{"id":"89905100-e086-40ce-9a2c-8168be88a556","entityType":"agent","slug":"clawhub-nutstrut-skill-vetter-v2","name":"Skill Vetter V2 0.0.6","canonicalUrl":"https://www.xpersona.co/agent/clawhub-nutstrut-skill-vetter-v2","canonicalPath":"/agent/clawhub-nutstrut-skill-vetter-v2","generatedAt":"2026-10-09T19:43:04.248Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:34:33.669Z","emptyReason":null},"description":"Verification-guided review workflow for inspecting skill packages before use or publication. Classifies risk and flags claims that exceed evidence. Does not...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 4.3K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s1727xn24msgdvsrzx31kvyn9d83jk5t:skill-vetter-v2","sourceUrl":"https://clawhub.ai/nutstrut/skill-vetter-v2","homepage":"https://clawhub.ai/nutstrut/skills/skill-vetter-v2","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/nutstrut/skill-vetter-v2","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/nutstrut/skills/skill-vetter-v2","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":67,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Skill Vetter V2 0.0.6 technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:34:33.669Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:34:33.669Z","emptyReason":null},"stars":null,"forks":null,"downloads":4334,"packageName":null,"latestVersion":"0.0.6","tractionLabel":"4.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:34:33.669Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T05:34:33.669Z","lastCrawledAt":"2026-10-09T05:34:33.669Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T05:34:33.669Z","lastVerifiedAt":null,"highlights":[{"version":"0.0.6","createdAt":"2026-07-04T06:54:22.918Z","changelog":"Claim precision correction: clarified skill is a verifiability-guided workflow aid. Does not perform cryptographic verification, emit Settlement Attestation Receipts, or prove skills are safe. Removed placeholder install URL. Added boundary, category, and claim-precision note sections.","fileCount":13,"zipByteSize":12597},{"version":"0.0.5","createdAt":"2026-03-29T21:04:57.711Z","changelog":"- Added concrete usage examples, including sample input and output JSON vetting reports. - Updated the report output format section for clarity and reference. - Improved formatting and consistency throughout documentation (e.g., use of bullet points, headers). - Clarified optional verification workflow and step-by-step reporting process. - No functionality changes; documentation enhancements only.","fileCount":16,"zipByteSize":13184},{"version":"0.0.4","createdAt":"2026-03-29T19:15:59.186Z","changelog":"* Rewrote `SKILL.md` for clarity, stronger guidance, and safer presentation. * Added report templates and review checklists to standardize skill safety analysis. * Added `.learnings/` files for tracking errors, feature requests, and operational learnings. * Included example OpenClaw integration files, hooks, and local scan helpers. * Clarified the optional SettlementWitness verification flow without changing the core evaluation model. * Removed `error-detector.sh` to eliminate a false-positive dynamic execution flag in ClawHub security scan. * Improved overall package safety and install trust. * No core logic changes; this release focuses on documentation, templates, and integration support.","fileCount":15,"zipByteSize":11492},{"version":"0.0.3","createdAt":"2026-03-29T19:09:40.761Z","changelog":"* Rewrote `SKILL.md` for clarity, stronger guidance, and safer presentation. * Added report templates and review checklists to standardize skill safety analysis. * Added `.learnings/` files for tracking errors, feature requests, and operational learnings. * Included example OpenClaw integration files, hooks, and local scan helpers. * Clarified the optional SettlementWitness verification flow without changing the core evaluation model. * Improved package completeness and usability for real-world agent workflows. * No core logic changes; this release focuses on documentation, templates, and integration support.","fileCount":16,"zipByteSize":12121},{"version":"0.0.2","createdAt":"2026-03-29T14:19:49.635Z","changelog":"Improved summary and top-level description for clarity and higher conversion. No functional changes.","fileCount":3,"zipByteSize":2780},{"version":"0.0.1","createdAt":"2026-03-27T17:40:02.616Z","changelog":"Introduced local-first safety evaluation with structured risk classification, external service transparency model, and optional SAR attestation.","fileCount":2,"zipByteSize":1985}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s1727xn24msgdvsrzx31kvyn9d83jk5t:skill-vetter-v2","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s1727xn24msgdvsrzx31kvyn9d83jk5t:skill-vetter-v2` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/nutstrut/skill-vetter-v2 before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T19:43:04.245Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-nutstrut-skill-vetter-v2/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T05:34:33.669Z","emptyReason":null},"readme":"Skill: Skill Vetter V2 0.0.6\n\nOwner: nutstrut\n\nSummary: Verification-guided review workflow for inspecting skill packages before use or publication. Classifies risk and flags claims that exceed evidence. Does not...\n\nTags: latest:0.0.6\n\nVersion history:\n\nv0.0.6 | 2026-07-04T06:54:22.918Z | user\n\nClaim precision correction: clarified skill is a verifiability-guided workflow aid. Does not perform cryptographic verification, emit Settlement Attestation Receipts, or prove skills are safe. Removed placeholder install URL. Added boundary, category, and claim-precision note sections.\n\nv0.0.5 | 2026-03-29T21:04:57.711Z | user\n\n- Added concrete usage examples, including sample input and output JSON vetting reports.\n- Updated the report output format section for clarity and reference.\n- Improved formatting and consistency throughout documentation (e.g., use of bullet points, headers).\n- Clarified optional verification workflow and step-by-step reporting process.\n- No functionality changes; documentation enhancements only.\n\nv0.0.4 | 2026-03-29T19:15:59.186Z | user\n\n* Rewrote `SKILL.md` for clarity, stronger guidance, and safer presentation.\n* Added report templates and review checklists to standardize skill safety analysis.\n* Added `.learnings/` files for tracking errors, feature requests, and operational learnings.\n* Included example OpenClaw integration files, hooks, and local scan helpers.\n* Clarified the optional SettlementWitness verification flow without changing the core evaluation model.\n* Removed `error-detector.sh` to eliminate a false-positive dynamic execution flag in ClawHub security scan.\n* Improved overall package safety and install trust.\n* No core logic changes; this release focuses on documentation, templates, and integration support.\n\nv0.0.3 | 2026-03-29T19:09:40.761Z | user\n\n* Rewrote `SKILL.md` for clarity, stronger guidance, and safer presentation.\n* Added report templates and review checklists to standardize skill safety analysis.\n* Added `.learnings/` files for tracking errors, feature requests, and operational learnings.\n* Included example OpenClaw integration files, hooks, and local scan helpers.\n* Clarified the optional SettlementWitness verification flow without changing the core evaluation model.\n* Improved package completeness and usability for real-world agent workflows.\n* No core logic changes; this release focuses on documentation, templates, and integration support.\n\nv0.0.2 | 2026-03-29T14:19:49.635Z | user\n\nImproved summary and top-level description for clarity and higher conversion. No functional changes.\n\nv0.0.1 | 2026-03-27T17:40:02.616Z | user\n\nIntroduced local-first safety evaluation with structured risk classification, external service transparency model, and optional SAR attestation.\n\nArchive index:\n\nArchive v0.0.6: 13 files, 12597 bytes\n\nFiles: _meta.json (134b), assets/REPORT-TEMPLATE.md (528b), assets/REVIEW-CHECKLIST.md (457b), hooks/openclaw/handler.js (1038b), hooks/openclaw/handler.ts (1056b), hooks/openclaw/HOOK.md (586b), README.md (3452b), references/examples.md (910b), references/openclaw-integration.md (763b), scripts/activator.sh (458b), scripts/scan-skill.sh (1471b), skill-card.md (2186b), SKILL.md (10672b)\n\nFile v0.0.6:SKILL.md\n\n---\n\nname: skill-vetter-v2\ndescription: Verification-guided review workflow for inspecting skill packages before use or publication. Classifies risk and flags claims that exceed evidence. Does not itself perform cryptographic verification, emit receipts, or prove a skill is safe.\nmetadata:\n---------\n\n# Skill Vetter v2\n\nSkill Vetter v2 is a verification-guided review skill for inspecting Claude/OpenClaw skill packages before use or publication.\n\nIt helps identify risky instructions, unclear authority boundaries, hidden assumptions, undeclared egress, provenance gaps, and claims that exceed evidence.\n\nThis skill does not itself perform cryptographic verification, emit Settlement Attestation Receipts, or prove that a skill is safe. It is a structured review workflow.\n\nFor actual receipt verification, use SettlementWitness or DefaultVerifier MCP verify_receipt.\n\nCategory: verifiability-guided workflow skill.\n\nBoundary: Skill Vetter v2 reviews claims and risk signals; it does not certify, approve, execute, or cryptographically verify artifacts.\n\n---\n\nAnalyze skills before installation or use. Classify capabilities, risks, and trust dependencies with structured local review. Optionally verify the completed report with SettlementWitness.\n\nThis is a **packaged vetting skill**, not a thin wrapper. It preserves local inspection as the primary decision path and adds an optional verification layer for auditability.\n\n## Data handling and trust\n\nThis skill defines a **local review workflow** with an optional verification step for the final report.\n\n* Perform capability analysis and risk classification locally\n* Do **not** send secrets, credentials, private keys, seed phrases, personal data, or full private repositories to any external service\n* If optional verification is used, send only the minimum structured task data needed to validate the report\n* Verification does **not** decide whether a skill is safe to install; it only validates that the vetting report matches the stated evaluation spec\n* Identity is optional; no wallet access, account access, or credentials are required\n\n## Core Principle\n\nNever outsource the safety decision.\n\nExternal systems may help verify that a report was produced correctly, but the actual judgment about whether a skill should be trusted remains local and reviewable.\n\n## Quick Reference\n\n| Situation                                      | Action                                                         |\n| ---------------------------------------------- | -------------------------------------------------------------- |\n| New skill from unknown source                  | Run full local vetting workflow                                |\n| Skill asks for secrets or credentials          | Escalate risk immediately                                      |\n| Skill writes outside workspace                 | Mark as high risk unless clearly justified                     |\n| Skill calls external services                  | Classify trust dependency and data exposure                    |\n| Skill contains obfuscation or hidden execution | Mark unsafe                                                    |\n| Final report is complete                       | Optionally verify the report structure and verdict consistency |\n| Verification returns PASS                      | Attach receipt metadata to the report                          |\n| Verification returns FAIL                      | Re-check findings and correct the report                       |\n| Verification returns INDETERMINATE             | Hold for manual review; do not treat as verified               |\n\n## What This Skill Does\n\nSkill Vetter v2 evaluates a target skill across four dimensions:\n\n1. **Purpose and scope**\n   What the skill claims to do, and whether its requested capabilities match that purpose.\n\n2. **Install-time behavior**\n   File writes, package installs, hooks, system changes, or bootstrap modifications.\n\n3. **Runtime behavior**\n   Commands, file access, network access, external APIs, tool usage, and data handling.\n\n4. **Trust dependency**\n   Whether the skill depends on transparent and reviewable systems, or on opaque and unverifiable services.