agentCLAWHUBUnverified

CMIC Skill Scanner (Linux x64)

使用 auto、native 或 external 引擎审计待安装的 skill 包或归档,并可选启用 LLM 语义分析。

OpenClaw

Rank

62

Safety

84

Downloads

1.5k

Updated

Oct 10, 2026

Version

0.11.1

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 10, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 10, 2026
Adoption signal
1.5K downloadsadoption · observed Oct 10, 2026
Latest release
0.11.1release · observed Jul 27, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner-linux-amd64
  1. Install using `clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner-linux-amd64` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/cyzlmh/cmic-skill-scanner-linux-amd64 before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-linux-amd64/snapshot"

Documentation

CLAWHUB

62,905 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: skillscan-wrapper
description: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档,并可选启用 LLM 语义分析。
license: MIT-0
author: CMIC Skill Scanner
---

# Skill Scan Wrapper

当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时,使用这个 skill。

## ⚠️ Security Notice

This tool scans locally by default and requires user trust in the binary you run. Native LLM review sends a bounded text packet to a user-configured endpoint; external LLM review follows the external scanner's data policy. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).

## Binary Included

| Property | Value |
|----------|-------|
| Location | `assets/bin/skillscan` |
| Version | `v0.11.1` |
| Platform | `Linux x64` |
| SHA-256 | `bb3847f3afca734ef0cf6c061f553602b3df5dad23f726215d25812b74d01bf0` |

**Verify locally before running:**
```bash
sha256sum assets/bin/skillscan
# Compare output with the SHA-256 value above
```

This bundled package includes a pre-compiled binary. You can still build from source if you prefer:

```bash
git clone https://gitee.com/random_player/cmic-skill-scanner.git
cd cmic-skill-scanner && cargo build --release
```


## 前置条件

- 默认 `auto` 模式会优先尝试本地可解析的 external scanner;没有可用 scanner 时回退到内置 native 引擎
- 不安装 external scanner 也可以使用:单二进制会回退到 native
- `--upload-url` 和 `--use-llm` 功能**默认禁用**,仅在用户显式配置时启用

## 信任模型

This is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.

**Your options:**

| Approach | Trust Requirement | Verification |
|----------|------------------|--------------|
| Build from source | None (you control everything) | Manual code review |
| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |

**Default behavior and trust boundaries:**
- CMIC does NOT upload reports unless you configure `--upload-url`
- CMIC does NOT configure an LLM endpoint unless you set `--use-llm`
- `auto` may execute a locally resolved external scanner; use `--engine native` to prevent that
- Does NOT access credentials or SSH configs as scan targets unless they are under the path you explicitly scan

## 工作流程

1. 调用 skillscan:

```bash
skillscan review /path/to/target --format markdown
skillscan review /path/to/skills --output-dir /tmp/skillscan-out
```

2. 阅读输出中的:输入类型、完整度、engine 执行状态、findings

## 网络上传功能 (默认禁用)

**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.

This applies to report upload only. LLM review is a separate, explicit network feature; a resolved external scanner has its own dependency and network behavior.

**What gets sent** (only when you configure `--upload-url`):
- A structured JSON report containing detection findings
- An instance identifier you supply via `--instance-id`
- **No skill source code, credentials, or system configuration is ever transmitted**

## Optional LLM Review

**⚠️ This feature is completely optional and 

_meta.json

{
  "ownerId": "kn7aj9m1ysjv99m3c7zjkj193d822ydj",
  "slug": "cmic-skill-scanner-linux-amd64",
  "version": "0.11.1",
  "publishedAt": 1785134584167
}

INSTALL.md

# Install

## Package Contents

- Binary: `assets/bin/skillscan`
- Skill document: `SKILL.md`
- Build metadata: `assets/build/build-info.json`
- SHA-256: `assets/build/skillscan.sha256`

## Install Steps

1. Unzip the release package.
2. Optionally verify the checksum:

```bash
shasum -a 256 assets/bin/skillscan
cat assets/build/skillscan.sha256
```

3. Run the binary directly:

```bash
./assets/bin/skillscan review /path/to/skill
./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out
```

The default engine is `auto`: it prefers a locally resolved external scanner and falls back to the built-in native engine if the external scanner is unavailable or fails. Use `--engine native` to run only the built-in engine.

4. If you want to require an external scanner bridge:

```bash
./assets/bin/skillscan review /path/to/skill --engine external
```

5. To opt into LLM semantic review, configure a trusted OpenAI-compatible endpoint. `native`, `external`, and `auto` all support `--use-llm`; external scanners must support the Cisco-compatible `--use-llm` contract.

```bash
./assets/bin/skillscan review /path/to/skill --engine native --use-llm \
  --llm-endpoint http://localhost:11434/v1 \
  --llm-model your-model
```

With `native`, this sends a bounded, basically redacted text packet from the target package to that endpoint. If the LLM is unavailable, the native static result still returns and records `engine.fallback_reason`.

