| Pre-install decision |
|---|
| 79 · Evidence missing | 82 · Manual review | |
|---|
| Source needs review, High execution risk, Claude | Clear source, High execution risk, Claude | Clear source, High execution risk, Claude |
|---|
| unexpected code execution, identity privilege abuse, data exfiltration | data exfiltration, human approval gap | unexpected code execution, identity privilege abuse, data exfiltration |
|---|
| missing repo, missing license, broad permissions | missing license, network without allowlist, no human approval | missing license, broad permissions, shell without guardrails |
|---|
| Permission review, Network, Secrets, Command | Network, Command | Permission review, Network, Secrets, Command |
|---|
| 69% | 63% | |
|---|
| Source & provenance |
|---|
| Source needs review | nextlevelbuilder/ui-ux-pro-max-skill/tree/main/.claude/skills/ui-ux-pro-max | openclaw/skills |
|---|
| Knowledge & RAG | Design & Content | Knowledge & RAG |
|---|
|
|---|
| Risk & permission signals |
|---|
| needs credentials, network access, runs shell, writes files | No explicit signals | needs credentials, writes files |
|---|
| review skill metadata before install, check required credentials in skill docs | registry access, remote metadata pull, runtime dependencies may be required | verify source provenance before install |
|---|
| Install & compatibility |
|---|
| Codex, OpenClaw, Claude, Cursor, Universal | Claude, Codex, Cursor, Universal | Claude, OpenClaw |
|---|
| instruction-only | registry-install | script-backed |
|---|
|
|---|
| Community |
|---|
| 108 | | 0 |
|---|