{"id":"5cb59811-3428-44ff-a5bd-89425b8100e1","entityType":"agent","slug":"clawhub-nerua1-nerua1-skill-vetter","name":"Skill Vetter — Security Audit for AI Skills","canonicalUrl":"https://www.xpersona.co/agent/clawhub-nerua1-nerua1-skill-vetter","canonicalPath":"/agent/clawhub-nerua1-nerua1-skill-vetter","generatedAt":"2026-10-10T08:09:46.112Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T21:53:31.061Z","emptyReason":null},"description":"Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... Skill: Skill Vetter — Security Audit for AI Skills Owner: nerua1 Summary: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... Tags: audit:1.0.0, latest:1.0.0, safety:1.0.0, security:1.0.0, skills:1.0.0, vetting:1.0.0 Version history: v1.0.0 | 2026-05-03T23:17:16.977Z | auto - Initial release of skill-vetter (v1","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s178f4bnw35dnxc3ymhvgf114983yzer:nerua1-skill-vetter","sourceUrl":"https://clawhub.ai/nerua1/nerua1-skill-vetter","homepage":"https://clawhub.ai/nerua1/skills/nerua1-skill-vetter","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/nerua1/nerua1-skill-vetter","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/nerua1/skills/nerua1-skill-vetter","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":66,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... "},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:53:31.061Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:53:31.061Z","emptyReason":null},"stars":null,"forks":null,"downloads":1958,"packageName":null,"latestVersion":"1.0.0","tractionLabel":"2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:53:31.061Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T21:53:31.061Z","lastCrawledAt":"2026-10-09T21:53:31.061Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T21:53:31.061Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.0","createdAt":"2026-05-03T23:17:16.977Z","changelog":"- Initial release of skill-vetter (v1.0.0): a security-first vetting protocol for AI agent skills. - Provides a structured checklist and report format to assess skill sources, code, permission scope, and risk. - Includes clear red flags, trust hierarchy, and actionable risk classifications. - Offers quick vet commands for GitHub skills and strong install guidance. - Emphasizes never installing unvetted skills and prioritizes security at every step.","fileCount":3,"zipByteSize":3525}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s178f4bnw35dnxc3ymhvgf114983yzer:nerua1-skill-vetter","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T08:09:46.112Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nerua1-nerua1-skill-vetter/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T21:53:31.061Z","emptyReason":null},"readme":"Skill: Skill Vetter — Security Audit for AI Skills\n\nOwner: nerua1\n\nSummary: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...\n\nTags: audit:1.0.0, latest:1.0.0, safety:1.0.0, security:1.0.0, skills:1.0.0, vetting:1.0.0\n\nVersion history:\n\nv1.0.0 | 2026-05-03T23:17:16.977Z | auto\n\n- Initial release of skill-vetter (v1.0.0): a security-first vetting protocol for AI agent skills.\n- Provides a structured checklist and report format to assess skill sources, code, permission scope, and risk.\n- Includes clear red flags, trust hierarchy, and actionable risk classifications.\n- Offers quick vet commands for GitHub skills and strong install guidance.\n- Emphasizes never installing unvetted skills and prioritizes security at every step.\n\nArchive index:\n\nArchive v1.0.0: 3 files, 3525 bytes\n\nFiles: _meta.json (138b), skill-card.md (2020b), SKILL.md (4701b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: skill-vetter\nversion: 1.0.0\ndescription: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.\n---\n\n# Skill Vetter 🔒\n\nSecurity-first vetting protocol for AI agent skills. **Never install a skill without vetting it first.**\n\n## When to Use\n\n- Before installing any skill from ClawdHub\n- Before running skills from GitHub repos\n- When evaluating skills shared by other agents\n- Anytime you're asked to install unknown code\n\n## Vetting Protocol\n\n### Step 1: Source Check\n\n```\nQuestions to answer:\n- [ ] Where did this skill come from?\n- [ ] Is the author known/reputable?\n- [ ] How many downloads/stars does it have?\n- [ ] When was it last updated?