skill-vetter

Inspect and filter AI agent skills from ClawdHub, GitHub, and third-party sources.

52|3|Updated Apr 3, 2026
One-click install
npx skills add https://github.com/Zhow01/SkillAttack --skill skill-vetter-zhow01
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-vetter
Source: https://github.com/Zhow01/SkillAttack/tree/main/data/hot100skills/094_fedrov2025_skill-vetter-1-0-0
Command: npx skills add https://github.com/Zhow01/SkillAttack --skill skill-vetter-zhow01

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Vetting AI skills before installation to prevent hidden threats and misuse.

Core Features & Use Cases

  • Stepwise vetting protocol including source checks, mandatory code review, permission scope evaluation, and risk classification.
  • Generates a structured vetting report that can be shared with teams before deployment.
  • Applies to skills sourced from ClawdHub, GitHub, or other repositories.

Quick Start

Run the vetting protocol on a candidate skill before installation and review the generated report.

Frequently Asked Questions about skill-vetter

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I vet AI skills before installation to prevent security risks?

To vet AI skills before installation, apply a stepwise protocol covering source validation, mandatory code review, permission scope evaluation, and risk classification to generate a structured report for deployment.

What is included in an AI skill risk assessment and code review?

An AI skill risk assessment includes source checks across repositories like ClawdHub and GitHub, frontmatter validation for SKILL.md files, code review, and permission scope evaluation to classify deployment risks.

Can I use this vetting workflow on skills sourced from GitHub and third-party repositories?

Yes, you can use this vetting workflow on AI skills sourced from ClawdHub, GitHub, and other third-party repositories to perform source validation and generate a structured risk assessment report.

How do I check if an AI agent skill requires a mandatory frontmatter SKILL.md format?

To check for mandatory frontmatter, inspect the candidate skill's SKILL.md file to ensure it contains the required name and description fields before proceeding with permission scope evaluation and risk classification.

What's the best way to generate a security compliance report for AI agent skills?

The best way to generate a security compliance report is running a structured vetting protocol that performs source validation, code review, and risk classification, yielding a shareable report for team review.

When should I not use an automated vetting protocol for AI skills?

You should not rely solely on an automated vetting protocol when a candidate skill lacks a valid SKILL.md with mandatory frontmatter, as source validation and permission scope evaluation require structured input.