← 返回 Skills 市场
73
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install skill-checker-jane
功能描述
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
安全使用建议
This skill is an instruction-only vetting checklist and appears internally consistent and low-risk. Before relying on it: 1) recognize it expects the agent to fetch and read repo files (GitHub network access); confirm you’re comfortable allowing those reads in your environment; 2) treat its output as an aid, not a replacement for human review—it flags patterns but cannot guarantee absence of hidden behavior; and 3) if you use the quick commands, ensure the agent’s network permissions and credentials for GitHub (if any) are scoped appropriately. Install only if you accept outbound repo reads and the agent’s autonomy to run the described checks.
功能分析
Type: OpenClaw Skill
Name: skill-checker-jane
Version: 1.0.0
The skill bundle 'skill-checker-jane' (skill-vetter) is a security utility designed to provide a structured vetting protocol for AI agents to evaluate other skills. The instructions in SKILL.md promote security best practices, such as checking for data exfiltration, unauthorized credential access, and obfuscated code. The included shell commands are limited to querying the official GitHub API for repository metadata, which is consistent with the tool's stated purpose of verifying skill sources.
能力评估
Purpose & Capability
Name and description (skill vetting) match the content of SKILL.md: it's a checklist and actionable commands for reviewing skills. It requests no credentials, binaries, installs, or config paths—proportionate for a vetting tool.
Instruction Scope
SKILL.md instructs the agent to read all files in a candidate skill and to run network queries (GitHub API / raw content) when evaluating GitHub-hosted skills. This is coherent for vetting, but implies the agent will access remote repos and potentially arbitrary repository files — ensure network access and repository read access are acceptable in your environment and that the agent won’t automatically exfiltrate reviewed content.
Install Mechanism
No install spec and no code files — lowest-risk model for disk persistence. Nothing will be downloaded or executed by an installer as part of this skill package.
Credentials
The skill declares no required environment variables or credentials, which is appropriate. However the vetting steps assume outbound network access (to api.github.com and raw.githubusercontent.com) and the ability to read repository files; those are operational permissions rather than secret credentials and should be allowed only if acceptable to you.
Persistence & Privilege
always is false and the skill does not request persistent system changes or modify other skills. Model invocation is allowed (default) which is normal for skills of this nature.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install skill-checker-jane - 安装完成后,直接呼叫该 Skill 的名称或使用
/skill-checker-jane触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of skill-vetter, a security-first protocol for vetting AI agent skills.
- Provides a detailed vetting checklist covering source, code review, permission scope, and risk classification.
- Includes a list of red flags to watch for in skill code, with clear reject criteria.
- Outlines a standardized reporting format for vetting outcomes.
- Supplies quick commands for evaluating skills hosted on GitHub.
- Establishes a trust hierarchy and reaffirms best security practices.
- Designed to be used before installing any external skill.
元数据
常见问题
Skill Vetter 1.0.0 是什么?
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 73 次。
如何安装 Skill Vetter 1.0.0?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install skill-checker-jane」即可一键安装,无需额外配置。
Skill Vetter 1.0.0 是免费的吗?
是的,Skill Vetter 1.0.0 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Skill Vetter 1.0.0 支持哪些平台?
Skill Vetter 1.0.0 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Skill Vetter 1.0.0?
由 janeaaaa(@janeaaaa)开发并维护,当前版本 v1.0.0。
推荐 Skills