Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Initial release of Skill Vetter: a security-first vetting guide for AI agent skills. - Outlines a step-by-step protocol to check source, code, permissions, and risk level before installing any skill. - Lists clear red flags to reject (e.g., credential access, suspicious network calls, use of eval/exec). - Provides a detailed vetting report template for consistent reviews. - Includes practical commands for vetting GitHub-hosted skills. - Highlights trust hierarchy and best practices for skill installation security.