\n\n## Core Execution Loop\n\n1. Inspect the skill package locally\n\n   * `SKILL.md`\n   * `README.md` and references\n   * scripts, hooks, assets, templates\n   * metadata and install surface\n\n2. Identify declared and implied capabilities\n\n   * file reads and writes\n   * command execution\n   * package installation\n   * network or API usage\n   * handling of credentials, memory, or sensitive files\n\n3. Evaluate risk\n\n   * install-time risk\n   * runtime risk\n   * data exposure risk\n   * trust dependency risk\n\n4. Generate a structured report\n\n5. Optional: verify the completed report\n\n   * define a deterministic verification spec for the report structure and verdict logic\n   * run verification only on the minimal structured report payload\n   * attach receipt metadata only when verification passes\n\n## Risk Evaluation Categories\n\n### Install-Time Risk\n\nReview for:\n\n* file writes outside the workspace\n* package installs or dependency changes\n* shell profile or system configuration changes\n* hook registration or startup injection\n* hidden setup steps not stated in the docs\n\n### Runtime Risk\n\nReview for:\n\n* external API calls\n* arbitrary command execution\n* broad file system access\n* credential discovery or token handling\n* browser/session access\n* transmission of user data or memory files\n\n### Trust Dependency\n\nClassify the skill's external dependencies:\n\n* **none** — local-only behavior, no external trust dependency\n* **transparent** — external dependency is narrow, explicit, and independently understandable\n* **opaque** — external dependency is broad, hidden, unverifiable, or requests sensitive data\n\n## Red Flags\n\nReject or escalate immediately if you find:\n\n* requests for credentials, API keys, seed phrases, or private keys\n* access to secret stores or credential directories without a clear need\n* obfuscated or encoded execution logic intended to hide behavior\n* silent network transmission of prompts, memory, or workspace files\n* writes outside expected directories without a clear reason\n* privilege escalation or system-level modification\n* unexplained background processes, persistence, or surveillance behavior\n\n## Output Format\n\n```json id=\"m8yx3p\"\n{\n  \"skill_name\": \"...\",\n  \"purpose\": \"...\",\n  \"source\": \"clawhub | github | local | other\",\n  \"capabilities\": [\"...\"],\n  \"install_risk\": \"low | medium | high | extreme\",\n  \"runtime_risk\": \"low | medium | high | extreme\",\n  \"trust_dependency\": \"none | transparent | opaque\",\n  \"warnings\": [\"...\"],\n  \"recommendations\": [\"...\"],\n  \"verdict\": \"safe | caution | unsafe\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run | pass | fail | indeterminate\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\n---\n\n## Example Usage\n\n### Input (Skill to Review)\n\n```json id=\"9j3kdx\"\n{\n  \"skill_name\": \"example-email-sender\",\n  \"source\": \"github\",\n  \"description\": \"Sends automated emails using an external API\",\n  \"files\": [\"SKILL.md\", \"scripts/send-email.sh\"]\n}\n```\n\n### Output (Vetting Report)\n\n```json id=\"4n6rfa\"\n{\n  \"skill_name\": \"example-email-sender\",\n  \"purpose\": \"Send automated emails via external API\",\n  \"source\": \"github\",\n  \"capabilities\": [\n    \"network access\",\n    \"external API calls\",\n    \"file read/write\"\n  ],\n  \"install_risk\": \"low\",\n  \"runtime_risk\": \"medium\",\n  \"trust_dependency\": \"opaque\",\n  \"warnings\": [\n    \"Uses external API with unclear data handling\",\n    \"No transparency on where email content is sent\"\n  ],\n  \"recommendations\": [\n    \"Verify API endpoint and data handling policy\",\n    \"Limit data exposure before use\"\n  ],\n  \"verdict\": \"caution\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\n---\n\n## Optional Verification Workflow\n\nUse verification only after the local review is complete.\n\nRecommended pattern:\n\n1. Define a deterministic verification spec for the report\n\n   * required fields present\n   * risk labels internally consistent\n   * verdict supported by findings\n   * no prohibited data included\n\n2. Submit only the structured report and spec\n\n3. Interpret results conservatively\n\n   * **PASS** → attach receipt metadata and mark `verified: true`\n   * **FAIL** → correct the report and keep `verified: false`\n   * **INDETERMINATE** → keep `verified: false` and escalate for manual review\n\nVerification is optional and must never override local safety concerns.\n\n## OpenClaw Setup (Recommended)\n\nOpenClaw is the best fit for this skill because it supports packaged skills, hooks, and workspace context.\n\n### Installation\n\n**Via ClawHub:**\n\n```bash id=\"t2j9mf\"\nclawdhub install skill-vetter-v2\n```\n\n**Manual:**\n\nThis legacy package does not currently publish a source install URL. Use the ClawHub listing/package as the reference artifact.\n\n### Optional Hook\n\nInstall the reminder hook if you want a prompt to vet skills before trusting them:\n\n```bash id=\"0xptv9\"\ncp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2\nopenclaw hooks enable skill-vetter-v2\n```\n\n### Local Scan Helper\n\nRun the local helper against a skill folder:\n\n```bash id=\"z7p2qs\"\nbash scripts/scan-skill.sh /path/to/skill\n```\n\nThis helper inventories files and flags common red-patterns locally. It does not make network calls.\n\n## Generic Setup (Other Agents)\n\nUse this skill with Claude Code, Codex, Copilot, or other agents by copying the package into your skills directory and reviewing target skills locally.\n\nSuggested workflow:\n\n1. Read the target `SKILL.md`\n2. Read all scripts, hooks, and references\n3. Run the local scan helper\n4. Write the structured report\n5. Optionally verify the report\n\n## What This Is Not\n\n* not an installer\n* not an auto-executor for unknown code\n* not an external decision authority\n* not a replacement for human judgment on high-risk skills\n\n## Outcome\n\nAgents can:\n\n* understand what a skill actually does before use\n* identify install-time and runtime risks clearly\n* separate transparent dependencies from opaque trust requirements\n* keep safety decisions local while optionally producing verifiable records\n\n## Claim precision note\n\nThis version clarifies that the skill is a verifiability-guided workflow aid. It does not itself perform cryptographic verification, emit Settlement Attestation Receipts, verify receipts, verify signatures, prove that a skill is safe, or approve execution. For receipt verification, use SettlementWitness or DefaultVerifier MCP verify_receipt.\n\n## Keywords\n\nai-agents, skill-safety, risk-analysis, verification, trust, security\n\nFile v0.0.6:README.md\n\n# Skill Vetter v2\n\n**Know what a skill does before you trust it.**\n\nSkill Vetter v2 is a packaged safety-review skill for evaluating agent skills before installation or use. It preserves a local, review-first workflow and adds optional SettlementWitness verification for the finished report.\n\n## Why this exists\n\nMost agent skills are installed based on a short description and a guess.\n\nThat creates avoidable risk:\n- hidden file access\n- undisclosed network behavior\n- silent trust in opaque external services\n- credential exposure or workspace exfiltration\n\nSkill Vetter v2 makes those risks visible before a skill is trusted.\n\n## What it analyzes\n\nEvery target skill is reviewed across four areas:\n\n### 1. Purpose and scope\nDoes the actual package match the stated purpose?\n\n### 2. Install-time behavior\nDoes it write files, register hooks, install packages, or modify environment state?\n\n### 3. Runtime behavior\nDoes it execute commands, access sensitive files, call external services, or handle data broadly?\n\n### 4. Trust dependency\nDoes it rely on narrow and understandable external systems, or on opaque services that require blind trust?\n\n## Output\n\nThe skill produces a structured report with:\n- capability inventory\n- install-time risk\n- runtime risk\n- trust dependency classification\n- warnings and recommendations\n- final verdict: `safe`, `caution`, or `unsafe`\n\n## SettlementWitness integration\n\nThis skill does **not** delegate the safety decision.\n\nOptional verification is used only after local review is complete.\nIt can validate that the final report matches a deterministic spec and provide receipt metadata for auditability.\n\nUse it conservatively:\n- send only structured report data\n- never send secrets, credentials, personal data, or full private repositories\n- treat PASS as evidence that the report matches the spec, not as a substitute for judgment\n\n## Included package structure\n\n```text\nskill-vetter-v2/\n├── SKILL.md\n├── README.md\n├── _meta.json\n├── .learnings/\n├── assets/\n├── hooks/\n├── references/\n└── scripts/\n```\n\n## Scripts\n\n### `scripts/scan-skill.sh`\nLocal helper that inventories a skill directory and flags suspicious patterns such as:\n- credential access attempts\n- network calls\n- package installs\n- obfuscated execution\n- writes outside expected scope\n\n### `scripts/activator.sh`\nReminder hook content for prompting a vetting pass before a skill is trusted.\n\n### `scripts/error-detector.sh`\nReminder that suspicious outputs or failures discovered during review should be captured in the final report.\n\n## Hook\n\nThe OpenClaw hook injects a short reminder during bootstrap:\n- review the full package, not just `SKILL.md`\n- classify risk before installation\n- keep verdict decisions local\n- optionally verify the final report\n\n## Best use cases\n\n- reviewing third-party skills before install\n- auditing internal packaged skills\n- comparing multiple skills that solve the same task\n- enforcing trust boundaries in autonomous agent environments\n\n## Design rules\n\n- preserve local judgment\n- prefer transparent dependencies\n- no mandatory identity\n- no required credentials\n- no blind PASS-to-trust shortcut\n- verification augments review; it does not replace it\n\n## Installation\n\nAdd this repository as a Claude/OpenClaw skill, or copy the folder into your local skills directory.\n\n## Tags\n\nai-agents  \nsecurity  \nrisk-analysis  \ntrust  \nverification  \nskill-review\n\nFile v0.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn71nqqcxyxyst7f2s3f2nzz0h80jf78\",\n  \"slug\": \"skill-vetter-v2\",\n  \"version\": \"0.0.6\",\n  \"publishedAt\": 1783148062918\n}\n\nFile v0.0.6:references/examples.md\n\n# Examples\n\n## Example verdict: safe\n\nA formatting skill that only reads local markdown files and rewrites output style.\n\n- install risk: low\n- runtime risk: low\n- trust dependency: none\n- verdict: safe\n\n## Example verdict: caution\n\nA deployment helper that writes config files, installs a package, and calls a documented API.\n\n- install risk: medium\n- runtime risk: medium\n- trust dependency: transparent\n- verdict: caution\n\n## Example verdict: unsafe\n\nA skill that requests credentials, reads memory files without explanation, and sends prompts to an opaque external service.\n\n- install risk: high\n- runtime risk: extreme\n- trust dependency: opaque\n- verdict: unsafe\n\n## Verification example\n\nAfter local review, define a deterministic verification spec such as:\n- all required report fields present\n- verdict supported by listed warnings\n- prohibited data absent\n\nOnly verify the structured report payload.\n\nFile v0.0.6:references/openclaw-integration.md\n\n# OpenClaw Integration\n\nSkill Vetter v2 works as a normal packaged skill in OpenClaw.\n\n## Install\n\n```bash\nclawdhub install skill-vetter-v2\n```\n\nOr copy manually:\n\n```bash\ncp -r skill-vetter-v2 ~/.openclaw/skills/\n```\n\n## Optional hook\n\n```bash\ncp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2\nopenclaw hooks enable skill-vetter-v2\n```\n\n## Suggested workflow\n\n1. Open the target skill folder\n2. Read `SKILL.md`, `README.md`, scripts, hooks, references, and metadata\n3. Run the local helper:\n   ```bash\n   bash scripts/scan-skill.sh /path/to/target-skill\n   ```\n4. Write the structured report\n5. Optionally verify the final report\n\n## Design intent\n\nThe hook is advisory. It does not install, execute, or approve the target skill.\nThe verdict remains local.\n\nFile v0.0.6:assets/REPORT-TEMPLATE.md\n\n# Vetting Report Template\n\n```json\n{\n  \"skill_name\": \"\",\n  \"purpose\": \"\",\n  \"source\": \"clawhub | github | local | other\",\n  \"capabilities\": [],\n  \"install_risk\": \"low | medium | high | extreme\",\n  \"runtime_risk\": \"low | medium | high | extreme\",\n  \"trust_dependency\": \"none | transparent | opaque\",\n  \"warnings\": [],\n  \"recommendations\": [],\n  \"verdict\": \"safe | caution | unsafe\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run | pass | fail | indeterminate\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\nFile v0.0.6:assets/REVIEW-CHECKLIST.md\n\n# Review Checklist\n\n## Read first\n- SKILL.md\n- README.md\n- _meta.json\n- all scripts\n- all hooks\n- references and assets\n\n## Capability review\n- file reads\n- file writes\n- command execution\n- package installs\n- network access\n- data handling\n- secrets or credential access\n\n## Red flags\n- obfuscation\n- unexplained network calls\n- privilege escalation\n- persistence mechanisms\n- broad access to memory or secret stores\n\n## Decision\n- safe\n- caution\n- unsafe\n\nFile v0.0.6:hooks/openclaw/HOOK.md\n\n---\nname: skill-vetter-v2\ndescription: \"Injects a reminder to vet packaged skills before trusting or installing them\"\nmetadata: {\"openclaw\":{\"emoji\":\"🛡️\",\"events\":[\"agent:bootstrap\"]}}\n---\n\n# Skill Vetter v2 Hook\n\nInjects a reminder to review the full skill package and keep verdict decisions local.\n\n## What It Does\n\n- Fires on `agent:bootstrap`\n- Adds a reminder to inspect the whole package, not just `SKILL.md`\n- Prompts the agent to classify install-time risk, runtime risk, and trust dependency\n- Reminds the agent that optional verification applies only to the final report\n\nFile v0.0.6:skill-card.md\n\n## Description:\n\nVerification-guided review workflow for inspecting skill packages before use or publication that classifies risk, flags claims that exceed evidence, and does not itself perform cryptographic verification, emit receipts, or prove a skill is safe.