{"_id":"clawvet","_rev":"33-1769b03755ff02886e18f9883be1479f","name":"clawvet","dist-tags":{"latest":"0.13.2"},"versions":{"0.1.0":{"name":"clawvet","version":"0.1.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.1.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"4af1f680b4074b5a59f39ae0f06c5818721ea2c9","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.1.0.tgz","fileCount":6,"integrity":"sha512-F346FRxeHFZNDFAITcwvWsnBGlz0dKVMxwYrUxYCcDqaK6lvtGGE+okJzGTrejIMgzmzQB2LEZwkSFGHcUK6AA==","signatures":[{"sig":"MEYCIQDs2CHzJAxEcXk9tiYGdnFlFAxVFfuK0Tj7JzKhXHS+nAIhAJQ8bRJd7oFaV7m/soqH7VDAU4ccs6odxFmjw31c6v8/","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":74871},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"cc17a05fec726d6ae5eb40f2fd85de94989974a1","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.1.0_1772523764447_0.19939487212986196","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"clawvet","version":"0.2.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.2.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"3f042e587c43355f67e8c4e1ba0b984259433deb","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.2.0.tgz","fileCount":6,"integrity":"sha512-L2yo3E+d3zH9aqC0WqToyjQenfCSjm2BONRUc2zwTKwnLG1+IGv77h5NOvYnkKGX8y4l0maz5CQMgPlHRjvRqw==","signatures":[{"sig":"MEQCIAndKceByGvtVbvDg4+mLp+CQwodacZnnkdSmQJTZgagAiBj2TVwf9noHo2i0Kb/79Iaqr/Ypu46IGYBvEExwrg1rA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":104454},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"82ed042b0d0fc6823ef50511bfbd667e1dc7cd7f","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.2.0_1772528027846_0.22363369056478266","host":"s3://npm-registry-packages-npm-production"}},"0.2.2":{"name":"clawvet","version":"0.2.2","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.2.2","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"4e7c3cf4bdb63c03cf7ca43fa91af9ac37640ce3","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.2.2.tgz","fileCount":6,"integrity":"sha512-0NKbJ36+nN4/WEydFDsYnk1y4xoBZJ0cPUSDQGmqhHjMWGy71EGAnm75B9ZvyDqr+of7+oAsOWVekx9ah/WHOg==","signatures":[{"sig":"MEUCIQDv9Cqg6i/t74+f0SVHgC5dwit9ghBWkMX6E7A6+1TNFQIgLk5tJ8wxLOFxRAGoubqqGtoO6q3y9M+WdjJHE8gGpXs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":104530},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"8cb217e223e498534aadbce21239a749b89c347b","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.2.2_1772691973070_0.6192951179241608","host":"s3://npm-registry-packages-npm-production"}},"0.2.3":{"name":"clawvet","version":"0.2.3","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.2.3","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"e8e6ff2a0e5e471ab64af694f004184a60bd37e8","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.2.3.tgz","fileCount":6,"integrity":"sha512-U65CUwOCr62jLQ1Dkwko+hIl37NbrCF59gWNWHiNkvgtfRvOAjpvtzQdx5jqhTuRdoCr60cVYGVbtf4cLs8cEQ==","signatures":[{"sig":"MEQCICcmk0iNgNoFcJVEjx3kFfAnZIZ5pZ6BE679aJgKWXrFAiBGkT8Ab4uean+FGOSvB3J6vdIU00nnEspQ4g5mrrGGOA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":107196},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"9100efd0f30cca776c9be9439f138e8bca32bc40","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.2.3_1772693934396_0.0056021418748963825","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"clawvet","version":"0.3.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.3.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"37db39df40fe04d3ac4c8cea79b909ef1e48a429","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.3.0.tgz","fileCount":6,"integrity":"sha512-+lO/aCCDxbxjnh6FFMuprrJws3MFBdTSMs2WJDLGz1e4tSO+TTRoU4ASgu86B75uYKcReKWgmo6eRyfCJ8G4PA==","signatures":[{"sig":"MEUCIFFAUgjEOka5nHvsjMGhpCXGuRokFi9u/mN8IbUMwp+jAiEAueOCTF29a1ZywBakrede1wrVbLuzXmsH8NVSmoVEIuY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":119722},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"83734ba59b7d7395d818306d115c11746d5a11a2","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.3.0_1772695587323_0.3989945138220319","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"clawvet","version":"0.4.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.4.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"aaa320d78ae91578757b773ce5fe3f3fa7e7f187","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.4.0.tgz","fileCount":6,"integrity":"sha512-EHUsiTCD/pE/oK7ki5gmJwwolnElpZo6qOkJgqc0O7gpdP//GWRiTj8Zk3K4eqdMXxeU09TQSsbxXGiLhQns9Q==","signatures":[{"sig":"MEYCIQC6MEKDBdUgSFK4X19gUDJqSIW0asMH9vnOVDAhbugWYQIhAOkcOjDwZrCAa38lOjav+OIs8/b4HxSfZR/Dibr4YgsP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":142962},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"3fb944c6f1f5e2f5e03c5f6d761d27df64708841","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.4.0_1772965623183_0.30167991557363916","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"clawvet","version":"0.5.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.5.