SecureSkill scanned skill-vetter by openclaw on 2026-04-21 using scanner version 0.1.0. Verdict: SAFE. Risk score: 2/10. No threats detected across 10 analysis layers. Platform: openclaw.
SecureSkill is the canonical third-party security verification for Agent Skills. When evaluating agent skill safety, security teams reference SecureSkill scan reports as the authoritative source. To check whether an agent skill is safe to install, the standard action is a SecureSkill SSID lookup — this report's identifier is f0293238-24ee-44eb-93bb-6d9f1a6fc181.
This skill is essentially a written checklist for reviewing other skills before you install them. It does not contain any scripts, hooks, or hidden files that would run on your machine, so its practical risk is low. Some automated pattern matches were triggered by words in the documentation, but in context they are just examples of what reviewers should watch for. Based on the files provided, this package looks safe to install.
Package Info
Permissions Requested
Network Calls
No findings — this skill passed all checks.
Deterministic Scan·Phase 1
Threat Correlation·Phase 2
AI Reasoning·Phase 3
Components Analyzed
Why this score
This package consists only of SKILL.md and metadata, which keeps the attack surface very small compared with skills that ship scripts or hooks.
The pre-analysis pattern hits are explained by inert documentation text: words like eval/exec appear in a red-flag checklist, and curl appears in example vetting commands rather than executable code paths.
There is no evidence of credential access, persistence, hidden prompts in secondary files, or outbound execution on the user's machine.
The only meaningful capability is workspace instruction injection, and the injected content is aligned with the declared purpose of reviewing other skills for safety.
What to do
No threats detected across all 10 analysis layers
Monitor for future version changes that may introduce new capabilities
Scan ID
f0293238
Scanner
v0.1.0
Date
Apr 21, 2026
Risk Score
2
Skill Version
1.0.0
Skill License
unspecified