skill-vetter

Evaluate AI agent skills for malicious code and excessive permissions.

Updated May 30, 2026
One-click install
npx skills add https://github.com/zeroix07/mcp-skill-agent --skill skill-vetter-zeroix07
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-vetter
Source: https://github.com/zeroix07/mcp-skill-agent/tree/main/skill-vetter
Command: npx skills add https://github.com/zeroix07/mcp-skill-agent --skill skill-vetter-zeroix07

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Installing unvetted AI agent skills from untrusted sources like GitHub or ClawdHub can introduce critical security risks including malware, credential theft, and unauthorized system access. This Skill eliminates that risk by providing a standardized, security-first vetting protocol to evaluate any skill before installation.

Core Features & Use Cases

  • 4-Step Vetting Protocol: Systematic checks covering source credibility, mandatory code review for security red flags, permission scope assessment, and standardized risk classification.
  • Standardized Vetting Report: Generates a consistent, easy-to-read report with risk level, installation verdict, and flagged issues to inform decision-making.
  • Quick GitHub Vet Commands: Pre-built commands to quickly fetch repository stats, file lists, and skill metadata for GitHub-hosted skills.
  • Use Case: Before installing a new data analysis skill from an unknown GitHub repository, use this protocol to scan for malicious code patterns like unauthorized data exfiltration or credential access, and get a clear safe/do not install verdict.

Quick Start

Use the skill-vetter protocol to evaluate the 'new-data-skill' from GitHub before installing it on your system.

Frequently Asked Questions about skill-vetter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check an AI agent skill for malware before installing it?

To check an AI agent skill for malware before installing it, apply a security-first vetting protocol that scans all scripts and configuration files for malicious code, unauthorized data access, and excessive permission requests. This process generates a standardized risk classification report.

What is skill vetting and when do I need to review agent permissions?

Skill vetting is a security protocol to evaluate third-party AI agent skills for malicious code and excessive permission requests before installation. You need to review agent permissions when sourcing skills from untrusted repositories like GitHub or ClawdHub to prevent unauthorized system access.

How to vet a GitHub-hosted AI skill for security red flags?

To vet a GitHub-hosted AI skill for security red flags, use pre-built commands to fetch repository stats and file lists, then perform a mandatory code review covering source credibility, permission scope, and malicious code patterns like credential theft. This yields a clear safe or do not install verdict.

Does the skill vetting protocol work with third-party repositories besides GitHub?

Yes, the skill vetting protocol works with third-party repositories beyond GitHub, including ClawdHub and other sources. It evaluates all skill files such as scripts, configuration, and documentation to detect unauthorized data exfiltration and classify installation risk consistently.

Can I get a standardized risk report after evaluating an AI agent skill?

Yes, you can get a standardized risk report after evaluating an AI agent skill. The vetting protocol generates an easy-to-read report detailing the risk level, installation verdict, and specific flagged issues to inform your decision-making before installation.