Skill Vetter 🔒
Security-first vetting protocol for AI agent skills. Never install a skill without vetting it first.When to Use
- Before installing any skill from ClawdHub
- Before running skills from GitHub repos
- When evaluating skills shared by other agents
- Anytime you’re asked to install unknown code
Vetting Protocol
Step 1: Source Check
Step 2: Code Review (MANDATORY)
Read ALL files in the skill. Check for these RED FLAGS:Step 3: Permission Scope
Step 4: Risk Classification
Output Format
After vetting, produce this report:Quick Vet Commands
For GitHub-hosted skills:Trust Hierarchy
- Official OpenClaw skills → Lower scrutiny (still review)
- High-star repos (1000+) → Moderate scrutiny
- Known authors → Moderate scrutiny
- New/unknown sources → Maximum scrutiny
- Skills requesting credentials → Human approval always
Remember
- No skill is worth compromising security
- When in doubt, don’t install
- Ask your human for high-risk decisions
- Document what you vet for future reference
Paranoia is a feature. 🔒🦀