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[nutstrut](https://clawhub.ai/user/nutstrut)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, maintainers, and agent operators use this skill to review Claude/OpenClaw skill packages before installation or publication, producing a local risk classification and recommendations while preserving the final trust decision for the reviewer.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The local scan helper can print credential-like lines from the user-selected target, which may include sensitive values.\n\nMitigation: Run it only on intended skill folders and keep raw scan output out of public logs or external services.\n\nRisk: The optional OpenClaw hook adds a persistent bootstrap reminder when enabled.\n\nMitigation: Enable the hook only when that reminder is desired and review the hook files before installation.\n\n## Reference(s):\n\n- [ClawHub skill listing](https://clawhub.ai/nutstrut/skills/skill-vetter-v2)\n- [README](README.md)\n- [OpenClaw Integration](references/openclaw-integration.md)\n- [Examples](references/examples.md)\n- [Review Checklist](assets/REVIEW-CHECKLIST.md)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with JSON report templates and shell command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Produces local review findings, warnings, recommendations, and optional verification status metadata.]\n\n## Skill Version(s):\n\n0.0.6 (source: server release evidence and artifact _meta.json)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v0.0.5: 16 files, 13184 bytes\n\nFiles: _meta.json (134b), .learnings/ERRORS.md (184b), .learnings/FEATURE_REQUESTS.md (189b), .learnings/LEARNINGS.md (223b), assets/REPORT-TEMPLATE.md (528b), assets/REVIEW-CHECKLIST.md (457b), hooks/openclaw/handler.js (1038b), hooks/openclaw/handler.ts (1056b), hooks/openclaw/HOOK.md (586b), README.md (3452b), references/examples.md (910b), references/openclaw-integration.md (763b), scripts/activator.sh (458b), scripts/scan-skill.sh (1471b), skill-card.md (2531b), SKILL.md (9461b)\n\nFile v0.0.5:SKILL.md\n\n---\n\nname: skill-vetter-v2\ndescription: Analyze any skill for safety before use. Preserve local judgment, classify risk clearly, and optionally verify the final report with SettlementWitness.\nmetadata:\n---------\n\n# Skill Vetter v2\n\nAnalyze skills before installation or use. Classify capabilities, risks, and trust dependencies with structured local review. Optionally verify the completed report with SettlementWitness.\n\nThis is a **packaged vetting skill**, not a thin wrapper. It preserves local inspection as the primary decision path and adds an optional verification layer for auditability.\n\n## Data handling and trust\n\nThis skill defines a **local review workflow** with an optional verification step for the final report.\n\n* Perform capability analysis and risk classification locally\n* Do **not** send secrets, credentials, private keys, seed phrases, personal data, or full private repositories to any external service\n* If optional verification is used, send only the minimum structured task data needed to validate the report\n* Verification does **not** decide whether a skill is safe to install; it only validates that the vetting report matches the stated evaluation spec\n* Identity is optional; no wallet access, account access, or credentials are required\n\n## Core Principle\n\nNever outsource the safety decision.\n\nExternal systems may help verify that a report was produced correctly, but the actual judgment about whether a skill should be trusted remains local and reviewable.\n\n## Quick Reference\n\n| Situation                                      | Action                                                         |\n| ---------------------------------------------- | -------------------------------------------------------------- |\n| New skill from unknown source                  | Run full local vetting workflow                                |\n| Skill asks for secrets or credentials          | Escalate risk immediately                                      |\n| Skill writes outside workspace                 | Mark as high risk unless clearly justified                     |\n| Skill calls external services                  | Classify trust dependency and data exposure                    |\n| Skill contains obfuscation or hidden execution | Mark unsafe                                                    |\n| Final report is complete                       | Optionally verify the report structure and verdict consistency |\n| Verification returns PASS                      | Attach receipt metadata to the report                          |\n| Verification returns FAIL                      | Re-check findings and correct the report                       |\n| Verification returns INDETERMINATE             | Hold for manual review; do not treat as verified               |\n\n## What This Skill Does\n\nSkill Vetter v2 evaluates a target skill across four dimensions:\n\n1. **Purpose and scope**\n   What the skill claims to do, and whether its requested capabilities match that purpose.\n\n2. **Install-time behavior**\n   File writes, package installs, hooks, system changes, or bootstrap modifications.\n\n3. **Runtime behavior**\n   Commands, file access, network access, external APIs, tool usage, and data handling.\n\n4. **Trust dependency**\n   Whether the skill depends on transparent and reviewable systems, or on opaque and unverifiable services.\n\n## Core Execution Loop\n\n1. Inspect the skill package locally\n\n   * `SKILL.md`\n   * `README.md` and references\n   * scripts, hooks, assets, templates\n   * metadata and install surface\n\n2. Identify declared and implied capabilities\n\n   * file reads and writes\n   * command execution\n   * package installation\n   * network or API usage\n   * handling of credentials, memory, or sensitive files\n\n3. Evaluate risk\n\n   * install-time risk\n   * runtime risk\n   * data exposure risk\n   * trust dependency risk\n\n4. Generate a structured report\n\n5. Optional: verify the completed report\n\n   * define a deterministic verification spec for the report structure and verdict logic\n   * run verification only on the minimal structured report payload\n   * attach receipt metadata only when verification passes\n\n## Risk Evaluation Categories\n\n### Install-Time Risk\n\nReview for:\n\n* file writes outside the workspace\n* package installs or dependency changes\n* shell profile or system configuration changes\n* hook registration or startup injection\n* hidden setup steps not stated in the docs\n\n### Runtime Risk\n\nReview for:\n\n* external API calls\n* arbitrary command execution\n* broad file system access\n* credential discovery or token handling\n* browser/session access\n* transmission of user data or memory files\n\n### Trust Dependency\n\nClassify the skill's external dependencies:\n\n* **none** — local-only behavior, no external trust dependency\n* **transparent** — external dependency is narrow, explicit, and independently understandable\n* **opaque** — external dependency is broad, hidden, unverifiable, or requests sensitive data\n\n## Red Flags\n\nReject or escalate immediately if you find:\n\n* requests for credentials, API keys, seed phrases, or private keys\n* access to secret stores or credential directories without a clear need\n* obfuscated or encoded execution logic intended to hide behavior\n* silent network transmission of prompts, memory, or workspace files\n* writes outside expected directories without a clear reason\n* privilege escalation or system-level modification\n* unexplained background processes, persistence, or surveillance behavior\n\n## Output Format\n\n```json id=\"m8yx3p\"\n{\n  \"skill_name\": \"...\",\n  \"purpose\": \"...\",\n  \"source\": \"clawhub | github | local | other\",\n  \"capabilities\": [\"...\"],\n  \"install_risk\": \"low | medium | high | extreme\",\n  \"runtime_risk\": \"low | medium | high | extreme\",\n  \"trust_dependency\": \"none | transparent | opaque\",\n  \"warnings\": [\"...\"],\n  \"recommendations\": [\"...\"],\n  \"verdict\": \"safe | caution | unsafe\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run | pass | fail | indeterminate\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\n---\n\n## Example Usage\n\n### Input (Skill to Review)\n\n```json id=\"9j3kdx\"\n{\n  \"skill_name\": \"example-email-sender\",\n  \"source\": \"github\",\n  \"description\": \"Sends automated emails using an external API\",\n  \"files\": [\"SKILL.md\", \"scripts/send-email.sh\"]\n}\n```\n\n### Output (Vetting Report)\n\n```json id=\"4n6rfa\"\n{\n  \"skill_name\": \"example-email-sender\",\n  \"purpose\": \"Send automated emails via external API\",\n  \"source\": \"github\",\n  \"capabilities\": [\n    \"network access\",\n    \"external API calls\",\n    \"file read/write\"\n  ],\n  \"install_risk\": \"low\",\n  \"runtime_risk\": \"medium\",\n  \"trust_dependency\": \"opaque\",\n  \"warnings\": [\n    \"Uses external API with unclear data handling\",\n    \"No transparency on where email content is sent\"\n  ],\n  \"recommendations\": [\n    \"Verify API endpoint and data handling policy\",\n    \"Limit data exposure before use\"\n  ],\n  \"verdict\": \"caution\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\n---\n\n## Optional Verification Workflow\n\nUse verification only after the local review is complete.\n\nRecommended pattern:\n\n1. Define a deterministic verification spec for the report\n\n   * required fields present\n   * risk labels internally consistent\n   * verdict supported by findings\n   * no prohibited data included\n\n2. Submit only the structured report and spec\n\n3. Interpret results conservatively\n\n   * **PASS** → attach receipt metadata and mark `verified: true`\n   * **FAIL** → correct the report and keep `verified: false`\n   * **INDETERMINATE** → keep `verified: false` and escalate for manual review\n\nVerification is optional and must never override local safety concerns.\n\n## OpenClaw Setup (Recommended)\n\nOpenClaw is the best fit for this skill because it supports packaged skills, hooks, and workspace context.\n\n### Installation\n\n**Via ClawHub:**\n\n```bash id=\"t2j9mf\"\nclawdhub install skill-vetter-v2\n```\n\n**Manual:**\n\n```bash id=\"a1vk0r\"\ngit clone https://github.com/your-org/skill-vetter-v2.git ~/.openclaw/skills/skill-vetter-v2\n```\n\n### Optional Hook\n\nInstall the reminder hook if you want a prompt to vet skills before trusting them:\n\n```bash id=\"0xptv9\"\ncp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2\nopenclaw hooks enable skill-vetter-v2\n```\n\n### Local Scan Helper\n\nRun the local helper against a skill folder:\n\n```bash id=\"z7p2qs\"\nbash scripts/scan-skill.sh /path/to/skill\n```\n\nThis helper inventories files and flags common red-patterns locally. It does not make network calls.\n\n## Generic Setup (Other Agents)\n\nUse this skill with Claude Code, Codex, Copilot, or other agents by copying the package into your skills directory and reviewing target skills locally.\n\nSuggested workflow:\n\n1. Read the target `SKILL.md`\n2. Read all scripts, hooks, and references\n3. Run the local scan helper\n4. Write the structured report\n5. Optionally verify the report\n\n## What This Is Not\n\n* not an installer\n* not an auto-executor for unknown code\n* not an external decision authority\n* not a replacement for human judgment on high-risk skills\n\n## Outcome\n\nAgents can:\n\n* understand what a skill actually does before use\n* identify install-time and runtime risks clearly\n* separate transparent dependencies from opaque trust requirements\n* keep safety decisions local while optionally producing verifiable records\n\n## Keywords\n\nai-agents, skill-safety, risk-analysis, verification, trust, security\n\nFile v0.0.5:README.md\n\n# Skill Vetter v2\n\n**Know what a skill does before you trust it.**\n\nSkill Vetter v2 is a packaged safety-review skill for evaluating agent skills before installation or use. It preserves a local, review-first workflow and adds optional SettlementWitness verification for the finished report.\n\n## Why this exists\n\nMost agent skills are installed based on a short description and a guess.\n\nThat creates avoidable risk:\n- hidden file access\n- undisclosed network behavior\n- silent trust in opaque external services\n- credential exposure or workspace exfiltration\n\nSkill Vetter v2 makes those risks visible before a skill is trusted.\n\n## What it analyzes\n\nEvery target skill is reviewed across four areas:\n\n### 1. Purpose and scope\nDoes the actual package match the stated purpose?\n\n### 2. Install-time behavior\nDoes it write files, register hooks, install packages, or modify environment state?\n\n### 3. Runtime behavior\nDoes it execute commands, access sensitive files, call external services, or handle data broadly?\n\n### 4. Trust dependency\nDoes it rely on narrow and understandable external systems, or on opaque services that require blind trust?