For `external`, CMIC adds `--use-llm` and passes the endpoint, model, and optional key through
`SKILL_SCANNER_LLM_BASE_URL`, `SKILL_SCANNER_LLM_MODEL`, and `SKILL_SCANNER_LLM_API_KEY` only to the child
process. The external scanner controls its own data packet and failure handling; `auto` falls back to native if
the external process fails.

6. For batch review in enterprise environments:

```bash
./assets/bin/skillscan review /path/to/skills \
  --output-dir /tmp/skillscan-out \
  --upload-url https://scanner.example.com/api/report \
  --instance-id prod-a1
```

The upload payload contains embedded review details for each skill, including the full scan summary and findings.

## Linux glibc Compatibility

There are two x86_64 Linux builds. Pick the right one **before** downloading:

| Package | Target systems | Requirement |
|---------|---------------|-------------|
| `linux-amd64` | Ubuntu 20.04+, Debian 11+, RHEL 9+, Fedora 31+ | glibc >= 2.30 |
| `bclinux21-amd64` | BCLinux 21/8.2, CentOS 7/8, RHEL 7/8, Amazon Linux 2 | none (static musl) |

Check your glibc version first:

```bash
ldd --version | head -1          # glibc < 2.30  -> use bclinux21-amd64
cat /etc/os-release | grep -i "bclinux\|bigcloud"   # matches -> use bclinux21-amd64
```

If you run `linux-amd64` and see `version 'GLIBC_2.30' not found` (or similar),
your glibc is too old — switch to the `bclinux21-amd64` package, which is
statically linked with musl and does not depend on the system glibc.

## Common Commands

```bash
./assets/bin/skillsca

skill-card.md

## Description:

Audits local skill packages or archives with auto, native, or external scanner engines and can optionally enable LLM semantic review.

This skill is ready for commercial/non-commercial use.

## Publisher:

[cyzlmh](https://clawhub.ai/user/cyzlmh)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and engineers use this skill to run a local security review before installing a skill package, archive, or release bundle. It helps summarize scanner engine status, findings, risk level, and installation guidance.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: The release evidence says the packaged binary and checksum are missing, so the claimed bundled binary should not be trusted without verification.

Mitigation: Confirm the package contains the expected binary and checksum before running it; verify the SHA-256 value or build from source.

Risk: Default auto mode may run a locally resolved external scanner with the current user's permissions.

Mitigation: Use --engine native unless the resolved external scanner and its configuration are trusted.

Risk: Optional LLM review or report upload can send scan data to configured endpoints.

Mitigation: Enable --use-llm or --upload-url only with endpoints you control and whose data-handling behavior is understood.

## Reference(s):

- [CMIC Skill Scanner ClawHub Page](https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner-linux-amd64)
- [CMIC Skill Scanner source repository referenced by package documentation](https://gitee.com/random_player/cmic-skill-scanner.git)

## Skill Output:

**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]

**Output Format:** [Markdown guidance with command examples and optional JSON or Markdown scan reports]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [May write scan reports to a user-specified output directory.]

## Skill Version(s):

0.11.1 (source: server release metadata and assets/build/build-info.json)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.

assets/build/build-info.json

{
  "version": "v0.11.1",
  "target_os": "linux",
  "target_arch": "amd64",
  "binary_name": "skillscan",
  "built_at_unix": 1785134501,
  "checksum": "bb3847f3afca734ef0cf6c061f553602b3df5dad23f726215d25812b74d01bf0"
}
Github ReposUpdated 16h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner-linux-amd64",
      "sourceUrl": "https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner-linux-amd64",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T09:05:35.070Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-linux-amd64/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-linux-amd64/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-10T09:05:35.070Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.5K downloads",
      "href": "https://clawhub.ai/cyzlmh/cmic-skill-scanner-linux-amd64",
      "sourceUrl": "https://clawhub.ai/cyzlmh/cmic-skill-scanner-linux-amd64",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-10T09:05:35.070Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "0.11.1",
      "href": "https://clawhub.ai/cyzlmh/cmic-skill-scanner-linux-amd64",
      "sourceUrl": "https://clawhub.ai/cyzlmh/cmic-skill-scanner-linux-amd64",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-07-27T06:43:04.167Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-linux-amd64/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-linux-amd64/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 0.11.1",
      "description": "- Updated included binary to version v0.11.1 (Linux x64) with new SHA-256 hash. - Refreshed SKILL.md to reflect the new binary version and checksum. - Removed obsolete skill-card.md file. - Minor documentation and build info updates.",
      "href": "https://clawhub.ai/cyzlmh/cmic-skill-scanner-linux-amd64",
      "sourceUrl": "https://clawhub.ai/cyzlmh/cmic-skill-scanner-linux-amd64",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-07-27T06:43:04.167Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 10, 2026.

Sponsored

Ads related to CMIC Skill Scanner (Linux x64) and adjacent AI workflows.