存\n- [ ] **审查报告**: 生成详细报告\n- [ ] **决策理由**: 记录通过/拒绝的理由\n- [ ] **时间戳**: 记录审查时间\n- [ ] **审查者**: 记录审查者信息\n\n## 快速检查命令\n\n```bash\n# 使用辅助脚本检查\npython3 /root/.openclaw/skills/skill-vetter/scripts/skill_checker.py /path/to/skill\n\n# 检查GitHub仓库信息\ncurl -s \"https://api.github.com/repos/owner/repo\" | jq '.stargazers_count, .forks_count, .updated_at'\n\n# 列出技能文件\nfind /path/to/skill -type f -name \"*.py\" -o -name \"*.sh\" -o -name \"*.js\"\n```\n\n## 注意事项\n\n1. **零信任原则**: 默认不信任，需要验证\n2. **最小权限**: 只授予必要的权限\n3. **持续监控**: 安装后仍需监控行为\n4. **及时更新**: 关注安全更新和漏洞\n5. **备份恢复**: 重要系统做好备份\n\n---\n\n*安全不是功能，而是基础。* 🔒\n\nFile v2.0.0:CHANGELOG.md\n\n# 更新日志 - Skill Vetter\n\n## v2.0.0 (2026-04-15)\n\n### 优化内容\n1. **清理无关文件**\n   - 删除 `_meta.json` (安装时生成的元数据文件)\n\n2. **新增实用工具**\n   - `scripts/skill_checker.py` - Python辅助检查脚本\n   - `references/checklist.md` - 系统化审查清单\n\n3. **更新SKILL.md**\n   - 更新版本号至 2.0.0\n   - 优化描述信息\n   - 添加对新工具的说明\n   - 保持核心审查协议完整\n\n### 新增功能\n1. **技能检查脚本** (`skill_checker.py`)\n   - 快速检查技能目录结构\n   - 提取SKILL.md元数据\n   - 检测常见危险模式\n   - 生成初步风险评估\n\n2. **系统化审查清单** (`checklist.md`)\n   - 四阶段审查流程\n   - 详细的检查项目\n   - 风险评估标准\n   - 决策记录模板\n\n### 核心功能保留\n- 安全优先的审查协议\n- 红标检测清单\n- 权限范围评估\n- 风险等级分类\n- 信任层次结构\n\n## v1.0.0 (原始版本)\n- 初始版本发布\n- 基本的技能审查协议\n- 安全优先的设计理念\n\nFile v2.0.0:skill-card.md\n\n## Description:\n\nSkill Vetter Optimized helps agents and reviewers evaluate AI agent skills before installation by checking source trust, permission scope, red flags, and suspicious patterns.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[confidentkai](https://clawhub.ai/user/confidentkai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, security reviewers, and agent operators use this skill to vet skills from ClawHub, GitHub, or other sources before installation. It provides a structured review protocol, checklist, and helper script for triaging obvious risk signals.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The helper script may be mistaken for a complete security scanner.\n\nMitigation: Use it only for quick triage and complete the documented full review before trusting a skill.\n\nRisk: The workflow is Chinese-oriented, which may reduce review accuracy for teams that cannot read the source language.\n\nMitigation: Use qualified reviewers or translation support so all checklist items, findings, and verdicts are understood before installation.\n\n## Reference(s):\n\n- [Skill Review Checklist](references/checklist.md)\n- [ClawHub Skill Page](https://clawhub.ai/confidentkai/skills/skill-vetter-optimized)\n- [Publisher Profile](https://clawhub.ai/user/confidentkai)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown with inline shell commands and checklist-style review output]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces a skill vetting report with source, author, version, red flags, permission needs, risk level, verdict, and notes.]\n\n## Skill Version(s):\n\n2.0.0 (source: frontmatter, changelog, server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: Skill Vetter Optimized Owner: confidentkai Summary: 🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化，添加了Python检查脚本和详细审查流程。 Tags: latest:2.0.0 Version history: v2.0.0 | 2026-04-15T03:52:01.620Z | user 优化版本：添加Python检查脚本、系统化审查清单、完善文档、清理代码结构 Archive index: Archive v2.0.0: 6 files, 8819 bytes Files: CHANGELOG.md (1029b), references/checklist.md (3294b), s","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"Questions to answer:\n- [ ] Where did this skill come from?\n- [ ] Is the author known/reputable?\n- [ ] How many downloads/stars does it have?