Is eddygk/skill-vetting safe?
Yes. eddygk/skill-vetting is safe to install. Oathe's behavioral security audit gave the skill-vetting skill by eddygk a trust score of 92/100 with 3 findings, none critical or high.
https://github.com/openclaw/skills/tree/main/skills/eddygk/skill-vetting
Is eddygk/skill-vetting safe to install?
This is a legitimate security tool designed to help users vet other ClawHub skills for security risks. While it contains content that addresses AI systems and includes executable code, both are for legitimate security purposes. The skill provides educational warnings about prompt injection and includes a Python scanner for detecting malicious patterns.
What security issues were found in eddygk/skill-vetting?
Category Scores
Findings (3)
MEDIUM AI-addressing content detected -15 ▶
The skill contains extensive text addressing AI systems, reviewers, and agents. However, this appears to be legitimate educational content warning about prompt injection techniques rather than malicious social engineering. The content actually instructs the AI to be MORE cautious about prompt injection attacks.
LOW Executable Python code present -10 ▶
The skill includes a Python script (scan.py) that performs security scanning operations. The code appears legitimate and is designed for static analysis of other skills rather than arbitrary code execution.
INFO Honeypot file access during installation -5 ▶
System monitoring detected access to sensitive honeypot files (.env, SSH keys, AWS credentials) during the installation process. However, this appears to be from normal system authentication processes rather than skill-initiated access.
Should I install eddygk/skill-vetting?
Oathe's verdict for eddygk/skill-vetting is SAFE with a trust score of 92/100. Recommendation: Install.