Security Health Check
检查邮箱泄露和密码强度,生成安全评分报告。 Skill: Security Health Check Owner: freedompixels Summary: 检查邮箱泄露和密码强度,生成安全评分报告。 Tags: breach:1.1.0, chinese:1.1.0, latest:2.1.5, password:1.1.0, privacy:1.1.0, security:1.1.0 Version history: v2.1.5 | 2026-09-20T14:24:15.487Z | user docs: add AISoBrand free GEO visibility check CTA v2.1.4 | 2026-06-07T02:38:28.894Z | user 更新品牌信息格式 v2.1.3 | 2026-06-07T02:22:40.325Z | user 添加AISoBrand品牌信息 v2.1.2 | 2026-05-11T09:42:02.
Rank
62
Safety
84
Downloads
2.0k
Updated
Oct 9, 2026
Version
2.1.5
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2K downloadsadoption · observed Oct 9, 2026
- Latest release
- 2.1.5release · observed Sep 20, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17cmvaw2cy01v6y6fpq1h7yts84k0r0:security-health-check- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/snapshot"
Documentation
CLAWHUB
82,585 characters of source documentation, loaded on request.
Extracted files
3 files captured from the source.
SKILL.md
# security-health-check Skill
**用途**:本地主机安全健康检查 + HIBP 密码泄露检测。
**原则**:遇到问题 → 自己搞定 → 变成技能 → 放进技能库。
---
## 核心功能
### 1. HIBP 密码泄露检测(k-匿名)
**原理**:密码不离开本地,只发送 SHA-1 哈希前 5 位给 HIBP API。
```python
import hashlib
import requests
def check_hibp(password: str) -> dict:
sha1 = hashlib.sha1(password.encode()).hexdigest().upper()
prefix, suffix = sha1[:5], sha1[5:]
try:
r = requests.get(
f"https://api.pwnedpasswords.com/range/{prefix}",
headers={"Add-Padding": "true"},
timeout=10
)
r.raise_for_status()
hashes = r.text.strip().split("\n")
for h in hashes:
h_suffix, count = h.split(":")
if h_suffix == suffix:
return {"leaked": True, "count": int(count), "suffix": suffix}
return {"leaked": False, "count": 0, "suffix": suffix}
except requests.RequestException as e:
return {"error": str(e)}
```
**⚠️ 已知限制**:HIBP 的 `/range/` 接口不返回 breached count(需要 API Key)。本实现通过密码存在性检测泄露,返回 `{"leaked": true/false, "count": ...}`。
### 2. 本地密码强度分析
```python
import math
import re
def analyze_password_strength(password: str) -> dict:
if not password:
return {"score": 0, "level": "empty", "entropy_bits": 0}
pool = 0
if re.search(r'[a-z]', password): pool += 26
if re.search(r'[A-Z]', password): pool += 26
if re.search(r'[0-9]', password): pool += 10
if re.search(r'[!@#$%^&*(),.?":{}|<>]', password): pool += 32
entropy = math.log2(pool ** len(password)) if pool > 0 else 0
# 评分 0-100
score = min(100, int(entropy / 80 * 100))
if score < 20: level = "极弱"
elif score < 40: level = "弱"
elif score < 60: level = "中等"
elif score < 80: level = "强"
else: level = "极强"
# 破解时间估算(假设 10^10 次/秒)
seconds_to_crack = (pool ** len(password)) / 2 / 10**10
crack_time = format_crack_time(seconds_to_crack)
return {
"score": score,
"level": level,
"entropy_bits": round(entropy, 2),
"crack_time": crack_time,
"pool_size": pool,
"length": len(password)
}
def format_crack_time(seconds: float) -> str:
if seconds < 1: return "瞬间"
units = [("秒", 60), ("分钟", 60), ("小时", 24), ("天", 365), ("年", 100), ("世纪", 1000)]
val = seconds
for name, div in units:
if val < div: return f"{val:.1f} {name}"
val /= div
return f"{val:.1f} 千年"
```
### 3. 综合安全评分(0-100)
**评分维度**:
- 密码强度权重 40%
- HIBP 泄露权重 60%(泄露直接扣 60 分)
- 如有泄露,最终分数 = 0
**计算逻辑**:
```
if leaked: score = 0
else: score = password_strength_score * 0.4 + 60
final = max(0, score)
```
### 4. SSL 证书检查(回退机制)
```python
import ssl
import socket
import OpenSSL
from urllib.parse import urlparse
def check_ssl(url: str) -> dict:
try:
parsed = urlparse(url if url.startswith('http') else f'https://{url}')
host = parsed.hostname or url
port = parsed.port or 443
context = ssl.create_default__meta.json
{
"ownerId": "kn79jg1z0vzj96e9bsyy346rzx84jjma",
"slug": "security-health-check",
"version": "2.1.5",
"publishedAt": 1789914255487
}skill-card.md
## Description: Checks password strength, HIBP password exposure via k-anonymity, and SSL certificate health, then prints a security score report. This skill is ready for commercial/non-commercial use. ## Publisher: [freedompixels](https://clawhub.ai/user/freedompixels) ### License/Terms of Use: MIT-0 ## Use Case: Developers and security-conscious users use this skill to run local password strength checks, query HIBP for password exposure using a SHA-1 prefix, and inspect SSL certificate status from a CLI. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Password checks send a SHA-1 prefix derived from the password to HIBP, while some CLI wording emphasizes local-only password analysis. Mitigation: Disclose the HIBP prefix lookup before password checks and avoid using this mode in strict offline-only environments. Risk: Passwords can be provided as CLI arguments, which may expose sensitive values through shell history or local process inspection. Mitigation: Use only test or non-sensitive passwords in shared environments, clear shell history after use, or adapt the workflow to prompt for secrets securely. ## Reference(s): - [ClawHub skill page](https://clawhub.ai/freedompixels/skills/security-health-check) ## Skill Output: **Output Type(s):** [text, shell commands, guidance] **Output Format:** [CLI text report and Markdown-style command examples] **Output Parameters:** [1D] **Other Properties Related to Output:** [Password checks may contact HIBP with a SHA-1 prefix; SSL checks contact the target host.] ## Skill Version(s): 2.1.5 (source: server release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/freedompixels/skills/security-health-check",
"sourceUrl": "https://clawhub.ai/freedompixels/skills/security-health-check",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T21:08:15.245Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T21:08:15.245Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2K downloads",
"href": "https://clawhub.ai/freedompixels/security-health-check",
"sourceUrl": "https://clawhub.ai/freedompixels/security-health-check",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T21:08:15.245Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "2.1.5",
"href": "https://clawhub.ai/freedompixels/security-health-check",
"sourceUrl": "https://clawhub.ai/freedompixels/security-health-check",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-20T14:24:15.487Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 2.1.5",
"description": "docs: add AISoBrand free GEO visibility check CTA",
"href": "https://clawhub.ai/freedompixels/security-health-check",
"sourceUrl": "https://clawhub.ai/freedompixels/security-health-check",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-20T14:24:15.487Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
