clawvet

Code quality and safety linter for OpenClaw skills. Runs 6 analysis passes before you install.

Safety Notice

This listing is imported from skills.sh public index metadata. Review upstream SKILL.md and repository scripts before running.

Copy this and send it to your AI assistant to learn

Install skill "clawvet" with this command: npx skills add mohibshaikh/clawvet/mohibshaikh-clawvet-clawvet

clawvet

Safety linter for OpenClaw skills. Analyzes skills for issues before installation.

Usage

Scan a local skill:

npx clawvet scan ./skill-folder/

JSON output for CI/CD:

npx clawvet scan ./skill-folder/ --format json

Audit all installed skills:

npx clawvet audit

Watch mode — auto-block risky installs:

npx clawvet watch --threshold 50

Submit feedback or get alerts:

npx clawvet feedback

Analysis Passes

  1. Skill Parser — Extracts YAML frontmatter, code blocks, URLs, and domains
  2. Static Analysis — 54 pattern rules across multiple categories
  3. Metadata Validator — Checks for undeclared binaries, env vars, missing descriptions
  4. Dependency Checker — Flags auto-install and global package installs
  5. Typosquat Detector — Levenshtein distance against popular skill names
  6. Semantic Analysis — AI-powered contextual analysis (Pro)

What's New in v0.6

  • Reliable telemetry — Telemetry now awaits before exit, so no data is lost.
  • CI-safe — Opt-in prompt is skipped in non-TTY environments (piped stdin, CI).
  • Less noise — Feedback CTA shows every 5th scan instead of every scan.
  • Trust badges — Generate trust badges for skill READMEs with npx clawvet badge.
  • Ban lists — Block skills by name/author/slug via .clawvetban files.
  • Confidence scores — Each finding shows a confidence percentage. Risk scores are weighted accordingly.
  • Fix suggestions — Every finding includes an actionable remediation in terminal and SARIF output.
  • Content-hash caching — Repeat scans of unchanged files are near-instant.
  • Feedback form — Run npx clawvet feedback to share what you think.

Risk Grades

ScoreGradeAction
0-10ASafe to install
11-25BSafe to install
26-50CReview before installing
51-75DReview carefully
76-100FDo not install

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Coding

openclaw-version-monitor

监控 OpenClaw GitHub 版本更新,获取最新版本发布说明,翻译成中文, 并推送到 Telegram 和 Feishu。用于:(1) 定时检查版本更新 (2) 推送版本更新通知 (3) 生成中文版发布说明

Archived SourceRecently Updated
Coding

ask-claude

Delegate a task to Claude Code CLI and immediately report the result back in chat. Supports persistent sessions with full context memory. Safe execution: no data exfiltration, no external calls, file operations confined to workspace. Use when the user asks to run Claude, delegate a coding task, continue a previous Claude session, or any task benefiting from Claude Code's tools (file editing, code analysis, bash, etc.).

Archived SourceRecently Updated
Coding

ai-dating

This skill enables dating and matchmaking workflows. Use it when a user asks to make friends, find a partner, run matchmaking, or provide dating preferences/profile updates. The skill should execute `dating-cli` commands to complete profile setup, task creation/update, match checking, contact reveal, and review.

Archived SourceRecently Updated
Coding

clawhub-rate-limited-publisher

Queue and publish local skills to ClawHub with a strict 5-per-hour cap using the local clawhub CLI and host scheduler.

Archived SourceRecently Updated