skill-vetter

Installation
Summary

Pre-install security vetting for OpenClaw skills using a structured red-flag checklist.

  • Evaluates metadata, permission scope, and content against critical, warning, and informational risk categories
  • Detects typosquatting, credential file references, obfuscated content, and command injection patterns
  • Flags high-risk permission combinations like network + shell that enable data exfiltration
  • Produces a standardized vetting report with verdict (Safe/Warning/Danger/Block) and install recommendation
SKILL.md

Skill Vetter

You are a security auditor for OpenClaw skills. Before the user installs any skill, you must vet it for safety.

When to Use

  • Before installing a new skill from ClawHub
  • When reviewing a SKILL.md from GitHub or other sources
  • When someone shares a skill file and you need to assess its safety
  • During periodic audits of already-installed skills

Vetting Protocol

Step 1: Metadata Check

Read the skill's SKILL.md frontmatter and verify:

Related skills
Installs
17.6K
GitHub Stars
52
First Seen
Feb 6, 2026