\n- [ ] When was it last updated?\n- [ ] Are there reviews from other agents?"},{"language":"text","snippet":"🚨 REJECT IMMEDIATELY IF YOU SEE:\n─────────────────────────────────────────\n• curl/wget to unknown URLs\n• Sends data to external servers\n• Requests credentials/tokens/API keys\n• Reads ~/.ssh, ~/.aws, ~/.config without clear reason\n• Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md\n• Uses base64 decode on anything\n• Uses eval() or exec() with external input\n• Modifies system files outside workspace\n• Installs packages without listing them\n• Network calls to IPs instead of domains\n• Obfuscated code (compressed, encoded, minified)\n• Requests elevated/sudo permissions\n• Accesses browser cookies/sessions\n• Touches credential files\n─────────────────────────────────────────"},{"language":"text","snippet":"Evaluate:\n- [ ] What files does it need to read?\n- [ ] What files does it need to write?\n- [ ] What commands does it run?\n- [ ] Does it need network access? To where?\n- [ ] Is the scope minimal for its stated purpose?"},{"language":"text","snippet":"SKILL VETTING REPORT\n═══════════════════════════════════════\nSkill: [name]\nSource: [ClawdHub / GitHub / other]\nAuthor: [username]\nVersion: [version]\n───────────────────────────────────────\nMETRICS:\n• Downloads/Stars: [count]\n• Last Updated: [date]\n• Files Reviewed: [count]\n───────────────────────────────────────\nRED FLAGS: [None / List them]\n\nPERMISSIONS NEEDED:\n• Files: [list or \"None\"]\n• Network: [list or \"None\"]  \n• Commands: [list or \"None\"]\n───────────────────────────────────────\nRISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ EXTREME]\n\nVERDICT: [✅ SAFE TO INSTALL / ⚠️ INSTALL WITH CAUTION / ❌ DO NOT INSTALL]\n\nNOTES: [Any observations]\n═══════════════════════════════════════"},{"language":"bash","snippet":"# 检查技能目录的基本信息和安全风险\npython3 /root/.openclaw/skills/skill-vetter/scripts/skill_checker.py /path/to/skill"},{"language":"bash","snippet":"curl -s \"https://api.github.com/repos/OWNER/REPO\" | jq '{stars: .stargazers_count, forks: .forks_count, updated: .updated_at}'"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: skill-vetter-optimized\nversion: 2.0.0\ndescription: \"🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化，添加了Python检查脚本和详细审查流程。\"\n---\n\n# Skill Vetter Optimized 🔒✨\n\n**优化版技能审查器** - 基于原始skill-vetter优化增强\n\n## 🚀 优化亮点\n\n✅ **新增实用工具** - Python检查脚本快速分析技能目录  \n✅ **系统化审查流程** - 四阶段审查清单  \n✅ **详细文档** - 完整的审查指南和示例  \n✅ **保持兼容** - 完全兼容原始审查协议  \n✅ **性能优化** - 更快的审查流程  \n\nSecurity-first vetting protocol for AI agent skills. **Never install a skill without vetting it first.**\n\n## When to Use\n\n- Before installing any skill from ClawdHub\n- Before running skills from GitHub repos\n- When evaluating skills shared by other agents\n- Anytime you're asked to install unknown code\n\n## Vetting Protocol\n\n### Step 1: Source Check\n\n```\nQuestions to answer:\n- [ ] Where did this skill come from?\n- [ ] Is the author known/reputable?\n- [ ] How many downloads/stars does it have?\n- [ ] When was it last updated?\n- [ ] Are there reviews from other agents?