\n\n## Output\n\nThe skill produces a structured report with:\n- capability inventory\n- install-time risk\n- runtime risk\n- trust dependency classification\n- warnings and recommendations\n- final verdict: `safe`, `caution`, or `unsafe`\n\n## SettlementWitness integration\n\nThis skill does **not** delegate the safety decision.\n\nOptional verification is used only after local review is complete.\nIt can validate that the final report matches a deterministic spec and provide receipt metadata for auditability.\n\nUse it conservatively:\n- send only structured report data\n- never send secrets, credentials, personal data, or full private repositories\n- treat PASS as evidence that the report matches the spec, not as a substitute for judgment\n\n## Included package structure\n\n```text\nskill-vetter-v2/\n├── SKILL.md\n├── README.md\n├── _meta.json\n├── .learnings/\n├── assets/\n├── hooks/\n├── references/\n└── scripts/\n```\n\n## Scripts\n\n### `scripts/scan-skill.sh`\nLocal helper that inventories a skill directory and flags suspicious patterns such as:\n- credential access attempts\n- network calls\n- package installs\n- obfuscated execution\n- writes outside expected scope\n\n### `scripts/activator.sh`\nReminder hook content for prompting a vetting pass before a skill is trusted.\n\n### `scripts/error-detector.sh`\nReminder that suspicious outputs or failures discovered during review should be captured in the final report.\n\n## Hook\n\nThe OpenClaw hook injects a short reminder during bootstrap:\n- review the full package, not just `SKILL.md`\n- classify risk before installation\n- keep verdict decisions local\n- optionally verify the final report\n\n## Best use cases\n\n- reviewing third-party skills before install\n- auditing internal packaged skills\n- comparing multiple skills that solve the same task\n- enforcing trust boundaries in autonomous agent environments\n\n## Design rules\n\n- preserve local judgment\n- prefer transparent dependencies\n- no mandatory identity\n- no required credentials\n- no blind PASS-to-trust shortcut\n- verification augments review; it does not replace it\n\n## Installation\n\nAdd this repository as a Claude/OpenClaw skill, or copy the folder into your local skills directory.\n\n## Tags\n\nai-agents  \nsecurity  \nrisk-analysis  \ntrust  \nverification  \nskill-review\n\nFile v0.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn71nqqcxyxyst7f2s3f2nzz0h80jf78\",\n  \"slug\": \"skill-vetter-v2\",\n  \"version\": \"0.0.5\",\n  \"publishedAt\": 1774818297711\n}\n\nFile v0.0.5:references/examples.md\n\n# Examples\n\n## Example verdict: safe\n\nA formatting skill that only reads local markdown files and rewrites output style.\n\n- install risk: low\n- runtime risk: low\n- trust dependency: none\n- verdict: safe\n\n## Example verdict: caution\n\nA deployment helper that writes config files, installs a package, and calls a documented API.\n\n- install risk: medium\n- runtime risk: medium\n- trust dependency: transparent\n- verdict: caution\n\n## Example verdict: unsafe\n\nA skill that requests credentials, reads memory files without explanation, and sends prompts to an opaque external service.\n\n- install risk: high\n- runtime risk: extreme\n- trust dependency: opaque\n- verdict: unsafe\n\n## Verification example\n\nAfter local review, define a deterministic verification spec such as:\n- all required report fields present\n- verdict supported by listed warnings\n- prohibited data absent\n\nOnly verify the structured report payload.\n\nFile v0.0.5:references/openclaw-integration.md\n\n# OpenClaw Integration\n\nSkill Vetter v2 works as a normal packaged skill in OpenClaw.\n\n## Install\n\n```bash\nclawdhub install skill-vetter-v2\n```\n\nOr copy manually:\n\n```bash\ncp -r skill-vetter-v2 ~/.openclaw/skills/\n```\n\n## Optional hook\n\n```bash\ncp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2\nopenclaw hooks enable skill-vetter-v2\n```\n\n## Suggested workflow\n\n1. Open the target skill folder\n2. Read `SKILL.md`, `README.md`, scripts, hooks, references, and metadata\n3. Run the local helper:\n   ```bash\n   bash scripts/scan-skill.sh /path/to/target-skill\n   ```\n4. Write the structured report\n5. Optionally verify the final report\n\n## Design intent\n\nThe hook is advisory. It does not install, execute, or approve the target skill.\nThe verdict remains local.\n\nFile v0.0.5:.learnings/ERRORS.md\n\n# Errors\n\nLog unexpected review failures here.\n\nExamples:\n- parser errors while scanning a skill\n- false negatives discovered after manual review\n- missing files or malformed packages\n\nFile v0.0.5:.learnings/FEATURE_REQUESTS.md\n\n# Feature Requests\n\nTrack user requests for future improvements.\n\nExamples:\n- richer capability classification\n- better diffing between two skill versions\n- export formats for audit trails\n\nFile v0.0.5:.learnings/LEARNINGS.md\n\n# Learnings\n\nUse this directory for improvements to the vetting workflow.\n\nExamples:\n- recurring red-flag patterns\n- better trust-dependency heuristics\n- false positives to avoid\n- review templates that improve consistency\n\nFile v0.0.5:assets/REPORT-TEMPLATE.md\n\n# Vetting Report Template\n\n```json\n{\n  \"skill_name\": \"\",\n  \"purpose\": \"\",\n  \"source\": \"clawhub | github | local | other\",\n  \"capabilities\": [],\n  \"install_risk\": \"low | medium | high | extreme\",\n  \"runtime_risk\": \"low | medium | high | extreme\",\n  \"trust_dependency\": \"none | transparent | opaque\",\n  \"warnings\": [],\n  \"recommendations\": [],\n  \"verdict\": \"safe | caution | unsafe\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run | pass | fail | indeterminate\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\nFile v0.0.5:assets/REVIEW-CHECKLIST.md\n\n# Review Checklist\n\n## Read first\n- SKILL.md\n- README.md\n- _meta.json\n- all scripts\n- all hooks\n- references and assets\n\n## Capability review\n- file reads\n- file writes\n- command execution\n- package installs\n- network access\n- data handling\n- secrets or credential access\n\n## Red flags\n- obfuscation\n- unexplained network calls\n- privilege escalation\n- persistence mechanisms\n- broad access to memory or secret stores\n\n## Decision\n- safe\n- caution\n- unsafe\n\nFile v0.0.5:hooks/openclaw/HOOK.md\n\n---\nname: skill-vetter-v2\ndescription: \"Injects a reminder to vet packaged skills before trusting or installing them\"\nmetadata: {\"openclaw\":{\"emoji\":\"🛡️\",\"events\":[\"agent:bootstrap\"]}}\n---\n\n# Skill Vetter v2 Hook\n\nInjects a reminder to review the full skill package and keep verdict decisions local.\n\n## What It Does\n\n- Fires on `agent:bootstrap`\n- Adds a reminder to inspect the whole package, not just `SKILL.md`\n- Prompts the agent to classify install-time risk, runtime risk, and trust dependency\n- Reminds the agent that optional verification applies only to the final report\n\nFile v0.0.5:skill-card.md\n\n## Description: <br>\nAnalyze any skill for safety before use. Preserve local judgment, classify risk clearly, and optionally verify the final report with SettlementWitness. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[nutstrut](https://clawhub.ai/user/nutstrut) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use Skill Vetter v2 to review packaged agent skills before installation or use, classify install-time and runtime risks, and produce structured local vetting reports. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Optional verification can expose sensitive information if a report payload includes secrets, credentials, personal data, or full private repositories. <br>\nMitigation: Send only the minimum structured report data needed for verification and exclude secrets, credentials, personal data, and private repository contents. <br>\nRisk: The optional OpenClaw hook injects bootstrap reminders, which may affect agent startup context. <br>\nMitigation: Enable the hook only when reminder behavior is wanted and review the hook files before installation. <br>\nRisk: The local scan helper inventories a target directory and reports pattern matches that are signals rather than proof of unsafe behavior. <br>\nMitigation: Run the helper only on intended skill folders and use its findings as inputs to local review rather than automatic verdicts. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/nutstrut/skill-vetter-v2) <br>\n- [OpenClaw Integration](references/openclaw-integration.md) <br>\n- [Examples](references/examples.md) <br>\n- [Review Checklist](assets/REVIEW-CHECKLIST.md) <br>\n- [Report Template](assets/REPORT-TEMPLATE.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [analysis, markdown, JSON, shell commands, guidance] <br>\n**Output Format:** [Structured JSON report and Markdown guidance with optional shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Optional verification receipt metadata can be attached when verification passes.] <br>\n\n## Skill Version(s): <br>\n0.0.5 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.0.4: 15 files, 11492 bytes\n\nFiles: _meta.json (134b), .learnings/ERRORS.md (184b), .learnings/FEATURE_REQUESTS.md (189b), .learnings/LEARNINGS.md (223b), assets/REPORT-TEMPLATE.md (528b), assets/REVIEW-CHECKLIST.md (457b), hooks/openclaw/handler.js (1038b), hooks/openclaw/handler.ts (1056b), hooks/openclaw/HOOK.md (586b), README.md (3452b), references/examples.md (910b), references/openclaw-integration.md (763b), scripts/activator.sh (458b), scripts/scan-skill.sh (1471b), SKILL.md (7901b)\n\nFile v0.0.4:SKILL.md\n\n---\nname: skill-vetter-v2\ndescription: \"Analyze any skill for safety before use. Preserve local judgment, classify risk clearly, and optionally verify the final report with SettlementWitness.\"\nmetadata:\n---\n\n# Skill Vetter v2\n\nAnalyze skills before installation or use. Classify capabilities, risks, and trust dependencies with structured local review. Optionally verify the completed report with SettlementWitness.\n\nThis is a **packaged vetting skill**, not a thin wrapper. It preserves local inspection as the primary decision path and adds an optional verification layer for auditability.\n\n## Data handling and trust\n\nThis skill defines a **local review workflow** with an optional verification step for the final report.\n\n- Perform capability analysis and risk classification locally\n- Do **not** send secrets, credentials, private keys, seed phrases, personal data, or full private repositories to any external service\n- If optional verification is used, send only the minimum structured task data needed to validate the report\n- Verification does **not** decide whether a skill is safe to install; it only validates that the vetting report matches the stated evaluation spec\n- Identity is optional; no wallet access, account access, or credentials are required\n\n## Core Principle\n\nNever outsource the safety decision.\n\nExternal systems may help verify that a report was produced correctly, but the actual judgment about whether a skill should be trusted remains local and reviewable.\n\n## Quick Reference\n\n| Situation | Action |\n|-----------|--------|\n| New skill from unknown source | Run full local vetting workflow |\n| Skill asks for secrets or credentials | Escalate risk immediately |\n| Skill writes outside workspace | Mark as high risk unless clearly justified |\n| Skill calls external services | Classify trust dependency and data exposure |\n| Skill contains obfuscation or hidden execution | Mark unsafe |\n| Final report is complete | Optionally verify the report structure and verdict consistency |\n| Verification returns PASS | Attach receipt metadata to the report |\n| Verification returns FAIL | Re-check findings and correct the report |\n| Verification returns INDETERMINATE | Hold for manual review; do not treat as verified |\n\n## What This Skill Does\n\nSkill Vetter v2 evaluates a target skill across four dimensions:\n\n1. **Purpose and scope**  \n   What the skill claims to do, and whether its requested capabilities match that purpose.\n\n2. **Install-time behavior**  \n   File writes, package installs, hooks, system changes, or bootstrap modifications.\n\n3. **Runtime behavior**  \n   Commands, file access, network access, external APIs, tool usage, and data handling.\n\n4. **Trust dependency**  \n   Whether the skill depends on transparent and reviewable systems, or on opaque and unverifiable services.