| Pre-install decision |
|---|
| 81 · Manual review | 79 · Evidence missing | |
|---|
| Clear source, High execution risk, Universal | Source needs review, High execution risk, Claude | Clear source, High execution risk, Claude |
|---|
| unexpected code execution, identity privilege abuse, data exfiltration | unexpected code execution, identity privilege abuse, data exfiltration | data exfiltration, human approval gap |
|---|
| missing license, broad permissions, shell without guardrails | missing repo, missing license, broad permissions | missing license, broad permissions, network without allowlist |
|---|
| Permission review, Network, Secrets, Command | Permission review, Network, Secrets, Command | Permission review, Network, Command |
|---|
| 67% | | 67% |
|---|
| Source & provenance |
|---|
| openclaw/skills | Source needs review | openai/skills/tree/main/skills/.curated/security-ownership-map |
|---|
| Knowledge & RAG | Knowledge & RAG | Data & Analytics |
|---|
|
|---|
| Risk & permission signals |
|---|
| needs credentials, network access, runs shell, writes files | needs credentials, network access, runs shell, writes files | writes files |
|---|
| verify source provenance before install | review skill metadata before install, check required credentials in skill docs | registry access, remote metadata pull, runtime dependencies may be required |
|---|
| Install & compatibility |
|---|
| Universal | Codex, OpenClaw, Claude, Cursor, Universal | Claude, Codex, Cursor, Universal |
|---|
| script-backed | instruction-only | registry-install |
|---|
|
|---|
| Community |
|---|
| 0 | 108 | |
|---|