A security-first vetting protocol designed to detect malicious code and risk levels in AI agent skills before installation.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install security-skiil-scanner
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install security-skiil-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
Skill Vetter is a comprehensive security protocol designed to protect developers and AI agents from malicious code and unauthorized data access. It provides a systematic framework for auditing the source code of potential additions to your toolkit, ensuring that no untrusted logic is executed within your environment. By standardizing the review of Openclaw Skills, this tool identifies red flags such as credential theft, obfuscated scripts, and unnecessary exfiltration attempts.
This skill acts as a gatekeeper, moving beyond simple installation to a model of deep inspection. It enforces the principle of least privilege by analyzing permission scopes and requiring structured vetting reports for every new integration. Whether you are downloading from a marketplace or a private repository, using this protocol ensures that all your Openclaw Skills are safe, transparent, and reliable.
To get started with the vetting process, ensure your environment has the required binaries installed.
# Install dependencies (Example for Debian/Ubuntu)
sudo apt-get update && sudo apt-get install curl jq -y
# Prepare a temporary directory for vetting new skills
mkdir -p /tmp/skill-vet
Once dependencies are met, you can use the built-in commands to inspect the metadata of various Openclaw Skills before they are added to your main workspace.
The skill produces and organizes security data using the following taxonomy:
| Attribute | Description |
|---|---|
| Source Metadata | Identifies the author, version, and repository origin. |
| Red Flags | A log of detected security violations like credential harvesting patterns. |
| Permission Scope | A breakdown of required file, network, and command permissions. |
| Risk Level | A classification (LOW, MEDIUM, HIGH, EXTREME) based on technical risk. |
| Verdict | The final security recommendation for the agent or user. |
Loading
A comprehensive command-line interface for managing Google Workspace services including Gmail, Calendar, Drive, and Sheets.

A specialized tool for AI agents to retrieve and summarize school timetables and substitution plans directly from WebUntis.

A comprehensive tool for browsing MongoDB Atlas API specifications and executing live administrative operations.

A lightweight utility to track your remaining Antigravity AI model tokens and quota status directly from the command line.

Automate the discovery and tracking of tech events and meetups globally from Luma.

A pre-install security gate that scans Openclaw Skills for prompt injections, malware, and hardcoded secrets before they touch your system.








