\n\n## Core Execution Loop\n\n1. Inspect the skill package locally\n   - `SKILL.md`\n   - `README.md` and references\n   - scripts, hooks, assets, templates\n   - metadata and install surface\n\n2. Identify declared and implied capabilities\n   - file reads and writes\n   - command execution\n   - package installation\n   - network or API usage\n   - handling of credentials, memory, or sensitive files\n\n3. Evaluate risk\n   - install-time risk\n   - runtime risk\n   - data exposure risk\n   - trust dependency risk\n\n4. Generate a structured report\n\n5. Optional: verify the completed report\n   - define a deterministic verification spec for the report structure and verdict logic\n   - run verification only on the minimal structured report payload\n   - attach receipt metadata only when verification passes\n\n## Risk Evaluation Categories\n\n### Install-Time Risk\n\nReview for:\n- file writes outside the workspace\n- package installs or dependency changes\n- shell profile or system configuration changes\n- hook registration or startup injection\n- hidden setup steps not stated in the docs\n\n### Runtime Risk\n\nReview for:\n- external API calls\n- arbitrary command execution\n- broad file system access\n- credential discovery or token handling\n- browser/session access\n- transmission of user data or memory files\n\n### Trust Dependency\n\nClassify the skill's external dependencies:\n\n- **none** — local-only behavior, no external trust dependency\n- **transparent** — external dependency is narrow, explicit, and independently understandable\n- **opaque** — external dependency is broad, hidden, unverifiable, or requests sensitive data\n\n## Red Flags\n\nReject or escalate immediately if you find:\n\n- requests for credentials, API keys, seed phrases, or private keys\n- access to secret stores or credential directories without a clear need\n- obfuscated or encoded execution logic intended to hide behavior\n- silent network transmission of prompts, memory, or workspace files\n- writes outside expected directories without a clear reason\n- privilege escalation or system-level modification\n- unexplained background processes, persistence, or surveillance behavior\n\n## Output Format\n\nUse this JSON shape for the final report:\n\n```json\n{\n  \"skill_name\": \"...\",\n  \"purpose\": \"...\",\n  \"source\": \"clawhub | github | local | other\",\n  \"capabilities\": [\"...\"],\n  \"install_risk\": \"low | medium | high | extreme\",\n  \"runtime_risk\": \"low | medium | high | extreme\",\n  \"trust_dependency\": \"none | transparent | opaque\",\n  \"warnings\": [\"...\"],\n  \"recommendations\": [\"...\"],\n  \"verdict\": \"safe | caution | unsafe\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run | pass | fail | indeterminate\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\n## Optional Verification Workflow\n\nUse verification only after the local review is complete.\n\nRecommended pattern:\n\n1. Define a deterministic verification spec for the report\n   - required fields present\n   - risk labels internally consistent\n   - verdict supported by findings\n   - no prohibited data included\n\n2. Submit only the structured report and spec\n\n3. Interpret results conservatively\n   - **PASS** → attach receipt metadata and mark `verified: true`\n   - **FAIL** → correct the report and keep `verified: false`\n   - **INDETERMINATE** → keep `verified: false` and escalate for manual review\n\nVerification is optional and must never override local safety concerns.\n\n## OpenClaw Setup (Recommended)\n\nOpenClaw is the best fit for this skill because it supports packaged skills, hooks, and workspace context.\n\n### Installation\n\n**Via ClawHub:**\n```bash\nclawdhub install skill-vetter-v2\n```\n\n**Manual:**\n```bash\ngit clone https://github.com/your-org/skill-vetter-v2.git ~/.openclaw/skills/skill-vetter-v2\n```\n\n### Optional Hook\n\nInstall the reminder hook if you want a prompt to vet skills before trusting them:\n\n```bash\ncp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2\nopenclaw hooks enable skill-vetter-v2\n```\n\n### Local Scan Helper\n\nRun the local helper against a skill folder:\n\n```bash\nbash scripts/scan-skill.sh /path/to/skill\n```\n\nThis helper inventories files and flags common red-patterns locally. It does not make network calls.\n\n## Generic Setup (Other Agents)\n\nUse this skill with Claude Code, Codex, Copilot, or other agents by copying the package into your skills directory and reviewing target skills locally.\n\nSuggested workflow:\n1. Read the target `SKILL.md`\n2. Read all scripts, hooks, and references\n3. Run the local scan helper\n4. Write the structured report\n5. Optionally verify the report\n\n## What This Is Not\n\n- not an installer\n- not an auto-executor for unknown code\n- not an external decision authority\n- not a replacement for human judgment on high-risk skills\n\n## Outcome\n\nAgents can:\n- understand what a skill actually does before use\n- identify install-time and runtime risks clearly\n- separate transparent dependencies from opaque trust requirements\n- keep safety decisions local while optionally producing verifiable records\n\n## Keywords\n\nai-agents, skill-safety, risk-analysis, verification, trust, security\n\nFile v0.0.4:README.md\n\n# Skill Vetter v2\n\n**Know what a skill does before you trust it.**\n\nSkill Vetter v2 is a packaged safety-review skill for evaluating agent skills before installation or use. It preserves a local, review-first workflow and adds optional SettlementWitness verification for the finished report.\n\n## Why this exists\n\nMost agent skills are installed based on a short description and a guess.\n\nThat creates avoidable risk:\n- hidden file access\n- undisclosed network behavior\n- silent trust in opaque external services\n- credential exposure or workspace exfiltration\n\nSkill Vetter v2 makes those risks visible before a skill is trusted.\n\n## What it analyzes\n\nEvery target skill is reviewed across four areas:\n\n### 1. Purpose and scope\nDoes the actual package match the stated purpose?\n\n### 2. Install-time behavior\nDoes it write files, register hooks, install packages, or modify environment state?\n\n### 3. Runtime behavior\nDoes it execute commands, access sensitive files, call external services, or handle data broadly?\n\n### 4. Trust dependency\nDoes it rely on narrow and understandable external systems, or on opaque services that require blind trust?\n\n## Output\n\nThe skill produces a structured report with:\n- capability inventory\n- install-time risk\n- runtime risk\n- trust dependency classification\n- warnings and recommendations\n- final verdict: `safe`, `caution`, or `unsafe`\n\n## SettlementWitness integration\n\nThis skill does **not** delegate the safety decision.\n\nOptional verification is used only after local review is complete.\nIt can validate that the final report matches a deterministic spec and provide receipt metadata for auditability.\n\nUse it conservatively:\n- send only structured report data\n- never send secrets, credentials, personal data, or full private repositories\n- treat PASS as evidence that the report matches the spec, not as a substitute for judgment\n\n## Included package structure\n\n```text\nskill-vetter-v2/\n├── SKILL.md\n├── README.md\n├── _meta.json\n├── .learnings/\n├── assets/\n├── hooks/\n├── references/\n└── scripts/\n```\n\n## Scripts\n\n### `scripts/scan-skill.sh`\nLocal helper that inventories a skill directory and flags suspicious patterns such as:\n- credential access attempts\n- network calls\n- package installs\n- obfuscated execution\n- writes outside expected scope\n\n### `scripts/activator.sh`\nReminder hook content for prompting a vetting pass before a skill is trusted.\n\n### `scripts/error-detector.sh`\nReminder that suspicious outputs or failures discovered during review should be captured in the final report.\n\n## Hook\n\nThe OpenClaw hook injects a short reminder during bootstrap:\n- review the full package, not just `SKILL.md`\n- classify risk before installation\n- keep verdict decisions local\n- optionally verify the final report\n\n## Best use cases\n\n- reviewing third-party skills before install\n- auditing internal packaged skills\n- comparing multiple skills that solve the same task\n- enforcing trust boundaries in autonomous agent environments\n\n## Design rules\n\n- preserve local judgment\n- prefer transparent dependencies\n- no mandatory identity\n- no required credentials\n- no blind PASS-to-trust shortcut\n- verification augments review; it does not replace it\n\n## Installation\n\nAdd this repository as a Claude/OpenClaw skill, or copy the folder into your local skills directory.\n\n## Tags\n\nai-agents  \nsecurity  \nrisk-analysis  \ntrust  \nverification  \nskill-review\n\nFile v0.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn71nqqcxyxyst7f2s3f2nzz0h80jf78\",\n  \"slug\": \"skill-vetter-v2\",\n  \"version\": \"0.0.4\",\n  \"publishedAt\": 1774811759186\n}\n\nFile v0.0.4:references/examples.md\n\n# Examples\n\n## Example verdict: safe\n\nA formatting skill that only reads local markdown files and rewrites output style.\n\n- install risk: low\n- runtime risk: low\n- trust dependency: none\n- verdict: safe\n\n## Example verdict: caution\n\nA deployment helper that writes config files, installs a package, and calls a documented API.\n\n- install risk: medium\n- runtime risk: medium\n- trust dependency: transparent\n- verdict: caution\n\n## Example verdict: unsafe\n\nA skill that requests credentials, reads memory files without explanation, and sends prompts to an opaque external service.\n\n- install risk: high\n- runtime risk: extreme\n- trust dependency: opaque\n- verdict: unsafe\n\n## Verification example\n\nAfter local review, define a deterministic verification spec such as:\n- all required report fields present\n- verdict supported by listed warnings\n- prohibited data absent\n\nOnly verify the structured report payload.\n\nFile v0.0.4:references/openclaw-integration.md\n\n# OpenClaw Integration\n\nSkill Vetter v2 works as a normal packaged skill in OpenClaw.\n\n## Install\n\n```bash\nclawdhub install skill-vetter-v2\n```\n\nOr copy manually:\n\n```bash\ncp -r skill-vetter-v2 ~/.openclaw/skills/\n```\n\n## Optional hook\n\n```bash\ncp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2\nopenclaw hooks enable skill-vetter-v2\n```\n\n## Suggested workflow\n\n1. Open the target skill folder\n2. Read `SKILL.md`, `README.md`, scripts, hooks, references, and metadata\n3. Run the local helper:\n   ```bash\n   bash scripts/scan-skill.sh /path/to/target-skill\n   ```\n4. Write the structured report\n5. Optionally verify the final report\n\n## Design intent\n\nThe hook is advisory. It does not install, execute, or approve the target skill.\nThe verdict remains local.\n\nFile v0.0.4:.learnings/ERRORS.md\n\n# Errors\n\nLog unexpected review failures here.\n\nExamples:\n- parser errors while scanning a skill\n- false negatives discovered after manual review\n- missing files or malformed packages\n\nFile v0.0.4:.learnings/FEATURE_REQUESTS.md\n\n# Feature Requests\n\nTrack user requests for future improvements.\n\nExamples:\n- richer capability classification\n- better diffing between two skill versions\n- export formats for audit trails\n\nFile v0.0.4:.learnings/LEARNINGS.md\n\n# Learnings\n\nUse this directory for improvements to the vetting workflow.\n\nExamples:\n- recurring red-flag patterns\n- better trust-dependency heuristics\n- false positives to avoid\n- review templates that improve consistency\n\nFile v0.0.4:assets/REPORT-TEMPLATE.md\n\n# Vetting Report Template\n\n```json\n{\n  \"skill_name\": \"\",\n  \"purpose\": \"\",\n  \"source\": \"clawhub | github | local | other\",\n  \"capabilities\": [],\n  \"install_risk\": \"low | medium | high | extreme\",\n  \"runtime_risk\": \"low | medium | high | extreme\",\n  \"trust_dependency\": \"none | transparent | opaque\",\n  \"warnings\": [],\n  \"recommendations\": [],\n  \"verdict\": \"safe | caution | unsafe\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run | pass | fail | indeterminate\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\nFile v0.0.4:assets/REVIEW-CHECKLIST.md\n\n# Review Checklist\n\n## Read first\n- SKILL.md\n- README.md\n- _meta.json\n- all scripts\n- all hooks\n- references and assets\n\n## Capability review\n- file reads\n- file writes\n- command execution\n- package installs\n- network access\n- data handling\n- secrets or credential access\n\n## Red flags\n- obfuscation\n- unexplained network calls\n- privilege escalation\n- persistence mechanisms\n- broad access to memory or secret stores\n\n## Decision\n- safe\n- caution\n- unsafe\n\nFile v0.0.4:hooks/openclaw/HOOK.md\n\n---\nname: skill-vetter-v2\ndescription: \"Injects a reminder to vet packaged skills before trusting or installing them\"\nmetadata: {\"openclaw\":{\"emoji\":\"🛡️\",\"events\":[\"agent:bootstrap\"]}}\n---\n\n# Skill Vetter v2 Hook\n\nInjects a reminder to review the full skill package and keep verdict decisions local.\n\n## What It Does\n\n- Fires on `agent:bootstrap`\n- Adds a reminder to inspect the whole package, not just `SKILL.md`\n- Prompts the agent to classify install-time risk, runtime risk, and trust dependency\n- Reminds the agent that optional verification applies only to the final report\n\nArchive v0.0.3: 16 files, 12121 bytes\n\nFiles: _meta.json (134b), .learnings/ERRORS.md (184b), .learnings/FEATURE_REQUESTS.md (189b), .learnings/LEARNINGS.md (223b), assets/REPORT-TEMPLATE.md (528b), assets/REVIEW-CHECKLIST.md (457b), hooks/openclaw/handler.js (1038b), hooks/openclaw/handler.ts (1056b), hooks/openclaw/HOOK.md (586b), README.md (3452b), references/examples.md (910b), references/openclaw-integration.md (763b), scripts/activator.sh (458b), scripts/error-detector.sh (792b), scripts/scan-skill.sh (1471b), SKILL.md (7901b)\n\nFile v0.0.3:SKILL.md\n\n---\nname: skill-vetter-v2\ndescription: \"Analyze any skill for safety before use. Preserve local judgment, classify risk clearly, and optionally verify the final report with SettlementWitness.\"\nmetadata:\n---\n\n# Skill Vetter v2\n\nAnalyze skills before installation or use. Classify capabilities, risks, and trust dependencies with structured local review. Optionally verify the completed report with SettlementWitness.\n\nThis is a **packaged vetting skill**, not a thin wrapper. It preserves local inspection as the primary decision path and adds an optional verification layer for auditability.