What problem does it solve?
Installing unvetted AI agent skills from untrusted sources like GitHub or ClawdHub can introduce critical security risks including malware, credential theft, and unauthorized system access. This Skill eliminates that risk by providing a standardized, security-first vetting protocol to evaluate any skill before installation.
Core Features & Use Cases
- 4-Step Vetting Protocol: Systematic checks covering source credibility, mandatory code review for security red flags, permission scope assessment, and standardized risk classification.
- Standardized Vetting Report: Generates a consistent, easy-to-read report with risk level, installation verdict, and flagged issues to inform decision-making.
- Quick GitHub Vet Commands: Pre-built commands to quickly fetch repository stats, file lists, and skill metadata for GitHub-hosted skills.
- Use Case: Before installing a new data analysis skill from an unknown GitHub repository, use this protocol to scan for malicious code patterns like unauthorized data exfiltration or credential access, and get a clear safe/do not install verdict.
Quick Start
Use the skill-vetter protocol to evaluate the 'new-data-skill' from GitHub before installing it on your system.