skill-vetter

Assess AI skills for security risks and generate a structured vetting report.

15|6|Updated Mar 11, 2026
One-click install
npx skills add https://github.com/CloudChef/atlasclaw-providers --skill skill-vetter-cloudchef
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-vetter
Source: https://github.com/CloudChef/atlasclaw-providers/tree/main/skills/skill-vetter-1.0.0
Command: npx skills add https://github.com/CloudChef/atlasclaw-providers --skill skill-vetter-cloudchef

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security-first vetting protocol to prevent unsafe AI skills from being installed by enforcing checks for red flags, permission scope, and suspicious patterns.

Core Features & Use Cases

  • Stepwise vetting process: source verification, mandatory code review, permission scope assessment, and risk classification
  • Generates a standardized vetting report with verdict, red flags, and recommended actions
  • Supports quick vetting for GitHub, ClawdHub, or other sources via reusable commands and guidelines
  • Provides trust hierarchy guidance and safety reminders for human decision-makers

Quick Start

Run a vet on a new skill before installation to generate a safety report.

Frequently Asked Questions about skill-vetter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I vet AI skills for security risks before installing them?

To vet AI skills for security risks, apply source verification, mandatory code review, permission scope assessment, and risk classification. This process identifies red flags and determines a trust level to produce a structured safety report with an install verdict.

What security red flags should I check for when reviewing AI skills from GitHub or ClawdHub?

When reviewing AI skills from GitHub or ClawdHub, check for suspicious patterns, excessive permission scopes, and unverified sources. A proper security vetting process classifies these red flags to determine the risk level and generate a standardized safety report.

How can I assess the permission scope of an AI skill to prevent unauthorized access?

Assessing the permission scope of an AI skill involves evaluating required permissions during a mandatory code review. This risk assessment identifies excessive access privileges, classifies them as red flags, and determines an overall trust level before installation.

Does code review help determine the trust level of third-party AI skills?

Code review is a mandatory step to determine the trust level of third-party AI skills. By analyzing the code alongside source verification and permission scope assessment, the vetting process classifies security risks and outputs a clear install verdict.

What is the best way to generate a standardized vetting report for AI skill installation?

The best way to generate a standardized vetting report is to apply a stepwise security protocol covering source verification, code review, and risk classification. This produces a structured document detailing red flags, required permissions, and an install verdict.

When should I avoid installing an AI skill based on a risk assessment?

You should avoid installing an AI skill when the risk assessment identifies unverified sources, excessive permission scopes, or suspicious code patterns. The vetting report will explicitly state these red flags and issue a negative install verdict to prevent security breaches.