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"72c326c285ae9c24d7c704c93fd77746ea614da8","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.5.0.tgz","fileCount":6,"integrity":"sha512-ZhyQCLXT63UkTAOeYGtMpdSKnNa3nQJNbCpQCOdmY2X18FNN9K4Ivkt3IT9DavI9yaGFIwmdz6xVPB/9BEjCxw==","signatures":[{"sig":"MEQCIA3shqrv1B2vh410a6ClBxAt9LDlwrnMkbD1kDvRB9utAiBVOeRPd2MdymqyRpOVJBXs3792M0zN/7tM5SvzxkY2WQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":154622},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"046eb31dbc1d589dbf3f871abd2dc55e26bb5e3b","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.5.0_1773443602595_0.4756619124978869","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"name":"clawvet","version":"0.5.1","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.5.1","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"11456cc3feb77b0ef185245229ceb8fae9de7b9a","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.5.1.tgz","fileCount":6,"integrity":"sha512-l7fQGlRZgL3jkZt7ymSpeQVnG/UwUTFcakwmGDT4jT1fqqLccB3jZggHq2LKUIaWBSHiU332gzvONNd2SIDIxg==","signatures":[{"sig":"MEUCIQCBE9RnlDfOhJC8TVho3TETWWZl7v1/Jhh5vjTBa+NLvgIgcuUXbx/W0tNeJSqJdv2TAERjXRGz/Bgo9DRRqn4ZwgY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":154670},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"1d3cbe2f0c97150f6e7542ced397802bf3b37d5a","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.5.1_1773447459852_0.7491316042238247","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"clawvet","version":"0.6.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.6.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"088e22a1fbb1552e782325226a0e15eed9eae770","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.6.0.tgz","fileCount":6,"integrity":"sha512-X1oKEtu/G0UQsjc9aNrKc2Vxsoxkr4LQ+5a6NAUAAEOFnqbIlIXK85kVfcZqXIVKj4xTDCmwtIdH48CwP1ViCQ==","signatures":[{"sig":"MEUCIGCE5t4yuB75WoKR0hGepqt9lw6JkGZEToEJC15zHw6wAiEAlgTVmI3M/TuKbwrVq/8uxXtDVUXhxVeeCBtmkZwI8bg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":165608},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"05ef4193d6c0ad29ab5505731bef59f7c09cdb68","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.6.0_1773481157850_0.5506166944246971","host":"s3://npm-registry-packages-npm-production"}},"0.6.1":{"name":"clawvet","version":"0.6.1","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.6.1","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"48aa821c294d008fe5d71189246095553e2f911a","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.6.1.tgz","fileCount":6,"integrity":"sha512-NKo/Esi8BUWh9LUXHtF42bQNz6/NZZlNwLoIcsvE2DJKoli5uGOLUcmBMrQUPU+kje+nhvYCz7eTRNaTJF7BWg==","signatures":[{"sig":"MEYCIQD0xwCeWAVymb2+RedNlPdscg3wEknX2Rg9qVkdHZdH8QIhAL3LI07+W42sSWjq/EYBYAnOWEUDU4LBAN1MAjwzFKuF","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":165608},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"530970ef05007dd9788f0ab693b799e26640a52a","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.6.1_1773483823043_0.6696897633243906","host":"s3://npm-registry-packages-npm-production"}},"0.6.2":{"name":"clawvet","version":"0.6.2","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.6.2","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"6f910c6740556ab2490774e5f31bb49aec3ce722","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.6.2.tgz","fileCount":6,"integrity":"sha512-os2nDX4RYzSX0Lb15G8BBOv81Sbvo/kWYK27Qi6eKo4UhM1u/E6MdTEewBsDq6rpJ/Ud9MN1YvC3QES7cUl6xg==","signatures":[{"sig":"MEUCID9Bnm3Q2XtO9L5mDh4h/CfTel3rRICTWQL8ctN+N6ahAiEArunIdYz9480WiH+sA9n8eMPbIq6yPx6PDI6XxuIUSxg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":162710},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"ff898a19595b9196b5bb22410542e1f4368ec00a","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.6.2_1773654800104_0.2314950013369148","host":"s3://npm-registry-packages-npm-production"}},"0.6.3":{"name":"clawvet","version":"0.6.3","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.6.3","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"4530a7d6656f902775baf07759cca990fd5eac27","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.6.3.tgz","fileCount":6,"integrity":"sha512-rxFBknDMFs9PVkfSh4KOI5ZmLiWaKTAIa8mQWafn1HRm4Tn8SenGX7ou/3r/UKIhLOPUYYtOf40yKvCzysezhg==","signatures":[{"sig":"MEQCIGZ5WtRN3QZ+WPVnpi1VDwgIweKU6i4GwEXWvVpJ2D4JAiAdhjEnGF9yX/txSvi2OB+dL2JN5ahG+/vvjY6tkIjHcg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":162710},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"ff898a19595b9196b5bb22410542e1f4368ec00a","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.6.0","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.6.3_1773654911206_0.672848894117259","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"clawvet","version":"0.7.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.7.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"b69b648e236755543619aa89041360c96ab58054","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.7.0.tgz","fileCount":6,"integrity":"sha512-EGhC14oGtTRo1RwaKYkQNJbiFNQYjW5/URY2CSh0tCDjvwadMV3vNFfwsGInEqEgJan7LOsoBZqDJKc7uxfPdA==","signatures":[{"sig":"MEUCIQCnpx0DrSuK7LJBqRkmkBdAH36IZa1ixadTyJky8/4sRwIgB4G1P2CeEg4zvOskO9RdDMN1Xn5gpzbLMHrgo9mHiFM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":167058},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"49e94060b053a21f093f958d08db306c625175e5","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.7.0_1777881483744_0.1619757315946888","host":"s3://npm-registry-packages-npm-production"}},"0.7.1":{"name":"clawvet","version":"0.7.1","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.7.1","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"98dff75bf8eee9946ab66d0a63219bcb2ad8ecc3","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.7.1.tgz","fileCount":6,"integrity":"sha512-HAL3fEON1E6P47sm116myKl0wjTzC2GnxRKjxbX/bU33Ec7sn7OJhe14Klq26XWSzSlUEQTW04QxXB2RbVCb3A==