\n- [ ] Are there reviews from other agents?\n```\n\n### Step 2: Code Review (MANDATORY)\n\nRead ALL files in the skill. Check for these **RED FLAGS**:\n\n```\n🚨 REJECT IMMEDIATELY IF YOU SEE:\n─────────────────────────────────────────\n• curl/wget to unknown URLs\n• Sends data to external servers\n• Requests credentials/tokens/API keys\n• Reads ~/.ssh, ~/.aws, ~/.config without clear reason\n• Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md\n• Uses base64 decode on anything\n• Uses eval() or exec() with external input\n• Modifies system files outside workspace\n• Installs packages without listing them\n• Network calls to IPs instead of domains\n• Obfuscated code (compressed, encoded, minified)\n• Requests elevated/sudo permissions\n• Accesses browser cookies/sessions\n• Touches credential files\n─────────────────────────────────────────\n```\n\n### Step 3: Permission Scope\n\n```\nEvaluate:\n- [ ] What files does it need to read?\n- [ ] What files does it need to write?\n- [ ] What commands does it run?\n- [ ] Does it need network access? To where?\n- [ ] Is the scope minimal for its stated purpose?\n```\n\n### Step 4: Risk Classification\n\n| Risk Level | Examples | Action |\n|------------|----------|--------|\n| 🟢 LOW | Notes, weather, formatting | Basic review, install OK |\n| 🟡 MEDIUM | File ops, browser, APIs | Full code review required |\n| 🔴 HIGH | Credentials, trading, system | Human approval required |\n| ⛔ EXTREME | Security configs, root access | Do NOT install |\n\n## Output Format\n\nAfter vetting, produce this report:\n\n```\nSKILL VETTING REPORT\n═══════════════════════════════════════\nSkill: [name]\nSource: [ClawdHub / GitHub / other]\nAuthor: [username]\nVersion: [version]\n───────────────────────────────────────\nMETRICS:\n• Downloads/Stars: [count]\n• Last Updated: [date]\n• Files Reviewed: [count]\n───────────────────────────────────────\nRED FLAGS: [None / List them]\n\nPERMISSIONS NEEDED:\n• Files: [list or \"None\"]\n• Network: [list or \"None\"]  \n• Commands: [list or \"None\"]\n───────────────────────────────────────\nRISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ EXTREME]\n\nVERDICT: [✅ SAFE TO INSTALL / ⚠️ INSTALL WITH CAUTION / ❌ DO NOT INSTALL]\n\nNOTES: [Any observations]\n═══════════════════════════════════════\n```\n\n## Quick Vet Commands\n\nFor GitHub-hosted skills:\n```bash\n# Check repo stats\ncurl -s \"https://api.github.com/repos/OWNER/REPO\" | jq '{stars: .stargazers_count, forks: .forks_count, updated: .updated_at}'\n\n# List skill files\ncurl -s \"https://api.github.com/repos/OWNER/REPO/contents/skills/SKILL_NAME\" | jq '.[].name'\n\n# Fetch and review SKILL.md\ncurl -s \"https://raw.githubusercontent.com/OWNER/REPO/main/skills/SKILL_NAME/SKILL.md\"\n```\n\n## Trust Hierarchy\n\n1. **Official OpenClaw skills** → Lower scrutiny (still review)\n2. **High-star repos (1000+)** → Moderate scrutiny\n3. **Known authors** → Moderate scrutiny\n4. **New/unknown sources** → Maximum scrutiny\n5. **Skills requesting credentials** → Human approval always\n\n## Remember\n\n- No skill is worth compromising security\n- When in doubt, don't install\n- Ask your human for high-risk decisions\n- Document what you vet for future reference\n\n---\n\n*Paranoia is a feature.* 🔒🦀\n\n---\n\nIf this saved you time: [☕ PayPal.me/nerudek](https://www.paypal.me/nerudek)\nGitHub: [github.com/nerua1](https://github.com/nerua1)\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn76wb59qjkjfvxkchxa79a3wx83yeds\",\n  \"slug\": \"nerua1-skill-vetter\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1777850236977\n}\n\nFile v1.0.0:skill-card.md\n\n## Description:\n\nSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[nerua1](https://clawhub.ai/user/nerua1)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, engineers, and agent operators use this skill to review AI agent skills before installation, checking source trust, permissions, suspicious patterns, and install risk.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill may prompt an agent to inspect candidate skill files and run GitHub lookup commands while reviewing third-party skills.\n\nMitigation: Review generated commands before execution, especially when assessing private repositories or sources that may expose sensitive metadata.\n\nRisk: The skill's audit guidance can classify install risk, but it does not replace human approval for high-risk skills.