Agent skill

Skill Vetter

by freestylefly in freestylefly/wesight

Security-first skill vetting for AI agents. An agent skill from freestylefly/wesight.

MITAuto-check: warnings

Install Skill Vetter

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add freestylefly/wesight --skill skill-vetter -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install freestylefly/wesight skill-vetter --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/freestylefly/wesight.git skills-src && mkdir -p .claude/skills && cp -r skills-src/SKILLs/skill-vetter .claude/skills/skill-vetter && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
skill-vetter
GitHub stars
944
Used in
4 other repos
Token cost
~982 tokens
SKILL.md length
187 words
Files
2
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

Security-first skill vetting for AI agents. An agent skill from freestylefly/wesight.

  • Works in 4 steps: Source Check → Code Review (MANDATORY) → Permission Scope → …
  • SKILL.md covers When to Use, Vetting Protocol, Output Format and Quick Vet Commands, plus 2 more sections
  • Calls curl and jq; reaches api.github.com and raw.githubusercontent.com

What it does

Skill Vetter is an agent skill from freestylefly/wesight. Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.

Its SKILL.md is about 980 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `_meta.json`).

It works with GitHub. The repository describes itself as: Open-source desktop AI agent workspace with one-click Claude Code, Codex, OpenClaw, Hermes Agent setup and custom LLM model routing. The licence is MIT.

Example prompts

  • “/skill-vetter”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Source Check
  2. Code Review (MANDATORY)
  3. Permission Scope
  4. Risk Classification

What it can do on your machine

Read from SKILL.md and the folder at commit c913cd9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com
    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Skill Vetter loads about 982 tokens when it runs. Until then it costs about 49 tokens; SKILL.md has 187 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~982

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:41
    • Reads ~/.ssh, ~/.aws, ~/.config without clear reason

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from freestylefly/wesight at commit c913cd9, republished under its MIT licence (© freestylefly). 187 words, ~982 tokens.

Download SKILL.mdSave it as .claude/skills/skill-vetter/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
skill-vetter
description
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
version
1.0.0

Skill Vetter 🔒

Security-first vetting protocol for AI agent skills. Never install a skill without vetting it first.

When to Use

  • Before installing any skill from ClawdHub
  • Before running skills from GitHub repos
  • When evaluating skills shared by other agents
  • Anytime you're asked to install unknown code

Vetting Protocol

Step 1: Source Check
Questions to answer:
- [ ] Where did this skill come from?
- [ ] Is the author known/reputable?
- [ ] How many downloads/stars does it have?
- [ ] When was it last updated?
- [ ] Are there reviews from other agents?
Step 2: Code Review (MANDATORY)

Read ALL files in the skill. Check for these RED FLAGS:

🚨 REJECT IMMEDIATELY IF YOU SEE:
─────────────────────────────────────────
• curl/wget to unknown URLs
• Sends data to external servers
• Requests credentials/tokens/API keys
• Reads ~/.ssh, ~/.aws, ~/.config without clear reason
• Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md
• Uses base64 decode on anything
• Uses eval() or exec() with external input
• Modifies system files outside workspace
• Installs packages without listing them
• Network calls to IPs instead of domains
• Obfuscated code (compressed, encoded, minified)
• Requests elevated/sudo permissions
• Accesses browser cookies/sessions
• Touches credential files
─────────────────────────────────────────
Step 3: Permission Scope
Evaluate:
- [ ] What files does it need to read?
- [ ] What files does it need to write?
- [ ] What commands does it run?
- [ ] Does it need network access? To where?
- [ ] Is the scope minimal for its stated purpose?
Step 4: Risk Classification
Risk LevelExamplesAction
🟢 LOWNotes, weather, formattingBasic review, install OK
🟡 MEDIUMFile ops, browser, APIsFull code review required
🔴 HIGHCredentials, trading, systemHuman approval required
⛔ EXTREMESecurity configs, root accessDo NOT install

Output Format

After vetting, produce this report:

SKILL VETTING REPORT
═══════════════════════════════════════
Skill: [name]
Source: [ClawdHub / GitHub / other]
Author: [username]
Version: [version]
───────────────────────────────────────
METRICS:
• Downloads/Stars: [count]
• Last Updated: [date]
• Files Reviewed: [count]
───────────────────────────────────────
RED FLAGS: [None / List them]

PERMISSIONS NEEDED:
• Files: [list or "None"]
• Network: [list or "None"]  
• Commands: [list or "None"]
───────────────────────────────────────
RISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ EXTREME]

VERDICT: [✅ SAFE TO INSTALL / ⚠️ INSTALL WITH CAUTION / ❌ DO NOT INSTALL]

NOTES: [Any observations]
═══════════════════════════════════════

Quick Vet Commands

For GitHub-hosted skills:

bash
# Check repo stats
curl -s "https://api.github.com/repos/OWNER/REPO" | jq '{stars: .stargazers_count, forks: .forks_count, updated: .updated_at}'