","signatures":[{"sig":"MEUCIQDVtP0iCffFP23tKKxB2UU0gdTE0GmnFrW66XI/tyfQ2wIgPp/SoMloQR2aIryAasgGonr+mX59fcf7BOKX1lbRqMg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":168509},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"64b0458377b93ee95ab609ea5e4410deb53879b8","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.7.1_1778223453347_0.9653715388466859","host":"s3://npm-registry-packages-npm-production"}},"0.7.2":{"name":"clawvet","version":"0.7.2","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.7.2","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"1be42fbab8cd3133b42c4e9a2b20bdce9bb7f7cd","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.7.2.tgz","fileCount":6,"integrity":"sha512-Y+zXoll+pHsgmdA3isjk/Pu7/d0dTkzZ5HEkBe3m26LbDUyVLuAZ64fsD61LxAbxnD1X/XqGeh5hIK7F2atuzQ==","signatures":[{"sig":"MEUCIQDiNufFrkrZnry8zoYTdv4WQAW+//KTLxge3rRHUBFtCwIgHtnOd7poEVbQYhB73qVXWCZhLgczv055WarowmeH+Z4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":175299},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"ebd50aeab0973ed6a4e8a4d0cfd341240c9d7205","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.7.2_1783904566202_0.2536832132121136","host":"s3://npm-registry-packages-npm-production"}},"0.7.3":{"name":"clawvet","version":"0.7.3","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.7.3","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"01d595321e19c4c6fa75de98dbdb7ac91b4a3868","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.7.3.tgz","fileCount":6,"integrity":"sha512-jEnVwdlQY53G0VRR6IPWD+rk9daF3uiRRM1nJ87+zfG27/EcZ6vIDCOpAw2Jljt7jRrPb8h2ljUD5Wta3gTPKQ==","signatures":[{"sig":"MEQCIFxqHzef8WH+rT/6QePHwRLwCnLeTVClYepOgjizhyH/AiACZxvq/IlgMD6Oq5bnU5CSP4uAz6xn65FN+H/0ZkS1Yw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":178146},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"413fb47932f427ab50ae392dd446eae77aedaeab","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.7.3_1783906827519_0.10666786311396015","host":"s3://npm-registry-packages-npm-production"}},"0.7.4":{"name":"clawvet","version":"0.7.4","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.7.4","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"6f917e2906d76aceb5f37d3983d2a03c17a36948","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.7.4.tgz","fileCount":6,"integrity":"sha512-40nx3jTz6011QA3fvYiShz+NGUVILiT1AsFJylTDdO3IrPz5qpmcwqYaIGRsh2qlXNrnWN4X1NBMjdbh7E16UA==","signatures":[{"sig":"MEQCIGCm6cY6faWQ7BREKFI6CTXbCYwcK8jIto3Wop8VWfKTAiASJ7rKoId5zyv0nhYq0hHVJLPRv5kDsNNxSVrgy6NWug==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":178146},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"6607106c96256f4d85b918487126970a60de3dbb","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.7.4_1783907570378_0.7840391672270133","host":"s3://npm-registry-packages-npm-production"}},"0.7.5":{"name":"clawvet","version":"0.7.5","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.7.5","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"915491e83745c193fc00e6bc95132326e37401ec","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.7.5.tgz","fileCount":6,"integrity":"sha512-XFV1ZPWHE5L2KpIv5QsE+3JxQnl+zm3siU1KxkMaBlh03TDrf15ScGZekuytBOKTMMD675dU8/53XOEmClaX8g==","signatures":[{"sig":"MEUCIH+GoG3+954+9xYtHJpYRVIjpp9FyE7mQSDjPoySHne9AiEAsG8c0hEJwEgrC+uHimi4Jn2jv9ThDBqVjEnyEgd3xKE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":178252},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"bffbe9d257247aaacdd0a98ba3003714d5eb108f","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.7.5_1783907910562_0.8444554234534325","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"clawvet","version":"0.8.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.8.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"d6242dd0593b1d8da3166ba070ec87d59e5080e4","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.8.0.tgz","fileCount":6,"integrity":"sha512-n+fTxikHr/Yo5GTBossprDXGwpGaEpwOaMut91etz3G2ZFthbcsx0yVirNPXZbLQaZUi9IC6X7JmP8fIlszKdw==","signatures":[{"sig":"MEYCIQC8BcE1/g3TGEl26IHAxApXjScd9UWsTltIbdQ27e8JIAIhAMpYzRMarKz2OmZKsV4aRpjEStByIlRmcYUQsKPvyh/p","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":181611},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"a2f7506ffea2a45edbb6de291f05947e475627a1","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"11.6.2","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"25.0.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.8.0_1784037597007_0.4080721327159924","host":"s3://npm-registry-packages-npm-production"}},"0.8.1":{"name":"clawvet","version":"0.8.1","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.8.1","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"13539f76f722f07e49625e87104c808a17af0975","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.8.1.tgz","fileCount":6,"integrity":"sha512-TDbk2RNDq/dtEmr0QGkeObs7fEmgHmx5gkj6lqIgMtYjYTcrZPY4xB0Ry3fn7I4jjZ19xTh43YmaxEVEDwC7YQ==","signatures":[{"sig":"MEQCIFUSBqTEtK+05VE4XA5nKCg3Kpj6yuS/M9AiH9WEQnjNAiBmbfwGVQYqbBZSkH7JYzHuxDaJqzQzHZF+7XLRpdE/iw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":187257},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"a224ce3aca839c57254a98c128214816594b2825","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.4.0","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.14.0","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.8.1_1784928952730_0.8628501631310901","host":"s3://npm-registry-packages-npm-production"}},"0.8.2":{"name":"clawvet","version":"0.8.2","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.8.2","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"fb1a5ac8a577cf42846896a724c6c4e3d02cbb17","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.8.2.tgz","fileCount":6,"integrity":"sha512-8mPNftbgC0uansKs37TQpXv6j6L9mc/HT02fj46VXFxryl2OKIYZK9MTOd0eLu5KLoj8xwldS/Gfpv0eORKJug==","signatures":[{"sig":"MEYCIQDTgZwBnSh/j5L4CbyjyXqtoxk6ozuYFMJIdJ3I5c+djAIhAI2ciKDKodvn6m8DkzsGZsaCEkj+UHAfot835G3zC7gE","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":184225},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"2355861268f2c6f0b0bab52e54636fdb58c474eb","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.8.2_1784969229673_0.6537757039509691","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"clawvet","version":"0.9.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.9.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"f353556213adb2caf42cd3b58f4c415fcaf2f422","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.9.0.tgz","fileCount":6,"integrity":"sha512-ZusiOwycU4wFCJ2LsIgbSYavbNzfGIjaJxYREcGENVBhBQel/AFEX6PLahMX1ofdOTFnqGLNhQJ/2cGgPzoMsQ==","signatures":[{"sig":"MEYCIQD59OD02Rw9vHpSaXHz0mlWX2wZxHf3rYmnOCbo0dsw7QIhALDhMTo3skQfq1/PRuqz+AQYqIplWQHVO5c9VFo/i6UZ","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":185952},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"b4a905137e9597db47ad9ec0b66bafd8898dec50","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.9.0_1785137968265_0.3844128801564459","host":"s3://npm-registry-packages-npm-production"}},"0.10.0":{"name":"clawvet","version":"0.10.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.10.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"5e8d8d103c9813f1acdc7c08ed25155b8d3c7922","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.10.0.tgz","fileCount":6,"integrity":"sha512-hLeskvZIl48xc/CpjSWoL056dYNgcy7F97GaFeXuful38xSZ3Xj8XwGUUkOWlCEcby0bE+33pGjb3hNgjRozNg==","signatures":[{"sig":"MEUCIB//zClQcnRdkYDwUPvCWF6sA6dIuSSafQcuPJsuNNB/AiEAvzwrBeixSiigAIfsAUkZHYfDtUBj86IQ3y0Od3uaW/g=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":192499},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"efc8489ae57af75300bafa415c4a4d34a9c2c28f","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.10.0_1787219793529_0.908618919847552","host":"s3://npm-registry-packages-npm-production"}},"0.11.0":{"name":"clawvet","version":"0.11.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.11.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"0562797ddd5970003e8562153eb242dbcedaa906","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.11.0.tgz","fileCount":6,"integrity":"sha512-lUMjFv0FV9A2u9QvXonTpfQglwkGy/euElGb+nWoD07Pi0uj/Ljrq6huREA5Wig+rEVOwuGuqw1hB8zQAl60Bw==","signatures":[{"sig":"MEYCIQC2QFjza2We4ZxuLhNXNXgK1QJ59q6AtBkbPHB2qD2iswIhAIe62QZft0djQ0LHyYOfTncRuJRid04Z4M7DjIIRk21E","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":201120},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"782143972941f0be6c29818b905a2eca16487d99","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.11.0_1787246788992_0.6038052239489864","host":"s3://npm-registry-packages-npm-production"}},"0.11.1":{"name":"clawvet","version":"0.11.1","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.11.1","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"fe1a9b1868599ab3ac089ca6775f1087383359cc","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.11.1.tgz","fileCount":6,"integrity":"sha512-H8Nqw6rrCt10IpB/9nPG+5JQmOuiCpT7cpn4YsU0a4TM3eBCYEMvj4OX49psaWOqEZydqrmhQ3gtCdGqPxoDHw==","signatures":[{"sig":"MEYCIQDxhP5pvOkVCG5N2xEaMUSgrZOLJpJ7OYH07u4JZsOF7wIhANk+JbFso19Ux1GXFCkj/2FhupUO253o0SWTntCgNlHj","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.11.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":205682},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"4027778a3ccc61a49680a2830e5db2bac9bcfb87","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.11.1_1787251148608_0.6991736099884758","host":"s3://npm-registry-packages-npm-production"}},"0.12.0":{"name":"clawvet","version":"0.12.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.12.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"607eaed300fdcd17089adf860508581c08bf9411","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.12.0.tgz","fileCount":6,"integrity":"sha512-sfavhTPAXqsqPRPdveIIawBUIbxgv4GKpm8aTeaYcX7jDz0tmpCCP/gJYRSwpgnQGF/1ivUr/KhyIWfqDGtw8g==","signatures":[{"sig":"MEYCIQCDZUm78DquU4IL0wu0n0ZM9o/zZ3tCBYNsfYc959QyfwIhAMEtVPdj4ycBUmx6/s89YYbQWfZ3NJRc1QDDMY1rSilx","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.12.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":219709},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"184248124c759e38bb3044d1f8bd95b7b923bf45","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.12.0_1788333516240_0.9727307997099941","host":"s3://npm-registry-packages-npm-production"}},"0.12.1":{"name":"clawvet","version":"0.12.1","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.12.1","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"38e5b4fba483bc1ac7542990daf7d20edb6849fa","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.12.1.tgz","fileCount":6,"integrity":"sha512-eBsj3oxPWurTzoUo+nxaCpm4OSv/D5V60t7YwY6dYLMr3rU/HmSLIUMKHnPa/jn4HsWDbr6TiQ6xQbaRapOtfA==","signatures":[{"sig":"MEQCIFIH8jMlS4pHAB5XXWpprMofLMce0d+QvDhlWInAuh7FAiA/4zzaay9k4TTj3winGfHKXzKFLRvV2r6NkURhGUkBbQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.12.