\n\nMitigation: Require human review before installing skills that request credentials, broad filesystem access, elevated permissions, or access to sensitive files.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/nerua1/skills/nerua1-skill-vetter)\n- [Publisher profile](https://clawhub.ai/user/nerua1)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown checklist and vetting report with optional shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces human-readable risk classifications, verdicts, notes, and permission-scope summaries.]\n\n## Skill Version(s):\n\n1.0.0 (source: frontmatter and release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.","readmeExcerpt":"Skill: Skill Vetter — Security Audit for AI Skills Owner: nerua1 Summary: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... Tags: audit:1.0.0, latest:1.0.0, safety:1.0.0, security:1.0.0, skills:1.0.0, vetting:1.0.0 Version history: v1.0.0 | 2026-05-03T23:17:16.977Z | auto - Initial release of skill-vetter (v1","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"Questions to answer:\n- [ ] Where did this skill come from?\n- [ ] Is the author known/reputable?\n- [ ] How many downloads/stars does it have?\n- [ ] When was it last updated?\n- [ ] Are there reviews from other agents?"},{"language":"text","snippet":"🚨 REJECT IMMEDIATELY IF YOU SEE:\n─────────────────────────────────────────\n• curl/wget to unknown URLs\n• Sends data to external servers\n• Requests credentials/tokens/API keys\n• Reads ~/.ssh, ~/.aws, ~/.config without clear reason\n• Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md\n• Uses base64 decode on anything\n• Uses eval() or exec() with external input\n• Modifies system files outside workspace\n• Installs packages without listing them\n• Network calls to IPs instead of domains\n• Obfuscated code (compressed, encoded, minified)\n• Requests elevated/sudo permissions\n• Accesses browser cookies/sessions\n• Touches credential files\n─────────────────────────────────────────"},{"language":"text","snippet":"Evaluate:\n- [ ] What files does it need to read?\n- [ ] What files does it need to write?\n- [ ] What commands does it run?\n- [ ] Does it need network access? To where?\n- [ ] Is the scope minimal for its stated purpose?"},{"language":"text","snippet":"SKILL VETTING REPORT\n═══════════════════════════════════════\nSkill: [name]\nSource: [ClawdHub / GitHub / other]\nAuthor: [username]\nVersion: [version]\n───────────────────────────────────────\nMETRICS:\n• Downloads/Stars: [count]\n• Last Updated: [date]\n• Files Reviewed: [count]\n───────────────────────────────────────\nRED FLAGS: [None / List them]\n\nPERMISSIONS NEEDED:\n• Files: [list or \"None\"]\n• Network: [list or \"None\"]  \n• Commands: [list or \"None\"]\n───────────────────────────────────────\nRISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ EXTREME]\n\nVERDICT: [✅ SAFE TO INSTALL / ⚠️ INSTALL WITH CAUTION / ❌ DO NOT INSTALL]\n\nNOTES: [Any observations]\n═══════════════════════════════════════"},{"language":"bash","snippet":"curl -s \"https://api.github.com/repos/OWNER/REPO\" | jq '{stars: .stargazers_count, forks: .forks_count, updated: .updated_at}'"},{"language":"bash","snippet":"curl -s \"https://api.github.com/repos/OWNER/REPO/contents/skills/SKILL_NAME\" | jq '.[].name'"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: skill-vetter\nversion: 1.0.0\ndescription: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.\n---\n\n# Skill Vetter 🔒\n\nSecurity-first vetting protocol for AI agent skills. **Never install a skill without vetting it first.**\n\n## When to Use\n\n- Before installing any skill from ClawdHub\n- Before running skills from GitHub repos\n- When evaluating skills shared by other agents\n- Anytime you're asked to install unknown code\n\n## Vetting Protocol\n\n### Step 1: Source Check\n\n```\nQuestions to answer:\n- [ ] Where did this skill come from?\n- [ ] Is the author known/reputable?\n- [ ] How many downloads/stars does it have?\n- [ ] When was it last updated?\n- [ ] Are there reviews from other agents?