Skill Vetter for Openclaw

A security-first vetting protocol designed to detect malicious code and risk levels in AI agent skills before installation.

firebroo
v1.0.0
Mar 4, 2026
0
859
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install security-skiil-scanner

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install security-skiil-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Skill Vetter?

Skill Vetter is a comprehensive security protocol designed to protect developers and AI agents from malicious code and unauthorized data access. It provides a systematic framework for auditing the source code of potential additions to your toolkit, ensuring that no untrusted logic is executed within your environment. By standardizing the review of Openclaw Skills, this tool identifies red flags such as credential theft, obfuscated scripts, and unnecessary exfiltration attempts.

This skill acts as a gatekeeper, moving beyond simple installation to a model of deep inspection. It enforces the principle of least privilege by analyzing permission scopes and requiring structured vetting reports for every new integration. Whether you are downloading from a marketplace or a private repository, using this protocol ensures that all your Openclaw Skills are safe, transparent, and reliable.

Skill Vetter Use Cases

  • Evaluating new scripts or packages from ClawHub before deployment.
  • Auditing third-party GitHub repositories for hidden malicious payloads.
  • Reviewing skills shared between autonomous agents in a multi-agent system.
  • Risk-assessing any skill that requests access to sensitive directories like .ssh or .aws config folders.

How Skill Vetter Works

  1. Source Verification: Analyzes the reputation of the author, update frequency, and community trust metrics.
  2. Mandatory Code Review: Scans all files for high-risk commands such as base64 decoding, eval, or unauthorized curl requests.
  3. Permission Audit: Evaluates the necessity of requested file system access and outbound network calls.
  4. Risk Classification: Assigns a risk level from LOW to EXTREME based on the findings of the review process.
  5. Structured Reporting: Generates a final Vetting Report with a clear recommendation: Install, Install with Caution, or Reject.

Skill Vetter Setup

To get started with the vetting process, ensure your environment has the required binaries installed.

# Install dependencies (Example for Debian/Ubuntu)
sudo apt-get update && sudo apt-get install curl jq -y

# Prepare a temporary directory for vetting new skills
mkdir -p /tmp/skill-vet

Once dependencies are met, you can use the built-in commands to inspect the metadata of various Openclaw Skills before they are added to your main workspace.

Skill Vetter Data Schema & Taxonomy

The skill produces and organizes security data using the following taxonomy:

Attribute Description
Source Metadata Identifies the author, version, and repository origin.
Red Flags A log of detected security violations like credential harvesting patterns.
Permission Scope A breakdown of required file, network, and command permissions.
Risk Level A classification (LOW, MEDIUM, HIGH, EXTREME) based on technical risk.
Verdict The final security recommendation for the agent or user.

Skill Vetter Advanced Features

  • Automated Red Flag Detection: Scans for obfuscated, minified, or encoded payloads designed to bypass simple filters.
  • Trust Hierarchy: Implements a tiered trust model that treats official Openclaw Skills differently than unverified third-party scripts.
  • Integration with Zero-Trust: Works seamlessly with security frameworks to enforce verification flows for high-risk decisions.
  • Audit Logging: Creates a permanent record of vetting decisions to maintain a history of security compliance.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*