\n```\n\n### Step 2: Code Review (MANDATORY)\n\nRead ALL files in the skill. Check for these **RED FLAGS**:\n\n```\n🚨 REJECT IMMEDIATELY IF YOU SEE:\n─────────────────────────────────────────\n• curl/wget to unknown URLs\n• Sends data to external servers\n• Requests credentials/tokens/API keys\n• Reads ~/.ssh, ~/.aws, ~/.config without clear reason\n• Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md\n• Uses base64 decode on anything\n• Uses eval() or exec() with external input\n• Modifies system files outside workspace\n• Installs packages without listing them\n• Network calls to IPs instead of domains\n• Obfuscated code (compressed, encoded, minified)\n• Requests elevated/sudo permissions\n• Accesses browser cookies/sessions\n• Touches credential files\n─────────────────────────────────────────\n```\n\n### Step 3: Permission Scope\n\n```\nEvaluate:\n- [ ] What files does it need to read?\n- [ ] What files does it need to write?\n- [ ] What commands does it run?\n- [ ] Does it need network access? To where?\n- [ ] Is the scope minimal for its stated purpose?\n```\n\n### Step 4: Risk Classification\n\n| Risk Level | Examples | Action |\n|------------|----------|--------|\n| 🟢 LOW | Notes, weather, formatting | Basic review, install OK |\n| 🟡 MEDIUM | File ops, browser, APIs | Full code review required |\n| 🔴 HIGH | Credentials, trading, system | Human approval required |\n| ⛔ EXTREME | Security configs, root access | Do NOT install |\n\n## Output Format\n\nAfter vetting, produce this report:\n\n```\nSKILL VETTING REPORT\n═══════════════════════════════════════\nSkill: [name]\nSource: [ClawdHub / GitHub / other]\nAuthor: [username]\nVersion: [version]\n───────────────────────────────────────\nMETRICS:\n• Downloads/Stars: [count]\n• Last Updated: [date]\n• Files Reviewed: [count]\n───────────────────────────────────────\nRED FLAGS: [None / List them]\n\nPERMISSIONS NEEDED:\n• Files: [list or \"None\"]\n• Network: [list or \"None\"]  \n• Commands: [list or \"None\"]\n───────────────────────────────────────\nRISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71bmpaxztz381rsxj3mmsnqx82wys2\",\n  \"slug\": \"skill-vetter-optimized\",\n  \"version\": \"2.0.0\",\n  \"publishedAt\": 1776225121620\n}"},{"path":"references/checklist.md","content":"# 技能审查清单\n\n## 第一阶段：基本信息检查\n\n### 1. 来源验证\n- [ ] **来源平台**: ClawHub / GitHub / 其他\n- [ ] **作者信誉**: 已知作者 / 新作者 / 匿名\n- [ ] **下载量/星标数**: 高(>1000) / 中(100-1000) / 低(<100)\n- [ ] **最后更新**: 最近(30天内) / 较近(90天内) / 很久以前\n- [ ] **许可证**: MIT / Apache / GPL / 其他 / 无\n\n### 2. 文件结构检查\n- [ ] **SKILL.md存在**: 是 / 否\n- [ ] **描述清晰**: 是 / 否\n- [ ] **版本号**: 有 / 无\n- [ ] **目录结构合理**: 是 / 否\n- [ ] **文件数量合理**: 是(≤20) / 否(>20)\n\n## 第二阶段：代码安全审查\n\n### 3. 危险模式检查 (立即拒绝如果发现)\n- [ ] **下载并执行**: `curl | bash`, `wget | sh`\n- [ ] **远程代码执行**: `eval()`, `exec()` 带外部输入\n- [ ] **数据外传**: 发送数据到外部服务器\n- [ ] **凭证访问**: 读取SSH密钥、API密钥、密码文件\n- [ ] **系统修改**: 修改系统文件、crontab、启动项\n- [ ] **权限提升**: `sudo`, `chmod 777`, `setuid`\n- [ ] **混淆代码**: base64编码、压缩、混淆\n\n### 4. 权限范围评估\n- [ ] **文件读取**: 明确列出需要读取的文件\n- [ ] **文件写入**: 明确列出需要写入的文件\n- [ ] **网络访问**: 明确列出需要访问的域名/IP\n- [ ] **命令执行**: 明确列出需要执行的命令\n- [ ] **权限最小化**: 权限是否与功能匹配\n\n### 5. 依赖检查\n- [ ] **依赖声明**: package.json / requirements.txt\n- [ ] **依赖安全性**: 已知漏洞检查\n- [ ] **依赖必要性**: 所有依赖都是必要的吗？\n- [ ] **依赖来源**: 官方源 / 第三方源\n\n## 第三阶段：风险评估\n\n### 6. 风险等级评估\n- **🟢 低风险**: 只读操作、格式化、信息展示\n- **🟡 中风险**: 文件操作、网络请求、API调用\n- **🔴 高风险**: 系统命令、凭证访问、数据修改\n- **⛔ 极高风险**: 提权操作、持久化、外传数据\n\n### 7. 上下文评估\n- [ ] **功能与权限匹配**: 是 / 否\n- [ ] **错误处理**: 有 / 无\n- [ ] **日志记录**: 有 / 无\n- [ ] **测试用例**: 有 / 无\n- [ ] **文档完整**: 是 / 否\n\n## 第四阶段：决策与记录\n\n### 8. 审查结论\n- **✅ 安全可安装**: 通过所有检查，风险可控\n- **⚠️ 谨慎安装**: 有中等风险，需要监控\n- **❌ 拒绝安装**: 发现高风险或恶意行为\n\n### 9. 