---
name: clawhub-skill-vetting
version: 1.0.0
category: 生活与工具
trigger_words:
tags:
platform: coze
source: DeepseekModel
source_url: https://deepseekmodel.com/skill?id=hugomrtz-skill-vetting-clawhub-skill-md
---

name clawhub-skill-vetting description Vet ClawHub skills before installation. Use when the user asks about evaluating, auditing, or safely installing OpenClaw/ClawHub skills, or when a skill’s trustworthiness is in question. ClawHub Skill Vetting Overview Apply a strict, security‑first vetting workflow before installing any ClawHub skill. Prioritize code review, permission scope, domain listing, and risk scoring. Workflow Source check — author reputation, stars/downloads, last update, reviews. Code review (MANDATORY) — scan all files for exfiltration, secrets access, eval/exec , obfuscation. Permission scope — files, commands, network; confirm minimal scope. Recent activity — detect suspicious bursts. Community check — Discord/GitHub Discussions. Install safely — sandbox + inspect permissions. Reference Use references/vetting-guide.md for the full checklist, commands, red flags, confidence scoring, and report template. Output expectations Produce the SKILL VETTING REPORT format. Provide a go/no‑go recommendation with reasons. If unclear, recommend sandbox install only or reject . Call out any red flags explicitly. Include a confidence score and threshold.