skill-vetter

Vets AI agent skills for security risks before installation.

Updated Apr 20, 2026
One-click install
npx skills add https://github.com/Kraits/cxc-ace --skill skill-vetter-kraits
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-vetter
Source: https://github.com/Kraits/cxc-ace/tree/main/skills-backup/skill-vetter
Command: npx skills add https://github.com/Kraits/cxc-ace --skill skill-vetter-kraits

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Security-first vetting of AI agent skills to prevent unsafe code, hidden permissions, and risky behavior from being installed without review.

Core Features & Use Cases

  • Source checks: verify origin, author reputation, and update history.
  • Code review: mandatory examination of all files for red flags and compliance.
  • Permission scope assessment: evaluate required read/write access and network usage.
  • Risk classification & reporting: produce a structured vetting report with actionable verdicts.

Quick Start

Provide the repository URL of the skill to vet, and start the vetting workflow before installation.

Frequently Asked Questions about skill-vetter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I vet AI skills for security risks before installing them?

Vetting AI agent skills before installation involves source verification, code review, and permission scope assessment. This skill guides reviewers through a structured workflow to flag hidden risks, analyze read/write access, and produce a standardized vetting report.

What is AI skill vetting and why is it necessary?

AI skill vetting is the security-first process of examining source code, author reputation, and permission scopes to prevent unsafe code installation. It is necessary to avoid hidden risks, ensure compliance, and maintain trust when adding agent skills from repositories.

Can I use this vetting workflow for skills sourced from GitHub and ClawdHub?

Yes, this vetting workflow applies to skills sourced from ClawdHub, GitHub, or other repositories. It guides reviewers through source checks, code reviews, and permission assessments universally, generating a standardized report regardless of the origin platform.

How do I review AI skill permissions and code for red flags?

Reviewing AI skill permissions involves evaluating required read/write access and network usage. This skill enforces a mandatory code review of all files to flag red flags and compliance issues, classifying the risk level into a structured vetting report.

What are the limitations of automated AI skill risk assessment?

Automated AI skill risk assessment guides reviewers through source checks, code review, and permission scope evaluation, but it requires manual examination of all files for hidden permissions. It produces a standardized report, but the reviewer must verify compliance and safety.