记录保存\n- [ ] **审查报告**: 生成详细报告\n- [ ] **决策理由**: 记录通过/拒绝的理由\n- [ ] **时间戳**: 记录审查时间\n- [ ] **审查者**: 记录审查者信息\n\n## 快速检查命令\n\n```bash\n# 使用辅助脚本检查\npython3 /root/.openclaw/skills/skill-vetter/scripts/skill_checker.py /path/to/skill\n\n# 检查GitHub仓库信息\ncurl -s \"https://api.github.com/repos/owner/repo\" | jq '.stargazers_count, .forks_count, .updated_at'\n\n# 列出技能文件\nfind /path/to/skill -type f -name \"*.py\" -o -name \"*.sh\" -o -name \"*.js\"\n```\n\n## 注意事项\n\n1. **零信任原则**: 默认不信任，需要验证\n2. **最小权限**: 只授予必要的权限\n3. **持续监控**: 安装后仍需监控行为\n4. **及时更新**: 关注安全更新和漏洞\n5. **备份恢复**: 重要系统做好备份\n\n---\n\n*安全不是功能，而是基础。* 🔒"},{"path":"CHANGELOG.md","content":"# 更新日志 - Skill Vetter\n\n## v2.0.0 (2026-04-15)\n\n### 优化内容\n1. **清理无关文件**\n   - 删除 `_meta.json` (安装时生成的元数据文件)\n\n2. **新增实用工具**\n   - `scripts/skill_checker.py` - Python辅助检查脚本\n   - `references/checklist.md` - 系统化审查清单\n\n3. **更新SKILL.md**\n   - 更新版本号至 2.0.0\n   - 优化描述信息\n   - 添加对新工具的说明\n   - 保持核心审查协议完整\n\n### 新增功能\n1. **技能检查脚本** (`skill_checker.py`)\n   - 快速检查技能目录结构\n   - 提取SKILL.md元数据\n   - 检测常见危险模式\n   - 生成初步风险评估\n\n2. **系统化审查清单** (`checklist.md`)\n   - 四阶段审查流程\n   - 详细的检查项目\n   - 风险评估标准\n   - 决策记录模板\n\n### 核心功能保留\n- 安全优先的审查协议\n- 红标检测清单\n- 权限范围评估\n- 风险等级分类\n- 信任层次结构\n\n## v1.0.0 (原始版本)\n- 初始版本发布\n- 基本的技能审查协议\n- 安全优先的设计理念"},{"path":"skill-card.md","content":"## Description:\n\nSkill Vetter Optimized helps agents and reviewers evaluate AI agent skills before installation by checking source trust, permission scope, red flags, and suspicious patterns.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[confidentkai](https://clawhub.ai/user/confidentkai)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, security reviewers, and agent operators use this skill to vet skills from ClawHub, GitHub, or other sources before installation. It provides a structured review protocol, checklist, and helper script for triaging obvious risk signals.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The helper script may be mistaken for a complete security scanner.\n\nMitigation: Use it only for quick triage and complete the documented full review before trusting a skill.\n\nRisk: The workflow is Chinese-oriented, which may reduce review accuracy for teams that cannot read the source language.\n\nMitigation: Use qualified reviewers or translation support so all checklist items, findings, and verdicts are understood before installation.\n\n## Reference(s):\n\n- [Skill Review Checklist](references/checklist.md)\n- [ClawHub Skill Page](https://clawhub.ai/confidentkai/skills/skill-vetter-optimized)\n- [Publisher Profile](https://clawhub.ai/user/confidentkai)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown with inline shell commands and checklist-style review output]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces a skill vetting report with source, author, version, red flags, permission needs, risk level, verdict, and notes.]\n\n## Skill Version(s):\n\n2.0.0 (source: frontmatter, changelog, server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化，添加了Python检查脚本和详细审查流程。 Skill: Skill Vetter Optimized Owner: confidentkai Summary: 🔒 优化版技能审查器 - 安全优先的AI代理技能审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。检查红标、权限范围和可疑模式。包含实用工具和系统化审查清单。基于原始skill-vetter优化，添加了Python检查脚本和详细审查流程。 Tags: latest:2.0.0 Version history: v2.0.0 | 2026-04-15T03:52:01.620Z | user 优化版本：添加Python检查脚本、系统化审查清单、完善文档、清理代码结构 Archive index: Archive v2.0.0: 6 files, 8819 bytes Files: CHANGELOG.md (1029b), references/checklist.md (3294b), s","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":809,"uniquenessScore":57,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T20:04:42.282Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T20:04:42.282Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T23:46:32.546Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}