\n\n## Data handling and trust\n\nThis skill defines a **local review workflow** with an optional verification step for the final report.\n\n- Perform capability analysis and risk classification locally\n- Do **not** send secrets, credentials, private keys, seed phrases, personal data, or full private repositories to any external service\n- If optional verification is used, send only the minimum structured task data needed to validate the report\n- Verification does **not** decide whether a skill is safe to install; it only validates that the vetting report matches the stated evaluation spec\n- Identity is optional; no wallet access, account access, or credentials are required\n\n## Core Principle\n\nNever outsource the safety decision.\n\nExternal systems may help verify that a report was produced correctly, but the actual judgment about whether a skill should be trusted remains local and reviewable.\n\n## Quick Reference\n\n| Situation | Action |\n|-----------|--------|\n| New skill from unknown source | Run full local vetting workflow |\n| Skill asks for secrets or credentials | Escalate risk immediately |\n| Skill writes outside workspace | Mark as high risk unless clearly justified |\n| Skill calls external services | Classify trust dependency and data exposure |\n| Skill contains obfuscation or hidden execution | Mark unsafe |\n| Final report is complete | Optionally verify the report structure and verdict consistency |\n| Verification returns PASS | Attach receipt metadata to the report |\n| Verification returns FAIL | Re-check findings and correct the report |\n| Verification returns INDETERMINATE | Hold for manual review; do not treat as verified |\n\n## What This Skill Does\n\nSkill Vetter v2 evaluates a target skill across four dimensions:\n\n1. **Purpose and scope**  \n   What the skill claims to do, and whether its requested capabilities match that purpose.\n\n2. **Install-time behavior**  \n   File writes, package installs, hooks, system changes, or bootstrap modifications.\n\n3. **Runtime behavior**  \n   Commands, file access, network access, external APIs, tool usage, and data handling.\n\n4. **Trust dependency**  \n   Whether the skill depends on transparent and reviewable systems, or on opaque and unverifiable services.\n\n## Core Execution Loop\n\n1. Inspect the skill package locally\n   - `SKILL.md`\n   - `README.md` and references\n   - scripts, hooks, assets, templates\n   - metadata and install surface\n\n2. Identify declared and implied capabilities\n   - file reads and writes\n   - command execution\n   - package installation\n   - network or API usage\n   - handling of credentials, memory, or sensitive files\n\n3. Evaluate risk\n   - install-time risk\n   - runtime risk\n   - data exposure risk\n   - trust dependency risk\n\n4. Generate a structured report\n\n5. Optional: verify the completed report\n   - define a deterministic verification spec for the report structure and verdict logic\n   - run verification only on the minimal structured report payload\n   - attach receipt metadata only when verification passes\n\n## Risk Evaluation Categories\n\n### Install-Time Risk\n\nReview for:\n- file writes outside the workspace\n- package installs or dependency changes\n- shell profile or system configuration changes\n- hook registration or startup injection\n- hidden setup steps not stated in the docs\n\n### Runtime Risk\n\nReview for:\n- external API calls\n- arbitrary command execution\n- broad file system access\n- credential discovery or token handling\n- browser/session access\n- transmission of user data or memory files\n\n### Trust Dependency\n\nClassify the skill's external dependencies:\n\n- **none** — local-only behavior, no external trust dependency\n- **transparent** — external dependency is narrow, explicit, and independently understandable\n- **opaque** — external dependency is broad, hidden, unverifiable, or requests sensitive data\n\n## Red Flags\n\nReject or escalate immediately if you find:\n\n- requests for credentials, API keys, seed phrases, or private keys\n- access to secret stores or credential directories without a clear need\n- obfuscated or encoded execution logic intended to hide behavior\n- silent network transmission of prompts, memory, or workspace files\n- writes outside expected directories without a clear reason\n- privilege escalation or system-level modification\n- unexplained background processes, persistence, or surveillance behavior\n\n## Output Format\n\nUse this JSON shape for the final report:\n\n```json\n{\n  \"skill_name\": \"...\",\n  \"purpose\": \"...\",\n  \"source\": \"clawhub | github | local | other\",\n  \"capabilities\": [\"...\"],\n  \"install_risk\": \"low | medium | high | extreme\",\n  \"runtime_risk\": \"low | medium | high | extreme\",\n  \"trust_dependency\": \"none | transparent | opaque\",\n  \"warnings\": [\"...\"],\n  \"recommendations\": [\"...\"],\n  \"verdict\": \"safe | caution | unsafe\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run | pass | fail | indeterminate\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\n## Optional Verification Workflow\n\nUse verification only after the local review is complete.\n\nRecommended pattern:\n\n1. Define a deterministic verification spec for the report\n   - required fields present\n   - risk labels internally consistent\n   - verdict supported by findings\n   - no prohibited data included\n\n2. Submit only the structured report and spec\n\n3. Interpret results conservatively\n   - **PASS** → attach receipt metadata and mark `verified: true`\n   - **FAIL** → correct the report and keep `verified: false`\n   - **INDETERMINATE** → keep `verified: false` and escalate for manual review\n\nVerification is optional and must never override local safety concerns.\n\n## OpenClaw Setup (Recommended)\n\nOpenClaw is the best fit for this skill because it supports packaged skills, hooks, and workspace context.\n\n### Installation\n\n**Via ClawHub:**\n```bash\nclawdhub install skill-vetter-v2\n```\n\n**Manual:**\n```bash\ngit clone https://github.com/your-org/skill-vetter-v2.git ~/.openclaw/skills/skill-vetter-v2\n```\n\n### Optional Hook\n\nInstall the reminder hook if you want a prompt to vet skills before trusting them:\n\n```bash\ncp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2\nopenclaw hooks enable skill-vetter-v2\n```\n\n### Local Scan Helper\n\nRun the local helper against a skill folder:\n\n```bash\nbash scripts/scan-skill.sh /path/to/skill\n```\n\nThis helper inventories files and flags common red-patterns locally. It does not make network calls.\n\n## Generic Setup (Other Agents)\n\nUse this skill with Claude Code, Codex, Copilot, or other agents by copying the package into your skills directory and reviewing target skills locally.\n\nSuggested workflow:\n1. Read the target `SKILL.md`\n2. Read all scripts, hooks, and references\n3. Run the local scan helper\n4. Write the structured report\n5. Optionally verify the report\n\n## What This Is Not\n\n- not an installer\n- not an auto-executor for unknown code\n- not an external decision authority\n- not a replacement for human judgment on high-risk skills\n\n## Outcome\n\nAgents can:\n- understand what a skill actually does before use\n- identify install-time and runtime risks clearly\n- separate transparent dependencies from opaque trust requirements\n- keep safety decisions local while optionally producing verifiable records\n\n## Keywords\n\nai-agents, skill-safety, risk-analysis, verification, trust, security\n\nFile v0.0.3:README.md\n\n# Skill Vetter v2\n\n**Know what a skill does before you trust it.**\n\nSkill Vetter v2 is a packaged safety-review skill for evaluating agent skills before installation or use. It preserves a local, review-first workflow and adds optional SettlementWitness verification for the finished report.\n\n## Why this exists\n\nMost agent skills are installed based on a short description and a guess.\n\nThat creates avoidable risk:\n- hidden file access\n- undisclosed network behavior\n- silent trust in opaque external services\n- credential exposure or workspace exfiltration\n\nSkill Vetter v2 makes those risks visible before a skill is trusted.\n\n## What it analyzes\n\nEvery target skill is reviewed across four areas:\n\n### 1. Purpose and scope\nDoes the actual package match the stated purpose?\n\n### 2. Install-time behavior\nDoes it write files, register hooks, install packages, or modify environment state?\n\n### 3. Runtime behavior\nDoes it execute commands, access sensitive files, call external services, or handle data broadly?\n\n### 4. Trust dependency\nDoes it rely on narrow and understandable external systems, or on opaque services that require blind trust?\n\n## Output\n\nThe skill produces a structured report with:\n- capability inventory\n- install-time risk\n- runtime risk\n- trust dependency classification\n- warnings and recommendations\n- final verdict: `safe`, `caution`, or `unsafe`\n\n## SettlementWitness integration\n\nThis skill does **not** delegate the safety decision.\n\nOptional verification is used only after local review is complete.\nIt can validate that the final report matches a deterministic spec and provide receipt metadata for auditability.\n\nUse it conservatively:\n- send only structured report data\n- never send secrets, credentials, personal data, or full private repositories\n- treat PASS as evidence that the report matches the spec, not as a substitute for judgment\n\n## Included package structure\n\n```text\nskill-vetter-v2/\n├── SKILL.md\n├── README.md\n├── _meta.json\n├── .learnings/\n├── assets/\n├── hooks/\n├── references/\n└── scripts/\n```\n\n## Scripts\n\n### `scripts/scan-skill.sh`\nLocal helper that inventories a skill directory and flags suspicious patterns such as:\n- credential access attempts\n- network calls\n- package installs\n- obfuscated execution\n- writes outside expected scope\n\n### `scripts/activator.sh`\nReminder hook content for prompting a vetting pass before a skill is trusted.\n\n### `scripts/error-detector.sh`\nReminder that suspicious outputs or failures discovered during review should be captured in the final report.\n\n## Hook\n\nThe OpenClaw hook injects a short reminder during bootstrap:\n- review the full package, not just `SKILL.md`\n- classify risk before installation\n- keep verdict decisions local\n- optionally verify the final report\n\n## Best use cases\n\n- reviewing third-party skills before install\n- auditing internal packaged skills\n- comparing multiple skills that solve the same task\n- enforcing trust boundaries in autonomous agent environments\n\n## Design rules\n\n- preserve local judgment\n- prefer transparent dependencies\n- no mandatory identity\n- no required credentials\n- no blind PASS-to-trust shortcut\n- verification augments review; it does not replace it\n\n## Installation\n\nAdd this repository as a Claude/OpenClaw skill, or copy the folder into your local skills directory.\n\n## Tags\n\nai-agents  \nsecurity  \nrisk-analysis  \ntrust  \nverification  \nskill-review\n\nFile v0.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn71nqqcxyxyst7f2s3f2nzz0h80jf78\",\n  \"slug\": \"skill-vetter-v2\",\n  \"version\": \"0.0.3\",\n  \"publishedAt\": 1774811380761\n}\n\nFile v0.0.3:references/examples.md\n\n# Examples\n\n## Example verdict: safe\n\nA formatting skill that only reads local markdown files and rewrites output style.\n\n- install risk: low\n- runtime risk: low\n- trust dependency: none\n- verdict: safe\n\n## Example verdict: caution\n\nA deployment helper that writes config files, installs a package, and calls a documented API.\n\n- install risk: medium\n- runtime risk: medium\n- trust dependency: transparent\n- verdict: caution\n\n## Example verdict: unsafe\n\nA skill that requests credentials, reads memory files without explanation, and sends prompts to an opaque external service.\n\n- install risk: high\n- runtime risk: extreme\n- trust dependency: opaque\n- verdict: unsafe\n\n## Verification example\n\nAfter local review, define a deterministic verification spec such as:\n- all required report fields present\n- verdict supported by listed warnings\n- prohibited data absent\n\nOnly verify the structured report payload.\n\nFile v0.0.3:references/openclaw-integration.md\n\n# OpenClaw Integration\n\nSkill Vetter v2 works as a normal packaged skill in OpenClaw.\n\n## Install\n\n```bash\nclawdhub install skill-vetter-v2\n```\n\nOr copy manually:\n\n```bash\ncp -r skill-vetter-v2 ~/.openclaw/skills/\n```\n\n## Optional hook\n\n```bash\ncp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2\nopenclaw hooks enable skill-vetter-v2\n```\n\n## Suggested workflow\n\n1. Open the target skill folder\n2. Read `SKILL.md`, `README.md`, scripts, hooks, references, and metadata\n3. Run the local helper:\n   ```bash\n   bash scripts/scan-skill.sh /path/to/target-skill\n   ```\n4. Write the structured report\n5. Optionally verify the final report\n\n## Design intent\n\nThe hook is advisory. It does not install, execute, or approve the target skill.\nThe verdict remains local.\n\nFile v0.0.3:.learnings/ERRORS.md\n\n# Errors\n\nLog unexpected review failures here.\n\nExamples:\n- parser errors while scanning a skill\n- false negatives discovered after manual review\n- missing files or malformed packages\n\nFile v0.0.3:.learnings/FEATURE_REQUESTS.md\n\n# Feature Requests\n\nTrack user requests for future improvements.