skill-vetter

Identifies and mitigates risks in third-party AI skills before installation.

Updated Mar 5, 2026
One-click install
npx skills add https://github.com/jitenkr2030/QR-Based-Guard-Attendance-Patrol-Proof-System --skill skill-vetter-jitenkr2030
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-vetter
Source: https://github.com/jitenkr2030/QR-Based-Guard-Attendance-Patrol-Proof-System/tree/main/skills/skill-vetter
Command: npx skills add https://github.com/jitenkr2030/QR-Based-Guard-Attendance-Patrol-Proof-System --skill skill-vetter-jitenkr2030

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill provides a formal vetting protocol to evaluate AI skills before installation, identifying red flags, permission scope issues, and potential risks to systems.

Core Features & Use Cases

  • Source Check: Assess origin, author reputation, and recency to determine trustworthiness.
  • Code Review & Risk Analysis: Mandatory review of all files for red flags and permission requirements.
  • Permission Scope Evaluation: Analyze files read/write access, network needs, and command execution to ensure minimal, necessary privileges.
  • Risk Classification & Reporting: Produce a clear risk level and a structured vetting report with a final verdict.

Quick Start

Run the vetting protocol on the target skill before installation to produce a risk assessment and safety recommendations.

Frequently Asked Questions about skill-vetter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I vet third-party AI skills before installation?

To vet third-party AI skills before installation, you need a formal protocol that assesses source credibility, performs code review for red flags, evaluates permission scope, and outputs a structured risk classification report with a final safety verdict.

What is permission scope evaluation in AI skill risk assessment?

Permission scope evaluation in AI skill risk assessment is the process of analyzing a skill's file read/write access, network requirements, and command execution privileges to ensure it maintains minimal necessary permissions and mitigates potential system threats.

How do I check AI skills for red flags and security risks from GitHub or ClawdHub?

Checking AI skills for red flags requires a mandatory code review of all files from sources like GitHub or ClawdHub to identify malicious patterns, evaluate author reputation, and classify potential data handling vulnerabilities before installation.

Can I use an automated vetting process for AI skills obtained from any source?

Yes, you can apply an automated vetting process to AI skills obtained from any source. The protocol assesses origin trustworthiness, recency, permission scopes, and code-level risks to produce a structured report with a clear installation verdict.

What is the best way to classify risks in third-party AI skills?

The best way to classify risks in third-party AI skills is to enforce a formal vetting process that evaluates source credibility, executes code review, and assesses data handling scenarios to generate a structured report with a defined risk level and safety notes.