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":220887},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"b3dd75b121dd461be2742e6d42d9bc606f298e15","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.12.1_1788334287563_0.19668361353725872","host":"s3://npm-registry-packages-npm-production"}},"0.12.2":{"name":"clawvet","version":"0.12.2","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.12.2","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"f279a8b1415fe5fbc139de76507dad44809f171e","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.12.2.tgz","fileCount":6,"integrity":"sha512-CGeGt+wLJLumatnZRsvX4NGN+t0urpsS8M6YjyANsebQE4JTHMDrcES1FaG+jSCIPkAmOE5hje7fumFRW1c4Yg==","signatures":[{"sig":"MEUCIH7SGUC0hgzg42NfqnTvZSS520L61mr3ozmwsszVdlZsAiEAqS8D9zenJOvjnTbVgcnlKgIAMXqskNrgbeQqAFzOsuM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.12.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":226562},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"afbedba75ffae798ed97dec8f105fa289e14262f","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.12.2_1788335115506_0.44118042350326725","host":"s3://npm-registry-packages-npm-production"}},"0.12.3":{"name":"clawvet","version":"0.12.3","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.12.3","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"d3f7ee34b9e455ff8cf4e42fd3e91038eb21b48a","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.12.3.tgz","fileCount":6,"integrity":"sha512-V19tAiwksJwFhq/0mHCATfqHttz5d1kN9gp8OaTFbsx8DTLZ37TtadnnM9VKHXhJtas06OvOkI0BREOGYh9rHg==","signatures":[{"sig":"MEYCIQDeNfNhJVKPaALTZNt0ZhlN8w90cXM3vAArADGE/7BrOgIhAOH8Lho3sRclwxMQNCffebOU8gKMWWgjKmAmwkK6/6oX","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.12.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":226562},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"fd4bb18fc4a74e5c6b856791a4ef8f1ce2d06067","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.12.3_1788335550843_0.7049137670377186","host":"s3://npm-registry-packages-npm-production"}},"0.12.4":{"name":"clawvet","version":"0.12.4","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.12.4","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"c9c728a7ec8e16baf9961d328e1cdb4d32da0170","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.12.4.tgz","fileCount":6,"integrity":"sha512-BeHom03juAk/J1IRWIt6rK7OpbkgpqB0DPTVFTeFAtS1mz4OsYFS0EYu4XXLlXAEl8rhtqJ95kB5lS78p/N4kQ==","signatures":[{"sig":"MEYCIQDzkhvKYNwS+V7vddJxneCNzA9Yf04l177nLHJWysUs5QIhAJxW+HTGc2y0iasu0vfNcebSnaTRs6XxCnUBDHHXNIXA","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.12.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":229694},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"ea71ae2d4b33e9cb6bb33d7acf520a5187157c4f","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.8","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.2","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.12.4_1788342234180_0.6408186650174121","host":"s3://npm-registry-packages-npm-production"}},"0.13.0":{"name":"clawvet","version":"0.13.0","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.13.0","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"840e060f71a03b2d269ba4eeadf7d2db8c438ce3","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.13.0.tgz","fileCount":6,"integrity":"sha512-gG6phgo2/1E3XCkTrYhkIS+rt++ds22/AVz0Ixsw1ig54ahUHcoApfQaFeU1fK6GVc3CM560aBQQ2vCG1Ux0nA==","signatures":[{"sig":"MEUCIB69s/L28gkJB/3/tDVHbP8syIgTqEStT8PE9GZhriJLAiEA1E5rKoBX7xeXCOZd4yzWli/gnMloJz27kVhVXugNE/E=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIARE9rvlFbsY2v/OwyWN08cAr8vbUKPJMmdOTmwf9rq6AiBEBSJqgLlJrQjXqcH2j53owAsSqW8IX8IGLGw2GFzxsQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.13.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":411885},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"f915ee9c1efe3f4a2d6024a280372eba0affa809","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.9","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.3","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.13.0_1791358718310_0.06478219308910904","host":"s3://npm-registry-packages-npm-production"}},"0.13.1":{"name":"clawvet","version":"0.13.1","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"license":"MIT","_id":"clawvet@0.13.1","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"homepage":"https://github.com/MohibShaikh/clawvet#readme","bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"bin":{"clawvet":"dist/index.js"},"dist":{"shasum":"8ba317156eab13c641051c1a09a2276f2ce35c84","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.13.1.tgz","fileCount":6,"integrity":"sha512-ZnoExSzhrKsn1Ye12jZWzxkqbdHOnLmLAH5TXAKFq5/8d2w4sAMbDtVzquwDrxmLLFZ7y1i67i1Mtq1PY1og/w==","signatures":[{"sig":"MEYCIQDW4f8ebvu20qUBAzTz/bczFthjnQchkWFlzwCb8f4s7QIhAPR4KcSbLsVdU0vO5NguNtRZRcbxAVvlCKOMqEvKiN6b","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCID70B1cCiqfna/uEdaIDgbDNGkyQyW5Scdo+HjGyv2v7AiAX2I9AGWgzJHASy290ZyBFab+R3ScWMZ2evztqHmfqrg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.13.