CMIC Skill Scanner
使用 auto、native 或 external 引擎审计待安装的 skill 包或归档,并可选启用 LLM 语义分析。
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
0.11.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.11.1release · observed Jul 27, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner- Install using `clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/cyzlmh/cmic-skill-scanner before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/snapshot"
Documentation
CLAWHUB
58,060 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
--- name: skillscan-wrapper description: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档,并可选启用 LLM 语义分析。 license: MIT-0 author: CMIC Skill Scanner --- # Skill Scan Wrapper 当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时,使用这个 skill。 ## ⚠️ Security Notice This tool scans locally by default and requires user trust in the binary you run. Native LLM review sends a bounded text packet to a user-configured endpoint; external LLM review follows the external scanner's data policy. **Always verify the checksum after downloading**. For maximum security, build from source (recommended). ## Reference Package (No Binary) This package contains only documentation. Pre-built binaries are hosted on **Gitee Releases** (open source, verifiable). **Download from Gitee Releases:** https://gitee.com/random_player/cmic-skill-scanner/releases **Verify checksums before running:** See https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.11.1/SHA256SUMS **Build from source (recommended for maximum security):** ```bash git clone https://gitee.com/random_player/cmic-skill-scanner.git cd cmic-skill-scanner && cargo build --release ``` ## 前置条件 - 默认 `auto` 模式会优先尝试本地可解析的 external scanner;没有可用 scanner 时回退到内置 native 引擎 - 不安装 external scanner 也可以使用:单二进制会回退到 native - `--upload-url` 和 `--use-llm` 功能**默认禁用**,仅在用户显式配置时启用 ## 信任模型 This is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust. **Your options:** | Approach | Trust Requirement | Verification | |----------|------------------|--------------| | Build from source | None (you control everything) | Manual code review | | Bundled/downloaded binary | You trust the release host | SHA-256 checksum | **Default behavior and trust boundaries:** - CMIC does NOT upload reports unless you configure `--upload-url` - CMIC does NOT configure an LLM endpoint unless you set `--use-llm` - `auto` may execute a locally resolved external scanner; use `--engine native` to prevent that - Does NOT access credentials or SSH configs as scan targets unless they are under the path you explicitly scan ## 工作流程 1. 调用 skillscan: ```bash skillscan review /path/to/target --format markdown skillscan review /path/to/skills --output-dir /tmp/skillscan-out ``` 2. 阅读输出中的:输入类型、完整度、engine 执行状态、findings ## 网络上传功能 (默认禁用) **⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`. This applies to report upload only. LLM review is a separate, explicit network feature; a resolved external scanner has its own dependency and network behavior. **What gets sent** (only when you configure `--upload-url`): - A structured JSON report containing detection findings - An instance identifier you supply via `--instance-id` - **No skill source code, credentials, or system configuration is ever transmitted** ## Optional LLM Review **⚠️ This feature is completely optional and disabled by default.
_meta.json
{
"ownerId": "kn7aj9m1ysjv99m3c7zjkj193d822ydj",
"slug": "cmic-skill-scanner",
"version": "0.11.1",
"publishedAt": 1785134566293
}skill-card.md
## Description: Audits local skill packages or archives with auto, native, or external scanner engines and can optionally enable LLM-assisted semantic review. This skill is ready for commercial/non-commercial use. ## Publisher: [cyzlmh](https://clawhub.ai/user/cyzlmh) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineers use this skill before installing local skills, archives, or release bundles to review scanner findings and risk level. It helps inspect target files locally by default, with optional configured report upload or LLM review. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Downloaded binaries require trust in the release host and may not match the reviewed source. Mitigation: Build from source when possible, or verify the published SHA-256 checksum before running a binary. Risk: The default auto engine may execute a locally resolved external scanner with the current user's permissions. Mitigation: Use `--engine native` when you want to prevent external scanner execution. Risk: Optional LLM review or report upload can send scan data to a configured endpoint. Mitigation: Use `--use-llm` and `--upload-url` only with trusted endpoints and scan only directories intended for inspection. ## Reference(s): - [ClawHub Skill Page](https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner) - [Gitee Releases](https://gitee.com/random_player/cmic-skill-scanner/releases) - [Release SHA256SUMS](https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.11.1/SHA256SUMS) - [Gitee Source Repository](https://gitee.com/random_player/cmic-skill-scanner.git) ## Skill Output: **Output Type(s):** [text, markdown, shell commands, guidance] **Output Format:** [Markdown reports with inline shell commands and risk findings] **Output Parameters:** [1D] **Other Properties Related to Output:** [Can write local report files to an output directory; optional upload and LLM review require explicit endpoint configuration.] ## Skill Version(s): 0.11.1 (source: server-resolved release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
agents/openai.yaml
display_name: CMIC Skill Scanner short_description: Audit skill packages for malware and suspicious patterns before installation. default_prompt: Audit this local skill target, output findings and risk level.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner",
"sourceUrl": "https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T08:02:56.004Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T08:02:56.004Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/cyzlmh/cmic-skill-scanner",
"sourceUrl": "https://clawhub.ai/cyzlmh/cmic-skill-scanner",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T08:02:56.004Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.11.1",
"href": "https://clawhub.ai/cyzlmh/cmic-skill-scanner",
"sourceUrl": "https://clawhub.ai/cyzlmh/cmic-skill-scanner",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-27T06:42:46.293Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.11.1",
"description": "- Updated reference checksum filename and links in documentation from v0.11.0 to v0.11.1 for consistency with the new release. - Removed deprecated file: skill-card.md.",
"href": "https://clawhub.ai/cyzlmh/cmic-skill-scanner",
"sourceUrl": "https://clawhub.ai/cyzlmh/cmic-skill-scanner",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-07-27T06:42:46.293Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
