skill-vetter

Analyze AI agent skills for security risks and installation verdicts.

2|Updated Mar 10, 2026
One-click install
npx skills add https://github.com/caoronglin/copaw-skills --skill skill-vetter-caoronglin
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-vetter
Source: https://github.com/caoronglin/copaw-skills/tree/main/skills/skill-vetter
Command: npx skills add https://github.com/caoronglin/copaw-skills --skill skill-vetter-caoronglin

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill provides a crucial security layer by vetting AI agent skills before installation, preventing the introduction of malicious code or risky permissions.

Core Features & Use Cases

  • Pre-installation Security Audit: Analyzes skills for red flags, suspicious network activity, and excessive permission requests.
  • Risk Classification: Assigns a risk level (Low, Medium, High, Extreme) to guide installation decisions.
  • Use Case: Before installing a new skill from an unknown GitHub repository, use the skill-vetter to perform a thorough security check and receive a clear verdict on whether it's safe to proceed.

Quick Start

Use the skill vetter to perform a security check on the skill named 'new-data-analyzer'.

Frequently Asked Questions about skill-vetter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I perform a security audit on an AI agent skill before installing it?

Perform a pre-installation security audit on an AI agent skill by analyzing its source code, network activity, and permission scope to identify red flags. This process assigns a risk classification and provides a clear installation verdict to prevent malicious code execution.

What is skill vetting and when do I need it for my AI agent?

Skill vetting is a security-first protocol needed when installing new AI agent skills from unknown sources. It identifies and mitigates risks by analyzing source code and permission scope, classifying risk levels from Low to Extreme to prevent malicious code execution.

How do I check if a skill from a GitHub repository is safe to use?

Check if a skill from a GitHub repository is safe by running a vetting protocol that analyzes the code for suspicious network activity and excessive permission requests. This security check assigns a risk level to guide your installation decision.

Can I assess code permissions and risk levels for AI agent skills automatically?

Yes, you can assess code permissions and risk levels automatically by using a vetting protocol that analyzes the permission scope of AI agent skills. It assigns a risk level of Low, Medium, High, or Extreme to guide safe installation decisions.

What are the limitations of using a security vetting protocol for AI agent skills?

The limitations of a security vetting protocol for AI agent skills include relying on analyzing source code and permission scope without runtime behavior monitoring. It provides a risk classification and installation verdict based solely on pre-installation static analysis.

Does the skill-vetter provide a clear verdict on whether to install an AI agent skill?

Yes, the skill-vetter provides a clear installation verdict by performing a security-first vetting protocol. It analyzes source, code, and permission scope to classify risk levels and determine if an AI agent skill is safe to install.