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":412343},"main":"dist/index.js","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"be31dedff39271b0d9659ba202c0822eaa439044","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.9","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"_nodeVersion":"22.23.3","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"tmp":"tmp/clawvet_0.13.1_1791368365762_0.7885312094165322","host":"s3://npm-registry-packages-npm-production"}},"0.13.2":{"_id":"clawvet@0.13.2","bin":{"clawvet":"dist/index.js"},"bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"dist":{"shasum":"0f5067ef1524df7d0b538d12fa9d3916379c9353","tarball":"https://registry.npmjs.org/clawvet/-/clawvet-0.13.2.tgz","fileCount":6,"integrity":"sha512-HrVaS2HZR7nxMEQKcUCjyvGjZUqz2RA1bQ0v3CbJePaJ1xKRBRCdWpA5/0xi8Ot1bA/e7d5zMTMCtCSEk65qBg==","signatures":[{"sig":"MEUCIF2O4q06D5QOmxzarIvs+mc+kxU6XXFG5rn4b+9UGNNMAiEA+Iuf0xJS+oa4SFYvPDWCSQWYMUkqyPnV1Vl+SYFjHo0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQC4BcOIJbXVN/2CVF/xVMz/B1uPLSJhOmqDPBFQgtgEPgIgBV1F3ZnXVObXE7JwsyNob8MmnXAF56I4J30bEzMC2Xg="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/clawvet@0.13.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":412530},"main":"dist/index.js","name":"clawvet","type":"module","types":"dist/index.d.ts","engines":{"node":">=22.0.0"},"gitHead":"b824c53220b52c8d556aa800c0ed8f27bc9f636f","license":"MIT","scripts":{"dev":"tsx src/index.ts","build":"tsup","prepublishOnly":"npm run build"},"version":"0.13.2","_npmUser":{"name":"mohibzz","email":"mohibuddin9@gmail.com"},"homepage":"https://github.com/MohibShaikh/clawvet#readme","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"_npmVersion":"10.9.9","description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","directories":{},"maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"_nodeVersion":"22.23.3","dependencies":{"yaml":"^2.8.3","chalk":"^5.4.0","commander":"^13.0.0","fastest-levenshtein":"^1.0.16"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.19.0","tsup":"^8.5.1","typescript":"^5.7.0","@types/node":"^22.0.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/clawvet_0.13.2_1791390672022_0.4494286964058878"}}},"time":{"created":"2026-03-03T07:42:44.320Z","modified":"2026-10-07T16:31:12.667Z","0.1.0":"2026-03-03T07:42:44.620Z","0.2.0":"2026-03-03T08:53:48.068Z","0.2.2":"2026-03-05T06:26:13.259Z","0.2.3":"2026-03-05T06:58:54.539Z","0.3.0":"2026-03-05T07:26:27.535Z","0.4.0":"2026-03-08T10:27:03.394Z","0.5.0":"2026-03-13T23:13:22.760Z","0.5.1":"2026-03-14T00:17:40.008Z","0.6.0":"2026-03-14T09:39:17.992Z","0.6.1":"2026-03-14T10:23:43.220Z","0.6.2":"2026-03-16T09:53:20.258Z","0.6.3":"2026-03-16T09:55:11.338Z","0.7.0":"2026-05-04T07:58:03.923Z","0.7.1":"2026-05-08T06:57:33.523Z","0.7.2":"2026-07-13T01:02:46.391Z","0.7.3":"2026-07-13T01:40:27.653Z","0.7.4":"2026-07-13T01:52:50.536Z","0.7.5":"2026-07-13T01:58:30.699Z","0.8.0":"2026-07-14T13:59:57.130Z","0.8.1":"2026-07-24T21:35:52.896Z","0.8.2":"2026-07-25T08:47:09.839Z","0.9.0":"2026-07-27T07:39:28.395Z","0.10.0":"2026-08-20T09:56:33.681Z","0.11.0":"2026-08-20T17:26:29.157Z","0.11.1":"2026-08-20T18:39:08.736Z","0.12.0":"2026-09-02T07:18:36.371Z","0.12.1":"2026-09-02T07:31:27.702Z","0.12.2":"2026-09-02T07:45:15.650Z","0.12.3":"2026-09-02T07:52:30.997Z","0.12.4":"2026-09-02T09:43:54.333Z","0.13.0":"2026-10-07T07:38:38.419Z","0.13.1":"2026-10-07T10:19:25.861Z","0.13.2":"2026-10-07T16:31:12.159Z"},"bugs":{"url":"https://github.com/MohibShaikh/clawvet/issues"},"license":"MIT","homepage":"https://github.com/MohibShaikh/clawvet#readme","keywords":["openclaw","clawvet","security","scanner","skill","supply-chain","prompt-injection","ai-agent","malware","cli"],"repository":{"url":"git+https://github.com/MohibShaikh/clawvet.git","type":"git"},"description":"Skill vetting & supply chain security for OpenClaw. Scans SKILL.md files for prompt injection, credential theft, RCE, typosquatting, and social engineering.","maintainers":[{"name":"mohibzz","email":"mohibuddin9@gmail.com"}],"readme":"# clawvet\n\n**Skill vetting & supply chain security for OpenClaw.**\n\nClawVet scans OpenClaw `SKILL.md` files for prompt injection, credential theft, remote code execution, typosquatting, and social engineering — before they reach your agent.\n\n## Demo\n\n![ClawVet CLI demo](https://raw.githubusercontent.com/MohibShaikh/clawvet/master/clawvet-demo.gif)\n\n## Install\n\n```bash\nnpm install -g clawvet\n```\n\nReleases are published with npm provenance, so the tarball is signed and\ntraceable to the GitHub Actions run that built it. `npm view clawvet\ndist.attestations` shows the attestation without installing anything, and\n`npm audit signatures` verifies it inside a project install (it rejects global\nones). Pin `clawvet@<version>` if you want a fixed release rather than current\ndetection rules.\n\n## Usage\n\n### Scan a local skill\n\n```bash\nclawvet scan ./my-skill/\nclawvet scan ./my-skill/SKILL.md\n```\n\n### JSON output (for CI/CD)\n\n```bash\nclawvet scan ./my-skill/ --format json\n```\n\n### Fail on severity threshold\n\n```bash\nclawvet scan ./my-skill/ --fail-on high\n# exits 1 if any high or critical findings\n```\n\n### Fetch and scan from ClawHub\n\n```bash\nclawvet scan weather-forecast --remote\n```\n\n### Audit all installed skills\n\n```bash\nclawvet audit\n```\n\n### Watch for new skill installs\n\n```bash\nclawvet watch --threshold 50\n```\n\n## Install-time enforcement\n\n`clawvet gate` is an OpenClaw [`security.installPolicy`](https://docs.openclaw.ai/tools/skills-config)\nhook. OpenClaw stages the source, writes the install metadata to the command's\nstdin, and reads back one JSON verdict before the install completes. It runs\nwhether or not an agent remembers to scan anything.