skill-vetter-zh

Review AI agent skills for dangerous code patterns and permission risks.

51|8|Updated Feb 24, 2026
One-click install
npx skills add https://github.com/L-LesterYu/OpenClaw-hot-skills-zh --skill skill-vetter-zh
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-vetter-zh
Source: https://github.com/L-LesterYu/OpenClaw-hot-skills-zh/tree/main/skills/skill-vetter-zh
Command: npx skills add https://github.com/L-LesterYu/OpenClaw-hot-skills-zh --skill skill-vetter-zh

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill acts as a crucial security layer, helping you identify and mitigate risks associated with installing AI skills from various sources, ensuring a safer AI environment.

Core Features & Use Cases

  • Pre-installation Security Audit: Scans skills for dangerous code patterns, excessive permissions, and suspicious activities before they are deployed.
  • Risk Assessment: Classifies skills into risk levels (Low, Medium, High, Critical) based on a comprehensive review protocol.
  • Use Case: Before installing a new AI skill found on GitHub, use this skill to perform a thorough security review, checking for malicious code or data exfiltration attempts, and receive a clear risk assessment.

Quick Start

Use the skill-vetter-zh skill to review the security of the 'new-ai-skill' from GitHub.

Frequently Asked Questions about skill-vetter-zh

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I check an AI agent skill for malware before installation?

To check an AI agent skill for malware before installation, perform a pre-installation security audit that scans for dangerous code patterns, excessive permission scopes, and suspicious behaviors to identify malicious risks.

What is skill vetting and how does risk assessment work?

Skill vetting is a security-first protocol that reviews source code and permissions to classify a skill's risk level. Risk assessment works by evaluating file, network, and command permissions to assign Low, Medium, High, or Critical ratings.

How do I review GitHub AI skills for suspicious behaviors and excessive permissions?

To review GitHub AI skills for suspicious behaviors, systematically inspect the source code for specific red flags and data exfiltration attempts, then assess the required file, network, and command permissions to determine if scopes are excessive.

Can I use this security review protocol on skills sourced from ClawHub and GitHub?

Yes, you can use this security review protocol on skills sourced from ClawHub, GitHub, or other origins. It systematically checks for dangerous code patterns and suspicious activities across various sources to ensure a safer AI environment.

What are the limitations of code inspection for detecting malicious AI skills?

Code inspection for detecting malicious AI skills is limited to identifying specific dangerous code patterns and excessive permission scopes. It relies on systematically checking for known red flags and may not detect novel or obfuscated malware techniques.

When do I need to perform a pre-installation security audit on AI agent skills?

You need to perform a pre-installation security audit on AI agent skills whenever you source new skills from GitHub, ClawHub, or other origins to prevent deploying malicious code and mitigate risks associated with data exfiltration attempts.