← 返回 Skills 市场
nidhov01

Skill Vetter

作者 nidhov01 · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ✓ 安全检测通过
408
总下载
0
收藏
1
当前安装
1
版本数
在 OpenClaw 中安装
/install nidhov01-skill-vetter
功能描述
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
安全使用建议
This skill is a coherent, conservative vetting checklist and safe as an instruction-only helper. Before using it, ensure the agent has only the minimum permissions needed to fetch and inspect candidate skill repositories (network access and read access to the skill package). Remember: vetting a skill via these checks does not sandbox or prevent a vetted skill from later performing malicious actions at runtime — for higher-risk skills manually review code, prefer running them in isolated sandboxes, verify releases/tags on authoritative repos, and require human approval for any skill that requests credentials or system access.
功能分析
Type: OpenClaw Skill Name: nidhov01-skill-vetter Version: 1.0.0 The 'skill-vetter' bundle is a security-oriented tool designed to provide a vetting protocol for AI agents to evaluate other skills before installation. The SKILL.md file contains instructions, checklists, and template reports focused on identifying red flags such as data exfiltration, unauthorized credential access, and obfuscated code, with no evidence of malicious intent or harmful commands.
能力评估
Purpose & Capability
Name/description claim to vet skills; SKILL.md only contains guidance and commands to fetch and inspect skill repos (e.g., GitHub API curl examples). It does not request unrelated credentials, binaries, or installs — this is proportionate for a vetting tool.
Instruction Scope
Instructions require reading all files of the target skill and optionally making network calls to GitHub (via curl examples). That is appropriate for vetting, but it assumes the agent has permission to fetch remote repos and to read the skill package being evaluated. The instructions do not tell the agent to read unrelated host secrets itself; they only flag those paths as items to check in target skills.
Install Mechanism
No install spec and no code files — instruction-only. This minimizes installation risk because nothing is written to disk by the skill itself.
Credentials
The skill declares no required environment variables, credentials, or config paths. The checklist mentions sensitive paths as red flags for target skills, but does not request access to them for itself.
Persistence & Privilege
always is false and default autonomy is unchanged. The skill does not request persistent/system-wide changes or elevated privileges.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install nidhov01-skill-vetter
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /nidhov01-skill-vetter 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Fork - 2026.3.16
元数据
Slug nidhov01-skill-vetter
版本 1.0.0
许可证 MIT-0
累计安装 1
当前安装数 1
历史版本数 1
常见问题

Skill Vetter 是什么?

Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 408 次。

如何安装 Skill Vetter?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install nidhov01-skill-vetter」即可一键安装,无需额外配置。

Skill Vetter 是免费的吗?

是的,Skill Vetter 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Skill Vetter 支持哪些平台?

Skill Vetter 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Skill Vetter?

由 nidhov01(@nidhov01)开发并维护,当前版本 v1.0.0。

💬 留言讨论