# List skill files
curl -s "https://api.github.com/repos/OWNER/REPO/contents/skills/SKILL_NAME" | jq '.[].name'

# Fetch and review SKILL.md
curl -s "https://raw.githubusercontent.com/OWNER/REPO/main/skills/SKILL_NAME/SKILL.md"

Trust Hierarchy

  1. Official OpenClaw skills → Lower scrutiny (still review)
  2. High-star repos (1000+) → Moderate scrutiny
  3. Known authors → Moderate scrutiny
  4. New/unknown sources → Maximum scrutiny
  5. Skills requesting credentials → Human approval always

Remember

  • No skill is worth compromising security
  • When in doubt, don't install
  • Ask your human for high-risk decisions
  • Document what you vet for future reference

Paranoia is a feature. 🔒🦀

© freestylefly, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in SKILLs/skill-vetter of freestylefly/wesight.

  • SKILL.md
  • _meta.json

Open the folder on GitHubat commit c913cd9

Used in 4 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 4 other GitHub owners. This page covers the copy in freestylefly/wesight, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Skill Vetter next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Skill Vetter compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Skill Vetter this skillfreestylefly/wesight9444 repos~982Automated safety check: WarnMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Diagnosing Superpowers Sessionsobra/superpowers297k3 repos~1.7kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow84k4 repos~1.3kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    297k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    84k GitHub starsUsed in 4 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.9k tokensUpdated yesterday
    Research & ScienceAuto-check: notes

More from freestylefly/wesight

All 17 skills in this repo
  • Develop Web Game

    freestylefly/wesight

    A skill your agent uses when Codex is building or iterating on a web game (HTML/JS) and needs a reliable development + testing loop: implement small changes, run a Playwright-based test script with…

    944 GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Web Search

    freestylefly/wesight

    Real-time web search using Playwright-controlled browser. An agent skill from freestylefly/wesight.

    944 GitHub starsUsed in 1 repo~4k tokens
    Auto-check: notes
  • Technology Search

    freestylefly/wesight

    Search tech blogs, developer forums, and IT media (TechCrunch, Hacker News, 36氪, etc.) for software and hardware industry updates with heat ranking and EN↔CN translation.

    944 GitHub stars~3.3k tokensUpdated 8 days ago
    Auto-check passed
  • Content Planner

    freestylefly/wesight

    WeChat Official Account topic planning and content calendar management.

    944 GitHub stars~1.2k tokensUpdated 8 days ago
    Auto-check passed
  • Films Search

    freestylefly/wesight

    Search cloud drives for downloadable film and TV resources (movies, TV series, anime).

    944 GitHub stars~825 tokensUpdated 8 days ago
    Auto-check: notes
  • Create Plan

    freestylefly/wesight

    Create a concise plan. An agent skill from freestylefly/wesight.

    944 GitHub starsUsed in 4 repos~611 tokens
    Auto-check passed

Works with

Questions about Skill Vetter

What does Skill Vetter do?

Security-first skill vetting for AI agents. An agent skill from freestylefly/wesight. Skill Vetter is an agent skill from freestylefly/wesight. Security-first skill vetting for AI agents.

How do I install Skill Vetter in Claude Code?

Run `npx skills add freestylefly/wesight --skill skill-vetter -a claude-code`. Or copy the skill folder (SKILLs/skill-vetter in freestylefly/wesight) into .claude/skills/skill-vetter in your project. Claude Code loads it when a task matches its description.

How do I install Skill Vetter in Codex?

Run `npx skills add freestylefly/wesight --skill skill-vetter -a codex`. Or copy the skill folder (SKILLs/skill-vetter in freestylefly/wesight) into .agents/skills/skill-vetter in your project. Codex loads it when a task matches its description.

Can I use Skill Vetter in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add freestylefly/wesight --skill skill-vetter -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/skill-vetter, .gemini/skills/skill-vetter, .github/skills/skill-vetter and .opencode/skills/skill-vetter in your project.

What does Skill Vetter need to run?

Going by SKILL.md and its folder, Skill Vetter needs the command-line tools its instructions call (curl and jq).

Does Skill Vetter access the network?

SKILL.md names 2 domains. In commands or code: api.github.com and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Skill Vetter safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Skill Vetter use?

Skill Vetter is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Skill Vetter use?

About 982 tokens (SKILL.md is roughly 3.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Skill Vetter?

Skills that share tags, products or a category with Skill Vetter: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 297k stars), Greploop (onyx-dot-app/onyx, 32k stars) and GitHub Deep Research (bytedance/deer-flow, 84k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Skill Vetter?

freestylefly (a GitHub user) maintains it in freestylefly/wesight, which has 944 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 1, 2026.

Source: freestylefly/wesight on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.