\n\nExamples:\n- richer capability classification\n- better diffing between two skill versions\n- export formats for audit trails\n\nFile v0.0.3:.learnings/LEARNINGS.md\n\n# Learnings\n\nUse this directory for improvements to the vetting workflow.\n\nExamples:\n- recurring red-flag patterns\n- better trust-dependency heuristics\n- false positives to avoid\n- review templates that improve consistency\n\nFile v0.0.3:assets/REPORT-TEMPLATE.md\n\n# Vetting Report Template\n\n```json\n{\n  \"skill_name\": \"\",\n  \"purpose\": \"\",\n  \"source\": \"clawhub | github | local | other\",\n  \"capabilities\": [],\n  \"install_risk\": \"low | medium | high | extreme\",\n  \"runtime_risk\": \"low | medium | high | extreme\",\n  \"trust_dependency\": \"none | transparent | opaque\",\n  \"warnings\": [],\n  \"recommendations\": [],\n  \"verdict\": \"safe | caution | unsafe\",\n  \"verified\": false,\n  \"verification\": {\n    \"status\": \"not_run | pass | fail | indeterminate\",\n    \"receipt_id\": null,\n    \"notes\": \"\"\n  }\n}\n```\n\nFile v0.0.3:assets/REVIEW-CHECKLIST.md\n\n# Review Checklist\n\n## Read first\n- SKILL.md\n- README.md\n- _meta.json\n- all scripts\n- all hooks\n- references and assets\n\n## Capability review\n- file reads\n- file writes\n- command execution\n- package installs\n- network access\n- data handling\n- secrets or credential access\n\n## Red flags\n- obfuscation\n- unexplained network calls\n- privilege escalation\n- persistence mechanisms\n- broad access to memory or secret stores\n\n## Decision\n- safe\n- caution\n- unsafe\n\nFile v0.0.3:hooks/openclaw/HOOK.md\n\n---\nname: skill-vetter-v2\ndescription: \"Injects a reminder to vet packaged skills before trusting or installing them\"\nmetadata: {\"openclaw\":{\"emoji\":\"🛡️\",\"events\":[\"agent:bootstrap\"]}}\n---\n\n# Skill Vetter v2 Hook\n\nInjects a reminder to review the full skill package and keep verdict decisions local.\n\n## What It Does\n\n- Fires on `agent:bootstrap`\n- Adds a reminder to inspect the whole package, not just `SKILL.md`\n- Prompts the agent to classify install-time risk, runtime risk, and trust dependency\n- Reminds the agent that optional verification applies only to the final report\n\nArchive v0.0.2: 3 files, 2780 bytes\n\nFiles: README.md (2161b), SKILL.md (3637b), _meta.json (134b)\n\nFile v0.0.2:SKILL.md\n\n\\---\r\n\r\nname: skill-vetter-v2\r\n\r\ndescription: Analyze any skill for safety risks before use. Classify behavior and optionally produce a signed verification result.\r\n\r\n\\---\r\n\r\n\r\n\r\n\\# Skill Vetter v2\r\n\r\n\r\n\r\nEvaluate agent skills for safety using structured local analysis. Optionally produce verifiable attestations of the result.\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## Core Principle\r\n\r\n\r\n\r\nNever delegate safety decisions to external systems.\r\n\r\n\r\n\r\nAll classification and risk evaluation must be performed locally.\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## What This Does\r\n\r\n\r\n\r\nSkill Vetter v2 analyzes a skill to determine:\r\n\r\n\r\n\r\n\\- what the skill does\r\n\r\n\\- what capabilities it uses\r\n\r\n\\- what risks it introduces\r\n\r\n\r\n\r\nIt produces a structured safety report.\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## Core Execution Loop\r\n\r\n\r\n\r\n1\\. Inspect skill:\r\n\r\n&#x20;  - instructions\r\n\r\n&#x20;  - structure\r\n\r\n&#x20;  - declared behavior\r\n\r\n\r\n\r\n2\\. Identify capabilities:\r\n\r\n&#x20;  - file access\r\n\r\n&#x20;  - execution\r\n\r\n&#x20;  - network calls\r\n\r\n&#x20;  - data handling\r\n\r\n\r\n\r\n3\\. Evaluate risk:\r\n\r\n&#x20;  - install-time risk\r\n\r\n&#x20;  - runtime behavior\r\n\r\n&#x20;  - trust dependencies\r\n\r\n\r\n\r\n4\\. Classify external services:\r\n\r\n&#x20;  - transparent vs opaque\r\n\r\n\r\n\r\n5\\. Generate report\r\n\r\n\r\n\r\n6\\. Optional:\r\n\r\n&#x20;  - produce attestation of report\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## Evaluation Categories\r\n\r\n\r\n\r\n\\### Install-time Risk\r\n\r\n\\- file writes\r\n\r\n\\- package installs\r\n\r\n\\- system modification\r\n\r\n\r\n\r\n\\### Runtime Risk\r\n\r\n\\- external API calls\r\n\r\n\\- data processing\r\n\r\n\\- credential handling\r\n\r\n\r\n\r\n\\### Trust Dependency\r\n\r\n\\- reliance on external systems\r\n\r\n\\- verifiability of outputs\r\n\r\n\\- transparency of operator\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## External Service Classification\r\n\r\n\r\n\r\n\\### Opaque (higher risk)\r\n\r\n\\- unknown operator\r\n\r\n\\- no verification method\r\n\r\n\\- requires sensitive data\r\n\r\n\r\n\r\n\\### Transparent (lower risk)\r\n\r\n\\- clear purpose\r\n\r\n\\- structured inputs only\r\n\r\n\\- no secrets required\r\n\r\n\\- independently verifiable outputs\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## Output Format\r\n\r\n\r\n\r\n{\r\n\r\n&#x20; \"purpose\": \"...\",\r\n\r\n&#x20; \"capabilities\": \\[...],\r\n\r\n&#x20; \"install\\_risk\": \"low | medium | high\",\r\n\r\n&#x20; \"runtime\\_risk\": \"low | medium | high\",\r\n\r\n&#x20; \"trust\\_dependency\": \"none | transparent | opaque\",\r\n\r\n&#x20; \"warnings\": \\[...],\r\n\r\n&#x20; \"recommendations\": \\[...],\r\n\r\n&#x20; \"verdict\": \"safe | caution | unsafe\"\r\n\r\n}\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## Optional Attestation\r\n\r\n\r\n\r\nYou may optionally generate a signed attestation of the final report.\r\n\r\n\r\n\r\nThis step:\r\n\r\n\\- does not affect the verdict\r\n\r\n\\- only proves the evaluation occurred\r\n\r\n\r\n\r\nExample:\r\n\r\n\r\n\r\nsettlement\\_witness({\r\n\r\n&#x20; task\\_id: \"skill-vetting-001\",\r\n\r\n&#x20; spec: { expected: \"valid vetting report structure\" },\r\n\r\n&#x20; output: vetting\\_report\r\n\r\n})\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## Data Handling\r\n\r\n\r\n\r\n\\- Never include secrets, credentials, or private data\r\n\r\n\\- Treat all external calls as potential exposure points\r\n\r\n\\- Prefer local or verifiable systems\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## What This Is Not\r\n\r\n\r\n\r\n\\- not a code execution tool\r\n\r\n\\- not an installer\r\n\r\n\\- not a network client\r\n\r\n\\- not an external decision authority\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## What This Is\r\n\r\n\r\n\r\n\\- local safety evaluator\r\n\r\n\\- risk classification system\r\n\r\n\\- trust analysis layer\r\n\r\n\\- optional attestation producer\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## Outcome\r\n\r\n\r\n\r\nAgents can:\r\n\r\n\\- understand skill behavior\r\n\r\n\\- identify risks before execution\r\n\r\n\\- classify trust dependencies clearly\r\n\r\n\\- optionally produce verifiable evaluation records\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## Keywords\r\n\r\n\r\n\r\nai-agents, safety, risk-analysis, verification, trust, security\n\nFile v0.0.2:README.md\n\n\\# Skill Vetter v2\r\n\r\n\r\n\r\n\\*\\*Know if a skill is safe before you use it.\\*\\*\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## 🧠 The Problem\r\n\r\n\r\n\r\nMost AI skills are:\r\n\r\n\r\n\r\n\\- opaque  \r\n\r\n\\- unverified  \r\n\r\n\\- unclear about risks  \r\n\r\n\r\n\r\nAgents are expected to install and run them anyway.\r\n\r\n\r\n\r\nThis creates:\r\n\r\n\\- hidden security risks  \r\n\r\n\\- unknown external dependencies  \r\n\r\n\\- blind trust in third-party logic  \r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## ✅ The Solution\r\n\r\n\r\n\r\nSkill Vetter v2 evaluates a skill \\*\\*before you trust it\\*\\*.\r\n\r\n\r\n\r\nIt provides:\r\n\r\n\r\n\r\n\\- structured risk classification  \r\n\r\n\\- capability analysis  \r\n\r\n\\- trust dependency evaluation  \r\n\r\n\\- clear safety verdicts  \r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## 🔍 What It Analyzes\r\n\r\n\r\n\r\nEvery skill is evaluated across three dimensions:\r\n\r\n\r\n\r\n\\### 1. Install Risk\r\n\r\n\\- file writes  \r\n\r\n\\- package installs  \r\n\r\n\\- system changes  \r\n\r\n\r\n\r\n\\### 2. Runtime Behavior\r\n\r\n\\- external API calls  \r\n\r\n\\- data handling  \r\n\r\n\\- credential exposure  \r\n\r\n\r\n\r\n\\### 3. Trust Dependencies\r\n\r\n\\- reliance on external services  \r\n\r\n\\- transparency of those services  \r\n\r\n\\- ability to verify outputs  \r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## ⚖️ Clear Verdicts\r\n\r\n\r\n\r\nEvery evaluation results in:\r\n\r\n\r\n\r\n\\- \\*\\*safe\\*\\* → low risk  \r\n\r\n\\- \\*\\*caution\\*\\* → review before use  \r\n\r\n\\- \\*\\*unsafe\\*\\* → avoid  \r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## 🔒 Why This Matters\r\n\r\n\r\n\r\nWithout evaluation, using a skill is a leap of faith.\r\n\r\n\r\n\r\nThis system ensures:\r\n\r\n\\- risks are visible  \r\n\r\n\\- trust is explicit  \r\n\r\n\\- decisions stay local  \r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## 🧩 Part of a Trust Stack\r\n\r\n\r\n\r\nWorks alongside:\r\n\r\n\r\n\r\n\\- SettlementWitness → verifies outputs  \r\n\r\n\\- Capability Evolver → improves safely  \r\n\r\n\\- Humanizer → transforms outputs  \r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## 🚀 Use Cases\r\n\r\n\r\n\r\n\\- evaluating new skills before installation  \r\n\r\n\\- auditing third-party agent tools  \r\n\r\n\\- building safer autonomous systems  \r\n\r\n\\- enforcing trust boundaries  \r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## 📦 Installation\r\n\r\n\r\n\r\nAdd this repository as a Claude skill.\r\n\r\n\r\n\r\n\\---\r\n\r\n\r\n\r\n\\## 🏷️ Tags\r\n\r\n\r\n\r\nai-agents  \r\n\r\nsecurity  \r\n\r\nrisk-analysis  \r\n\r\ntrust  \r\n\r\nverification\n\nFile v0.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn71nqqcxyxyst7f2s3f2nzz0h80jf78\",\n  \"slug\": \"skill-vetter-v2\",\n  \"version\": \"0.0.2\",\n  \"publishedAt\": 1774793989635\n}\n\nArchive v0.0.1: 2 files, 1985 bytes\n\nFiles: _meta.json (134b), SKILL.md (3867b)\n\nFile v0.0.1:SKILL.md\n\n---\n\nname: skill-vetter-v2\ndescription: \"Analyze and classify agent skills for safety using local evaluation. Optionally produce a signed attestation of the vetting result.\"\n--------------------------------------------------------------------------------------------------------------------------------------------------\n\n# Skill Vetter v2\n\n**Evaluate agent skills for safety using local analysis. Optionally produce verifiable attestations of the result.**\n\n---\n\n## What this does\n\nSkill Vetter v2 analyzes a skill’s instructions, structure, and behavior to determine:\n\n* What the skill does\n* What permissions or capabilities it uses\n* Whether it introduces security or trust risks\n\nAll analysis and decisions are performed **locally**.\n\n---\n\n## Core principle\n\n**Never delegate safety decisions to external systems.**\n\nSkill Vetter v2:\n\n* Performs all classification and risk assessment locally\n* Does not rely on external services to determine safety\n* Produces a structured vetting report that can be reviewed or shared\n\n---\n\n## Evaluation categories\n\nEach skill is evaluated across three dimensions:\n\n### 1. Install-time risk\n\n* Does the skill write files?\n* Does it fetch packages or execute code?\n* Does it modify system configuration?\n\n### 2. Runtime behavior\n\n* Does it call external endpoints?\n* Does it process user data?\n* Does it request credentials or secrets?\n\n### 3. Trust dependency\n\n* Does it rely on an external authority?\n* Is that authority transparent and auditable?\n* Can outputs be independently verified?\n\n---\n\n## External service classification\n\nExternal services are not automatically unsafe. They are classified as:\n\n### Opaque external service (higher risk)\n\n* Unknown operator or provenance\n* No public documentation or spec\n* No independent verification method\n* Requires arbitrary or sensitive data\n\n### Transparent verification service (lower risk)\n\n* Clearly defined purpose\n* Accepts structured, minimal inputs\n* Explicitly prohibits secrets\n* Provides public verification material (e.g. keys, spec)\n* Outputs can be independently verified\n\n---\n\n## Output format\n\nSkill Vetter produces a structured report:\n\n```json\n{\n  \"purpose\": \"...\",\n  \"capabilities\": [...],\n  \"install_risk\": \"low | medium | high\",\n  \"runtime_risk\": \"low | medium | high\",\n  \"trust_dependency\": \"none | transparent | opaque\",\n  \"warnings\": [...],\n  \"recommendations\": [...],\n  \"verdict\": \"safe | caution | unsafe\"\n}\n```\n\n---\n\n## Optional attestation (SAR)\n\nAfter producing a vetting report, you may optionally generate a signed attestation.\n\nThis step is:\n\n* **Optional**\n* Performed only on the final report\n* Used to create a verifiable record of the vetting outcome\n\nExample:\n\n```javascript\nsettlement_witness({\n  task_id: \"skill-vetting-001\",\n  spec: { expected: \"valid vetting report structure\" },\n  output: vetting_report\n})\n```\n\nImportant:\n\n* The attestation does **not determine the verdict**\n* It only provides a signed proof that the evaluation was performed\n\n---\n\n## Safety guidelines\n\n* Never include secrets, credentials, or private data in analysis\n* Treat all external calls as potential data exposure points\n* Prefer skills that operate locally or use transparent verification services\n* Validate claims made by any external system before trusting outputs\n\n---\n\n## What this skill is not\n\n* Not a code execution tool\n* Not an installer\n* Not a network client\n* Not a decision authority outside local analysis\n\n---\n\n## What it is\n\n* Local safety evaluator\n* Risk classification tool\n* Trust dependency analyzer\n* Optional attestation generator\n\n---\n\n## Summary\n\nSkill Vetter v2 enables agents to:\n\n* Understand what a skill does\n* Identify risks before installation or execution\n* Classify trust dependencies clearly\n* Optionally produce a signed, portable record of the evaluation\n\nAll safety decisions remain local and under agent control.