Before you install a skill from any source, you need to check it for safety. This tool walks you through a step-by-step security review. It looks for red flags like dangerous permissions, suspicious commands, and fake skill names. Use it to protect your system from harmful code.
Security first is the rule here. The checklist covers metadata, permissions, file content, and typosquatting. Each check helps you decide if a skill is safe to install or should be blocked. Manual review gives you full control over the decision.
Anyone who installs skills from ClawHub, GitHub, or other places will find this useful. It is a legacy audit module for conservative operators. Follow the steps and get a clear verdict: safe, warning, danger, or block.
Global
mkdir -p ~/.claude/skills/skill-vetterProject
mkdir -p .claude/skills/skill-vetterSource Repository
Azure Compliancemicrosoft/azure-skills
Audit Azure compliance and Key Vault expiration with azqr scans
Firebase Security Rules Auditorfirebase/agent-skills
Find weak spots in Firestore rules and get clear fixes
Golang Securitysamber/cc-skills-golang
Find and fix security flaws in Go code using expert guidance and automated tools
Clerk Nextjs Patternsclerk/skills
Secure your Next.js app with Clerk middleware, server actions, and caching
Persona It Admingoogleworkspace/cli
Keep your digital workspace safe with IT admin security workflows
Two Factor Authentication Best Practicesbetter-auth/skills
Secure user logins with two-factor authentication using Better Auth
Gws Modelarmor Create Templategoogleworkspace/cli
Create new templates for Google Model Armor to protect AI apps from harmful content
Gws Modelarmor Sanitize Promptgoogleworkspace/cli
Clean user prompts safely with Google Model Armor templates