skill-vetter

Automate security vetting of AI agent skills before installation.

1|1|Updated Mar 22, 2026
One-click install
npx skills add https://github.com/polaris-dxz/xclaw --skill skill-vetter-polaris-dxz
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-vetter
Source: https://github.com/polaris-dxz/xclaw/tree/main/apps/desktop/openclaw-runtime/config/skills/skill-vetter
Command: npx skills add https://github.com/polaris-dxz/xclaw --skill skill-vetter-polaris-dxz

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This tool ensures secure vetting of AI agent skills before installation, protecting systems from unsafe or untrusted code.

Core Features & Use Cases

  • Stepwise vetting protocol including source checks, mandatory code review, permission scope assessment, and risk classification to produce a standardized vetting report.
  • Useful before installing skills from ClawdHub, GitHub, or other sources, or when evaluating skills shared by other agents.
  • Quick-start guidance for running the vetting workflow and generating actionable safety recommendations.

Quick Start

Run the vetting workflow on a target skill repository to generate a structured vetting report.

Frequently Asked Questions about skill-vetter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I vet AI skills for security risks before installing them?

Vetting AI skills for security risks requires applying a defined protocol with source checks, mandatory code review, and permission scope assessment to generate a standardized risk classification report before installation.

What is the process for risk assessment of AI agent skills from GitHub?

Risk assessment of AI agent skills from GitHub applies a stepwise vetting protocol including source verification, mandatory code review, and permission scope evaluation to produce a standardized safety report.

Can I perform trust and safety code review on skills from unknown sources?

Yes, you can perform trust and safety code review on skills from unknown sources by applying the vetting protocol, which guides introspection and permission review to classify risks and generate actionable safety recommendations.

Does automated skill vetting work with ClawdHub skill acquisition workflows?

Automated skill vetting applies directly during skill acquisition from ClawdHub, GitHub, or other unknown sources, guiding introspection and permission review to prevent dangerous code installation.

What's the best way to generate a security report for an AI skill before installation?

The best way to generate a security report is running the stepwise vetting workflow on the target skill repository, which performs source checks and permission scope assessment to output a standardized vetting report.

When do I need to use a standardized vetting protocol for AI skills?

You need a standardized vetting protocol when evaluating skills shared by other agents or acquiring them from untrusted repositories, ensuring dangerous code is identified before system execution.