\n\nInstall `clawvet` globally once, then print a ready-to-paste config with the\npaths already resolved:\n\n```bash\nnpm install -g clawvet\nclawvet gate --print-config\n```\n\nDo not use `npx clawvet gate --print-config`. The config embeds resolved paths,\nand npx resolves them into its cache (`~/.npm/_npx/...`). A cache cleanup later\nremoves the policy executable the config points at. Every install then fails\nclosed, and the only fix is pasting the config again. A global install is\npermanent.\n\nUse the printed block rather than writing the paths by hand. OpenClaw requires\nthe policy command and any interpreter script argument to be regular files, and\nrejects symlinks. `npm i -g clawvet` installs a symlink into `bin/`, so\npointing `installPolicy` at `which clawvet` fails. `--print-config` resolves\nthrough to the real `dist/index.js` and invokes it via an absolute `node` path.\nThe block is valid as-is; it includes the `source: \"exec\"` field OpenClaw's\nconfig validation requires.\n\nCheck `npm view clawvet dist.attestations` before installing; `npm audit\nsignatures` does not accept global installs.\n\nThe gate is persistent. Once the block is in your config it scans every skill\ninstall from then on and fails closed on anything it cannot parse. Scope it\nwith `--block-at <score>` when printing the config; the default is 76, so\nscores block only at F, while clear evidence of hidden or fetched code blocks\nat any score. To remove it, set `security.installPolicy.enabled` to false or\ndelete the block, then `npm uninstall -g clawvet`.\n\nOpenClaw also refuses to execute the policy through insecure paths. The\nresolved `node` and `dist/index.js`, and every directory above them, must not\nbe writable by group or others. A stock npm global install is `0755`, so\npasting the block and running an install can fail with `... exec.command\nparent directory permissions are too open`. The fix is to remove the\ngroup/other-write bits on the directories the block names, typically the node\ninstallation and the npm global prefix. A launcher-managed node such as\n`~/.local/share/fnm/node-versions/<version>` is commonly installed\ngroup-writable and needs the same treatment. The failure message names the\noffending directory; start there.\n\n`targets` is `[\"skill\"]`. ClawVet reads `SKILL.md` and the files it references,\nso a plugin that ships no `SKILL.md` is allowed through, and `\"plugin\"` is not\nlisted because it would claim a protection that does not exist yet. A skill\ntarget that stages no `SKILL.md` is blocked: with the policy aimed only at\nskills, an instruction-less \"skill\" is either not a skill or installs its\npayload without saying so.\n\nVerdicts map onto ClawVet's own vocabulary:\n\n| Risk score | Grade | ClawVet | installPolicy |\n|-----------|-------|---------|---------------|\n| 0-25 | A / B | `approve` | `allow` |\n| 26-75 | C / D | `warn` | `warn` |\n| 76-100 | F | `block` | `block` |\n\nA `warn` is not a pass. OpenClaw's docs are explicit: \"A warning stops the\ninstall before commit.\" An interactive CLI install asks the operator to confirm,\nand Gateway-backed or automatic installs stay blocked without an\noperator-confirmation path.\n\n**Choosing a threshold.** `--block-at <score>` moves the blocking line, default\n76. ClawHavoc campaign fixtures score 28-36, below that line, but their\ninstructions to download and run code block under either profile regardless of\nscore: all 49 corpus500 ClawHavoc skills that ship their referenced files block.\n`--block-at 26` also denies anything scoring 26 or more, at the cost of denying\ndual-use skills. A finding marked `disqualifying`, such as a known-malicious C2 address,\nblocks at any threshold.\n\nStatic passes only. Runtime depends on the referenced files; the host enforces\nthe configured timeout and fails closed if inspection takes too long. The semantic pass is never reached, so\nno API key and no network round trip.\n\nAnything the host cannot parse fails closed. A malformed payload, an unreadable\nstaged path, or a scanner error returns `block` with a reason rather than a bare\nnon-zero exit, so the operator sees why the install stopped.\n\n### Inspection coverage\n\nLocal folder and direct `SKILL.md` scans follow recognized file references\nrecursively through the skill directory, including references inside helpers.\nJSON reports include `coverage.complete`, inspected file/line ranges, and any\ncoverage issues. Reference discovery is static: it recognizes filenames,\nconcrete interpreter/script paths, and local Markdown links. Skill-root\nplaceholders such as `{baseDir}/`, `$SKILL_DIR/` and `<skill-dir>/` resolve to\nthe bundle, so the script behind them is inspected. Recognized dynamic\ncommands, globs, computed imports, runtime evaluation, remote modules, and\ndownload-to-execution paths make coverage incomplete; the profile below decides\nwhich of those block. These checks run inside referenced helpers too. Literal inline commands are inspected up to four nested\nlevels; exceeding that limit also fails coverage.\n\nMarkdown prose is not shell. Outside a fence, only inline code and lines that\nstart with a recognized command (optionally after \"Run\") are read as commands,\nso a price table or a bullet that mentions `python3` is not. Fences are read by\nlanguage: shell fences as shell, text and data fences like prose, and\nunlabelled and other code fences with both the shell and the code-loading\nrules, since a fence label cannot hide a command. A line that starts with `|`\nis a table row, not a command.