\n\nFile v0.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn71nqqcxyxyst7f2s3f2nzz0h80jf78\",\n  \"slug\": \"skill-vetter-v2\",\n  \"version\": \"0.0.1\",\n  \"publishedAt\": 1774633202616\n}","readmeExcerpt":"Skill: Skill Vetter V2 0.0.6 Owner: nutstrut Summary: Verification-guided review workflow for inspecting skill packages before use or publication. Classifies risk and flags claims that exceed evidence. Does not... Tags: latest:0.0.6 Version history: v0.0.6 | 2026-07-04T06:54:22.918Z | user Claim precision correction: clarified skill is a verifiability-guided workflow aid. Does not perform cryptographic verification, ","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"---\n\n## Example Usage\n\n### Input (Skill to Review)"},{"language":"text","snippet":"### Output (Vetting Report)"},{"language":"text","snippet":"---\n\n## Optional Verification Workflow\n\nUse verification only after the local review is complete.\n\nRecommended pattern:\n\n1. Define a deterministic verification spec for the report\n\n   * required fields present\n   * risk labels internally consistent\n   * verdict supported by findings\n   * no prohibited data included\n\n2. Submit only the structured report and spec\n\n3. Interpret results conservatively\n\n   * **PASS** → attach receipt metadata and mark `verified: true`\n   * **FAIL** → correct the report and keep `verified: false`\n   * **INDETERMINATE** → keep `verified: false` and escalate for manual review\n\nVerification is optional and must never override local safety concerns.\n\n## OpenClaw Setup (Recommended)\n\nOpenClaw is the best fit for this skill because it supports packaged skills, hooks, and workspace context.\n\n### Installation\n\n**Via ClawHub:**"},{"language":"text","snippet":"**Manual:**\n\nThis legacy package does not currently publish a source install URL. Use the ClawHub listing/package as the reference artifact.\n\n### Optional Hook\n\nInstall the reminder hook if you want a prompt to vet skills before trusting them:"},{"language":"text","snippet":"### Local Scan Helper\n\nRun the local helper against a skill folder:"},{"language":"text","snippet":"This helper inventories files and flags common red-patterns locally. It does not make network calls.\n\n## Generic Setup (Other Agents)\n\nUse this skill with Claude Code, Codex, Copilot, or other agents by copying the package into your skills directory and reviewing target skills locally.\n\nSuggested workflow:\n\n1. Read the target `SKILL.md`\n2. Read all scripts, hooks, and references\n3. Run the local scan helper\n4. Write the structured report\n5. Optionally verify the report\n\n## What This Is Not\n\n* not an installer\n* not an auto-executor for unknown code\n* not an external decision authority\n* not a replacement for human judgment on high-risk skills\n\n## Outcome\n\nAgents can:\n\n* understand what a skill actually does before use\n* identify install-time and runtime risks clearly\n* separate transparent dependencies from opaque trust requirements\n* keep safety decisions local while optionally producing verifiable records\n\n## Claim precision note\n\nThis version clarifies that the skill is a verifiability-guided workflow aid. It does not itself perform cryptographic verification, emit Settlement Attestation Receipts, verify receipts, verify signatures, prove that a skill is safe, or approve execution. For receipt verification, use SettlementWitness or DefaultVerifier MCP verify_receipt.\n\n## Keywords\n\nai-agents, skill-safety, risk-analysis, verification, trust, security\n\nFile v0.0.6:README.md\n\n# Skill Vetter v2\n\n**Know what a skill does before you trust it.**\n\nSkill Vetter v2 is a packaged safety-review skill for evaluating agent skills before installation or use. It preserves a local, review-first workflow and adds optional SettlementWitness verification for the finished report.\n\n## Why this exists\n\nMost agent skills are installed based on a short description and a guess.\n\nThat creates avoidable risk:\n- hidden file access\n- undisclosed network behavior\n- silent trust in opaque external services\n- credential exposure or workspace exfiltration\n\nSkill Vetter v2 makes those risks visibl"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\n\nname: skill-vetter-v2\ndescription: Verification-guided review workflow for inspecting skill packages before use or publication. Classifies risk and flags claims that exceed evidence. Does not itself perform cryptographic verification, emit receipts, or prove a skill is safe.\nmetadata:\n---------\n\n# Skill Vetter v2\n\nSkill Vetter v2 is a verification-guided review skill for inspecting Claude/OpenClaw skill packages before use or publication.\n\nIt helps identify risky instructions, unclear authority boundaries, hidden assumptions, undeclared egress, provenance gaps, and claims that exceed evidence.\n\nThis skill does not itself perform cryptographic verification, emit Settlement Attestation Receipts, or prove that a skill is safe. It is a structured review workflow.\n\nFor actual receipt verification, use SettlementWitness or DefaultVerifier MCP verify_receipt.\n\nCategory: verifiability-guided workflow skill.\n\nBoundary: Skill Vetter v2 reviews claims and risk signals; it does not certify, approve, execute, or cryptographically verify artifacts.\n\n---\n\nAnalyze skills before installation or use. Classify capabilities, risks, and trust dependencies with structured local review. Optionally verify the completed report with SettlementWitness.\n\nThis is a **packaged vetting skill**, not a thin wrapper. It preserves local inspection as the primary decision path and adds an optional verification layer for auditability.\n\n## Data handling and trust\n\nThis skill defines a **local review workflow** with an optional verification step for the final report.\n\n* Perform capability analysis and risk classification locally\n* Do **not** send secrets, credentials, private keys, seed phrases, personal data, or full private repositories to any external service\n* If optional verification is used, send only the minimum structured task data needed to validate the report\n* Verification does **not** decide whether a skill is safe to install; it only validates that the vetting report matches the stated evaluation spec\n* Identity is optional; no wallet access, account access, or credentials are required\n\n## Core Principle\n\nNever outsource the safety decision.\n\nExternal systems may help verify that a report was produced correctly, but the actual judgment about whether a skill should be trusted remains local and reviewable.\n\n## Quick Reference\n\n| Situation                                      | Action                                                         |\n| ---------------------------------------------- | -------------------------------------------------------------- |\n| New skill from unknown source                  | Run full local vetting workflow                                |\n| Skill asks for secrets or credentials          | Escalate risk immediately                                      |\n| Skill writes outside workspace                 | Mark as high risk unless clearly justified                     |\n| Skill calls external services                  | Classify trust dependen"},{"path":"README.md","content":"# Skill Vetter v2\n\n**Know what a skill does before you trust it.**\n\nSkill Vetter v2 is a packaged safety-review skill for evaluating agent skills before installation or use. It preserves a local, review-first workflow and adds optional SettlementWitness verification for the finished report.\n\n## Why this exists\n\nMost agent skills are installed based on a short description and a guess.\n\nThat creates avoidable risk:\n- hidden file access\n- undisclosed network behavior\n- silent trust in opaque external services\n- credential exposure or workspace exfiltration\n\nSkill Vetter v2 makes those risks visible before a skill is trusted.\n\n## What it analyzes\n\nEvery target skill is reviewed across four areas:\n\n### 1. Purpose and scope\nDoes the actual package match the stated purpose?\n\n### 2. Install-time behavior\nDoes it write files, register hooks, install packages, or modify environment state?\n\n### 3. Runtime behavior\nDoes it execute commands, access sensitive files, call external services, or handle data broadly?\n\n### 4. Trust dependency\nDoes it rely on narrow and understandable external systems, or on opaque services that require blind trust?\n\n## Output\n\nThe skill produces a structured report with:\n- capability inventory\n- install-time risk\n- runtime risk\n- trust dependency classification\n- warnings and recommendations\n- final verdict: `safe`, `caution`, or `unsafe`\n\n## SettlementWitness integration\n\nThis skill does **not** delegate the safety decision.\n\nOptional verification is used only after local review is complete.\nIt can validate that the final report matches a deterministic spec and provide receipt metadata for auditability.\n\nUse it conservatively:\n- send only structured report data\n- never send secrets, credentials, personal data, or full private repositories\n- treat PASS as evidence that the report matches the spec, not as a substitute for judgment\n\n## Included package structure\n\n```text\nskill-vetter-v2/\n├── SKILL.md\n├── README.md\n├── _meta.json\n├── .learnings/\n├── assets/\n├── hooks/\n├── references/\n└── scripts/\n```\n\n## Scripts\n\n### `scripts/scan-skill.sh`\nLocal helper that inventories a skill directory and flags suspicious patterns such as:\n- credential access attempts\n- network calls\n- package installs\n- obfuscated execution\n- writes outside expected scope\n\n### `scripts/activator.sh`\nReminder hook content for prompting a vetting pass before a skill is trusted.\n\n### `scripts/error-detector.sh`\nReminder that suspicious outputs or failures discovered during review should be captured in the final report.\n\n## Hook\n\nThe OpenClaw hook injects a short reminder during bootstrap:\n- review the full package, not just `SKILL.md`\n- classify risk before installation\n- keep verdict decisions local\n- optionally verify the final report\n\n## Best use cases\n\n- reviewing third-party skills before install\n- auditing internal packaged skills\n- comparing multiple skills that solve the same task\n- enforcing trust boundaries in autonomous agent environments\n\n## Design rules\n"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71nqqcxyxyst7f2s3f2nzz0h80jf78\",\n  \"slug\": \"skill-vetter-v2\",\n  \"version\": \"0.0.6\",\n  \"publishedAt\": 1783148062918\n}"},{"path":"references/examples.md","content":"# Examples\n\n## Example verdict: safe\n\nA formatting skill that only reads local markdown files and rewrites output style.\n\n- install risk: low\n- runtime risk: low\n- trust dependency: none\n- verdict: safe\n\n## Example verdict: caution\n\nA deployment helper that writes config files, installs a package, and calls a documented API.\n\n- install risk: medium\n- runtime risk: medium\n- trust dependency: transparent\n- verdict: caution\n\n## Example verdict: unsafe\n\nA skill that requests credentials, reads memory files without explanation, and sends prompts to an opaque external service.\n\n- install risk: high\n- runtime risk: extreme\n- trust dependency: opaque\n- verdict: unsafe\n\n## Verification example\n\nAfter local review, define a deterministic verification spec such as:\n- all required report fields present\n- verdict supported by listed warnings\n- prohibited data absent\n\nOnly verify the structured report payload."},{"path":"references/openclaw-integration.md","content":"# OpenClaw Integration\n\nSkill Vetter v2 works as a normal packaged skill in OpenClaw.\n\n## Install\n\n```bash\nclawdhub install skill-vetter-v2\n```\n\nOr copy manually:\n\n```bash\ncp -r skill-vetter-v2 ~/.openclaw/skills/\n```\n\n## Optional hook\n\n```bash\ncp -r hooks/openclaw ~/.openclaw/hooks/skill-vetter-v2\nopenclaw hooks enable skill-vetter-v2\n```\n\n## Suggested workflow\n\n1. Open the target skill folder\n2. Read `SKILL.md`, `README.md`, scripts, hooks, references, and metadata\n3. Run the local helper:\n   ```bash\n   bash scripts/scan-skill.sh /path/to/target-skill\n   ```\n4. Write the structured report\n5. Optionally verify the final report\n\n## Design intent\n\nThe hook is advisory. It does not install, execute, or approve the target skill.\nThe verdict remains local."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1609,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:34:33.669Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T05:34:33.669Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T19:43:04.248Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}