{"product_id":"ai-skill-vetter-secure-code-review-for-clawhub-local-packages","title":"AI Skill Vetter: Secure Code Review for ClawHub \u0026 Local Packages","description":"\u003ch3\u003eAI Skill Vetter: Secure Code Review for ClawHub \u0026amp; Local Packages\u003c\/h3\u003e\n\u003cp\u003eAI Skill Vetter performs security-first reviews of ClawHub or local Skill packages before installation. The skill classifies risks and provides a structured security report, assisting developers in evaluating potential vulnerabilities and ensuring safer installations.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this skill does\u003c\/h3\u003e\n\u003cul\u003e\n    \u003cli\u003eInspects ClawHub slugs or local Skill directories before installation to identify security risks.\u003c\/li\u003e\n    \u003cli\u003eClassifies risks such as suspicious code, broad permissions, credential access, persistence hooks, and risky network behavior.\u003c\/li\u003e\n    \u003cli\u003eGenerates a structured JSON report with details on the reviewed files, detected red flags, permission clues, risk level, verdict, and notes.\u003c\/li\u003e\n    \u003cli\u003eIncludes an optional helper script to facilitate the review process, requiring execution in the Skill package's root directory.\u003c\/li\u003e\n    \u003cli\u003eSupports specific actions like checking Python runtime compatibility and ClawHub CLI availability, fetching and vetting ClawHub skills by slug, and vetting local skill folders.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eWho it is for\u003c\/h3\u003e\n\u003cp\u003eThis skill is designed for developers and teams using AI coding agents such as Claude Code, Cursor, and Codex. It is particularly beneficial for those focused on maintaining secure development environments when integrating new skills or packages.\u003c\/p\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n    \u003cli\u003ePre-installation security vetting of new skills to ensure they meet organizational security standards.\u003c\/li\u003e\n    \u003cli\u003eComparison and evaluation of candidate skills to select the safest options.\u003c\/li\u003e\n    \u003cli\u003eAssessment of locally developed skills for potential security risks prior to deployment.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n    \u003cli\u003eUtilizes tools such as agent-skills, aiapplication, and skill-vetter-runtime for vetting processes.\u003c\/li\u003e\n    \u003cli\u003eThe input for the optional helper script must be a JSON object, and users perform actions using specified commands.\u003c\/li\u003e\n    \u003cli\u003eDesigned for secure and authorized security testing, defensive research, and educational use only.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003c!-- mcpcart:static-blocks:start --\u003e\n\u003chr\u003e\n\u003ch3\u003eSource \u0026amp; Licence\u003c\/h3\u003e\n\u003cp\u003eThis package is built on open-source work published by \u003cstrong\u003euvwt\u003c\/strong\u003e (\u003ca href=\"https:\/\/github.com\/uvwt\/agentdock\" rel=\"nofollow noopener\" target=\"_blank\"\u003euvwt\/agentdock\u003c\/a\u003e) and distributed under \u003cstrong\u003eApache-2.0\u003c\/strong\u003e. The original licence text and copyright notice are included in your download.\u003c\/p\u003e\n\u003cp\u003ePersonal and commercial use, modification and redistribution are permitted under the Apache License 2.0, which also includes an express patent grant. Attribution and any NOTICE file must be retained.\u003c\/p\u003e\n\u003cp\u003eYour purchase covers curation, licence verification, packaging, documentation and instant delivery. It does not grant exclusive rights to the underlying open-source code, which remains available under its original licence.\u003c\/p\u003e\n\u003ch3\u003eDelivery \u0026amp; Support\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eDelivery:\u003c\/strong\u003e instant — a secure download link is emailed to you as soon as payment is confirmed.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eFormat:\u003c\/strong\u003e ZIP archive containing the skill files, documentation and the original licence.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSupport:\u003c\/strong\u003e \u003ca href=\"mailto:support@mcpcart.com\"\u003esupport@mcpcart.com\u003c\/a\u003e — we aim to reply within 2 business days.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eUpdates:\u003c\/strong\u003e updates are included only where stated on this page.\u003c\/li\u003e\n\u003c\/ul\u003e\n\u003ch3\u003eRefunds\u003c\/h3\u003e\n\u003cp\u003eThis is a digital product delivered immediately after purchase. By completing your order you request immediate delivery and acknowledge that, once the download has been accessed, the statutory right to cancel no longer applies to the extent permitted by law. Refund requests are handled in accordance with our published Refund Policy.\u003c\/p\u003e\n\u003cp style=\"font-size:0.85em;color:#666;\"\u003eClaude, Codex, Gemini and Cursor are trademarks of their respective owners. MCP Cart is an independent marketplace and is not affiliated with, endorsed by, or sponsored by any of them. Compatibility references describe interoperability only.\u003c\/p\u003e\n\u003c!-- mcpcart:static-blocks:end --\u003e","brand":"MCP Cart","offers":[{"title":"Default Title","offer_id":52864566853943,"sku":"MCP-UVWT-AGENTDOCK-SKILL-VETTER-RUNTIME","price":20.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0981\/3950\/4951\/files\/Gvvx8RVycK-vvAzvOcyz-_fe7ce415d4dc447aa3f2b0903a6b969f.jpg?v=1787137845","url":"https:\/\/mcpcart.com\/products\/ai-skill-vetter-secure-code-review-for-clawhub-local-packages","provider":"SPF PRO","version":"1.0","type":"link"}