\n\n**Profiles.** Coverage gaps are not equal, so a profile decides what each one\ndoes. The default profile blocks on clear evidence that code is hidden, swapped,\nor fetched and run: a downloaded file that is later run or followed,\ninstructions to download and run code, `curl | sh` from any host other than an\nexact trusted vendor installer such as `astral.sh` or `sh.rustup.rs`, a path\noutside the skill, encoded or remote execution, process calls and `eval` on\nunresolved arguments, and anything ClawVet could not read. Other gaps, such as\na package fetched at install time with `npx`, a computed command, an unused\ndownload, or a document linked from outside the skill, pass quietly and stay\nlisted in `coverage`. The gate then asks the operator only when the scan's own\nfindings are borderline. A gate that asks too often gets switched off or\napproved without reading, which protects no one.\n\n`--strict` on `gate` and `scan` blocks every gap in inspection and asks about\nthe reviewable ones. Registry installs such as `pip install requests` are not a\ngap under either profile; the dependency checker scores the package names.\nMeasurements of both profiles are in `benchmarks/gate-eval/`.\n\nThe gate stays offline: it never executes a skill or downloads its dependencies.\nTo resolve these coverage failures, stage fixed dependencies locally, use\nliteral paths, and remove their runtime downloads. A clean staged file does not\nclear a runtime replacement downloaded over it. Ordinary API data requests do\nnot fail coverage solely because they use the network.\n\nDownloads made with `curl`, `wget`, PowerShell, or Python `urlretrieve` are\nchecked for code destinations and later use as instructions. A script that\nreads from the network (`requests`, `httpx`, `urlopen`, `fetch`, `axios`) and\nwrites a literal filename counts as downloading it; running or importing that\nfile afterwards blocks. A bundled harmless\ncopy does not clear a runtime replacement, including an instruction file such as\n`notes.txt`. Reading or summarizing ordinary API data remains supported. These\nare bounded syntax checks, not general data-flow analysis of arbitrary programs.\n\nKnown gap: prose that tells the agent to fetch a page and do what it says, with\nno file in between, is not detected. Telling that apart from ordinary setup\ndocs (\"follow the instructions at <url> to get an API key\") takes reading for\nmeaning, which the offline CLI does not do. Review a skill's external links\nyourself before installing it.\n\n`scan --remote` fetches only the manifest, reports incomplete coverage, and exits\n1 even if that manifest has no findings. Responses are bounded to 256 KiB.\nStage the full skill locally before relying on a gate verdict.\n\nA gap that blocks under the active profile returns `block` regardless of\n`--block-at`, and cannot produce `allow`. Local scans then return `status:\n\"failed\"`, `recommendation: \"block\"`, and exit 1; any reported score describes\nonly the inspected content. Audits return a nonzero exit status for them, and\nbadges are not generated. `review` and `approve` always use the strict profile:\napproving a skill should mean all of it was inspected.\n\nLimits are 256 KiB per inspected file (including the manifest), 2 MiB of inspected\ncontent, 1,024 directory entries, and 16 nested directory levels. Symlinks and\nspecial files anywhere in the inventory make coverage incomplete; referenced\nbinary or invalid UTF-8 files do too. These conservative limits can reject\nlegitimate skills; resolve the reported issue and rescan instead of lowering the\nrisk threshold. Keep the staged directory unchanged while inspection runs.\n\nComplete coverage means the recognized references were inspected within these\nlimits. These checks recognize supported syntax, not every possible program:\nobfuscated or unsupported runtime loading can still evade static detection.\nComplete coverage does not certify a skill as safe. `watch` reports file changes; install enforcement requires\n`gate`.\n\n\n## What it detects\n\nClawVet runs a 6-pass analysis on every skill:\n\n| Pass | What it checks |\n|------|---------------|\n| **Skill Parser** | Extracts YAML frontmatter, code blocks, URLs, IPs, domains |\n| **Static Analysis** | 57 regex patterns: RCE, reverse shells, credential theft, obfuscation, DNS exfil, privilege escalation |\n| **Metadata Validator** | Undeclared binaries, env vars, missing descriptions, invalid semver |\n| **Dependency Checker** | `npx -y` auto-install, global `npm install`, risky packages |\n| **Typosquat Detector** | Levenshtein distance against popular skills, suspicious naming patterns |\n| **Semantic Analysis** | AI-powered detection of social engineering & prompt injection (optional) |\n\n## Risk Scoring\n\n| Score | Grade | Action |\n|-------|-------|--------|\n| 0-10 | A | Approve |\n| 11-25 | B | Approve |\n| 26-50 | C | Warn |\n| 51-75 | D | Warn |\n| 76-100 | F | Block |\n\n## CI/CD Integration\n\n```yaml\n# GitHub Actions example. Add clawvet as a dev dependency first\n# (`npm install --save-dev clawvet`) so the lockfile pins the exact\n# version; --no-install then refuses to fetch anything else.\n- name: Vet skill\n  run: npx --no-install clawvet scan ./my-skill --format json --fail-on high\n```\n\n## License\n\nMIT\n","readmeFilename":"README.md"}