\n```\n\n### Step 2: Code Review (MANDATORY)\n\nRead ALL files in the skill. Check for these **RED FLAGS**:\n\n```\n🚨 REJECT IMMEDIATELY IF YOU SEE:\n─────────────────────────────────────────\n• curl/wget to unknown URLs\n• Sends data to external servers\n• Requests credentials/tokens/API keys\n• Reads ~/.ssh, ~/.aws, ~/.config without clear reason\n• Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md\n• Uses base64 decode on anything\n• Uses eval() or exec() with external input\n• Modifies system files outside workspace\n• Installs packages without listing them\n• Network calls to IPs instead of domains\n• Obfuscated code (compressed, encoded, minified)\n• Requests elevated/sudo permissions\n• Accesses browser cookies/sessions\n• Touches credential files\n─────────────────────────────────────────\n```\n\n### Step 3: Permission Scope\n\n```\nEvaluate:\n- [ ] What files does it need to read?\n- [ ] What files does it need to write?\n- [ ] What commands does it run?\n- [ ] Does it need network access? To where?\n- [ ] Is the scope minimal for its stated purpose?\n```\n\n### Step 4: Risk Classification\n\n| Risk Level | Examples | Action |\n|------------|----------|--------|\n| 🟢 LOW | Notes, weather, formatting | Basic review, install OK |\n| 🟡 MEDIUM | File ops, browser, APIs | Full code review required |\n| 🔴 HIGH | Credentials, trading, system | Human approval required |\n| ⛔ EXTREME | Security configs, root access | Do NOT install |\n\n## Output Format\n\nAfter vetting, produce this report:\n\n```\nSKILL VETTING REPORT\n═══════════════════════════════════════\nSkill: [name]\nSource: [ClawdHub / GitHub / other]\nAuthor: [username]\nVersion: [version]\n───────────────────────────────────────\nMETRICS:\n• Downloads/Stars: [count]\n• Last Updated: [date]\n• Files Reviewed: [count]\n───────────────────────────────────────\nRED FLAGS: [None / List them]\n\nPERMISSIONS NEEDED:\n• Files: [list or \"None\"]\n• Network: [list or \"None\"]  \n• Commands: [list or \"None\"]\n───────────────────────────────────────\nRISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ EXTREME]\n\nVERDICT: [✅ SAFE TO INSTALL / ⚠️ INSTALL WITH CAUTION / ❌ DO NOT INSTALL]\n\nNOTES: [Any observations]\n═══════════════════════════════════════\n```\n\n## Q"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn76wb59qjkjfvxkchxa79a3wx83yeds\",\n  \"slug\": \"nerua1-skill-vetter\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1777850236977\n}"},{"path":"skill-card.md","content":"## Description:\n\nSecurity-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[nerua1](https://clawhub.ai/user/nerua1)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, engineers, and agent operators use this skill to review AI agent skills before installation, checking source trust, permissions, suspicious patterns, and install risk.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill may prompt an agent to inspect candidate skill files and run GitHub lookup commands while reviewing third-party skills.\n\nMitigation: Review generated commands before execution, especially when assessing private repositories or sources that may expose sensitive metadata.\n\nRisk: The skill's audit guidance can classify install risk, but it does not replace human approval for high-risk skills.\n\nMitigation: Require human review before installing skills that request credentials, broad filesystem access, elevated permissions, or access to sensitive files.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/nerua1/skills/nerua1-skill-vetter)\n- [Publisher profile](https://clawhub.ai/user/nerua1)\n\n## Skill Output:\n\n**Output Type(s):** [Analysis, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Markdown checklist and vetting report with optional shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces human-readable risk classifications, verdicts, notes, and permission-scope summaries.]\n\n## Skill Version(s):\n\n1.0.0 (source: frontmatter and release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... Skill: Skill Vetter — Security Audit for AI Skills Owner: nerua1 Summary: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... Tags: audit:1.0.0, latest:1.0.0, safety:1.0.0, security:1.0.0, skills:1.0.0, vetting:1.0.0 Version history: v1.0.0 | 2026-05-03T23:17:16.977Z | auto - Initial release of skill-vetter (v1","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":904,"uniquenessScore":48,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T21:53:31.061Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T21:53:31.061Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:09:46.112Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}