Skill Vetter

SkillDev tools

Use before installing or trusting third-party skills from skillhub, clawhub, GitHub, or other external sources when source trust, permissions, secrets, or command/network risk need review.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Skill Vetter skill

What this skill tells your AI

The instructions your AI receives, as published by qianleigood/crawclaw in skills/skill-vetter/SKILL.md and read by ahel’s review.

Use this skill before installing unknown skills.

Workflow

  1. Check the source:
    • where it came from
    • who maintains it
    • trust signals such as stars, installs, reviews, or update recency
  2. Read all files in the skill.
  3. Classify the permission scope:
    • files read or written
    • commands run
    • network access
  4. Assign a risk level.
  5. Produce a clear install verdict.

Immediate reject signals

  • exfiltration to unknown external services
  • requests for credentials, tokens, or secrets without a clear reason
  • reads of sensitive config or key stores without a narrow purpose
  • obfuscated or encoded code
  • arbitrary eval or exec
  • unexplained package installs
  • broad filesystem writes outside the stated workspace
  • requests for elevated privileges

Output

Report:

  • source
  • files reviewed
  • red flags
  • permission scope
  • risk level
  • verdict

Rules

  • When in doubt, do not install.
  • Human approval is required for high-risk skills.
  • Prefer bundled or audited skills over unknown sources.

Signals

GitHub stars
30
Forks
1
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
skill-vetter-qianleigood
Source
github.com/qianleigood/crawclaw