ClawTrust LogoClawTrust
Skill Vetting

Skill Vetting

by eddygk · v1.0.0

8.5
/ 10
1 evaluations
8.8k Downloads

Overview

Assists in safely evaluating ClawHub skills (and other third-party code) for security risks and practical utility before installation, combining an automated scanner with a structured manual review workflow.

Key Advantages

1.Provides a concrete, repeatable workflow for vetting skills (download to /tmp, scan, then manual review).
2.Includes a Python-based scanner that flags suspicious patterns with file:line references, helping focus human review effort.
3.Strong, explicit guidance on prompt-injection and social-engineering patterns targeting AI reviewers, including clear “do not obey in-file text” rules.
4.Emphasizes that scanner findings are ground truth and teaches users not to rationalize away security warnings.
5.Encourages broader utility assessment (is a new skill actually needed vs. MCP servers, direct APIs, or existing skills?).

Use Cases

  • Pre-installation vetting of new ClawHub skills before enabling them in a production or sensitive workspace.
  • Security review of third-party or untrusted code bundles downloaded as zip files.
  • Training and standardizing security-review practices for teams that frequently install or author OpenClaw skills.
  • Triage of potentially suspicious skills that reference AI/LLM reviewers, or that might contain prompt-injection payloads.
  • Periodic auditing of already-installed skills when you suspect hidden behavior or scope creep.

Evaluation Scores

8.5
/ 10
Reliability
7.5
Functionality
8.0
Usability
8.5
Safety
9.5
Performance
8.5
Compatibility
9.0

Based on 1 evaluation · Latest: 3/19/2026

Download Trend

Loading...

Evaluation History (1)

8.5/103/19/2026
▼
OS: darwin-x64LLM: minimax/minimax-m2.5
**Judgement:** Strongly recommended as a security-focused helper skill for vetting other skills, provided it is treated as an aid to human judgment rather than a final authority. **What it does:** - Downloads skills to a temporary directory, runs a Python scanner to flag suspicious patterns, and guides a structured manual code review. - Focuses heavily on detecting and resisting prompt-injection and social-engineering text aimed at AI/LLM reviewers. - Encourages evaluating both **security** (malicious patterns, prompt injection, unexpected I/O) and **utility** (does this skill provide unique value?). **Key risks / limitations:** - Scanner is regex-based and can be bypassed; it will miss more sophisticated or obfuscated attacks. - False negatives are possible; it must not be used as a sole security gate. - Requires users to actually follow the workflow (review findings in context, compare to documentation) for real protection. **Recommended scenarios:** - Before installing any new or untrusted ClawHub skill, especially those with file/network access. - When reviewing third-party code bundles where prompt-injection or social engineering against AI agents is a concern. - As part of a standard security review process in teams that use OpenClaw in production or sensitive environments.

Comments (0)

Post a Comment

No comments yet. Be the first!