security-skill beginner active

Openclaw Skill Vetter

Unknown skill authors can inject anything into your agent. Vet first.

What breaks without openclaw skill security audit

Prompt injections missed. Bad SKILL.md practices installed unchecked. LLM-only analysis without manual review.

Pre-install security audit of any skill × 375-star security essential ÷ 5–10 minutes ÷ LLM key only = unknown skills vetted before damage.

openclaw skill security audit — what it actually does

01
Audits SKILL.md files for security vulnerabilities before install
02
Detects prompt injection risks and bad practices
03
Runs /vet steipete/trello before installing any third-party skill
04
Produces a risk assessment report with actionable findings
05
Supplements LLM analysis — always follow up with manual review

Security check — openclaw skill security audit

Privacy score: 7/10 — accesses connected platform APIs only. Lock it: review OAuth scopes before install, confirm Linux, macOS; OpenClaw ≥1.0 compatibility.

Quick start — openclaw skill security audit in 5–10 minutes

Setup time: 5–10 minutes

!
You need:
  • OpenClaw core
  • LLM API key

Install the package:

clawhub install skills/openclaw-skill-vetter
1
Install skill
2
Run /vet steipete/trello to analyse a skill before installing
3
Receive a risk assessment report
4
Proceed with install or skip based on findings

Troubleshooting openclaw skill security audit

1
1. Vetter uses LLM analysis — not a guarantee of safety, supplement with manual review
2
2. Always vet skills from unknown authors

Compatibility & status

Works with: Linux, macOS; OpenClaw ≥1.0 beginner Last updated: Nov 2025 ★ 375 on GitHub MIT

Official docs →

View on GitHub →

Related — more like openclaw skill security audit

More by skills

Every unvetted skill is an attack surface your agent carries silently. Install before the next unknown skill enters your stack.

Get it on GitHub →