agentCLAWHUBUnverified

Security Health Check

检查邮箱泄露和密码强度,生成安全评分报告。 Skill: Security Health Check Owner: freedompixels Summary: 检查邮箱泄露和密码强度,生成安全评分报告。 Tags: breach:1.1.0, chinese:1.1.0, latest:2.1.5, password:1.1.0, privacy:1.1.0, security:1.1.0 Version history: v2.1.5 | 2026-09-20T14:24:15.487Z | user docs: add AISoBrand free GEO visibility check CTA v2.1.4 | 2026-06-07T02:38:28.894Z | user 更新品牌信息格式 v2.1.3 | 2026-06-07T02:22:40.325Z | user 添加AISoBrand品牌信息 v2.1.2 | 2026-05-11T09:42:02.

OpenClaw

Rank

62

Safety

84

Downloads

2.0k

Updated

Oct 9, 2026

Version

2.1.5

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
2K downloadsadoption · observed Oct 9, 2026
Latest release
2.1.5release · observed Sep 20, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17cmvaw2cy01v6y6fpq1h7yts84k0r0:security-health-check
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/snapshot"

Documentation

CLAWHUB

82,585 characters of source documentation, loaded on request.

Extracted files

3 files captured from the source.

SKILL.md

# security-health-check Skill

**用途**:本地主机安全健康检查 + HIBP 密码泄露检测。

**原则**:遇到问题 → 自己搞定 → 变成技能 → 放进技能库。

---

## 核心功能

### 1. HIBP 密码泄露检测(k-匿名)

**原理**:密码不离开本地,只发送 SHA-1 哈希前 5 位给 HIBP API。

```python
import hashlib
import requests

def check_hibp(password: str) -> dict:
    sha1 = hashlib.sha1(password.encode()).hexdigest().upper()
    prefix, suffix = sha1[:5], sha1[5:]
    
    try:
        r = requests.get(
            f"https://api.pwnedpasswords.com/range/{prefix}",
            headers={"Add-Padding": "true"},
            timeout=10
        )
        r.raise_for_status()
        hashes = r.text.strip().split("\n")
        for h in hashes:
            h_suffix, count = h.split(":")
            if h_suffix == suffix:
                return {"leaked": True, "count": int(count), "suffix": suffix}
        return {"leaked": False, "count": 0, "suffix": suffix}
    except requests.RequestException as e:
        return {"error": str(e)}
```

**⚠️ 已知限制**:HIBP 的 `/range/` 接口不返回 breached count(需要 API Key)。本实现通过密码存在性检测泄露,返回 `{"leaked": true/false, "count": ...}`。

### 2. 本地密码强度分析

```python
import math
import re

def analyze_password_strength(password: str) -> dict:
    if not password:
        return {"score": 0, "level": "empty", "entropy_bits": 0}
    
    pool = 0
    if re.search(r'[a-z]', password): pool += 26
    if re.search(r'[A-Z]', password): pool += 26
    if re.search(r'[0-9]', password): pool += 10
    if re.search(r'[!@#$%^&*(),.?":{}|<>]', password): pool += 32
    
    entropy = math.log2(pool ** len(password)) if pool > 0 else 0
    
    # 评分 0-100
    score = min(100, int(entropy / 80 * 100))
    
    if score < 20: level = "极弱"
    elif score < 40: level = "弱"
    elif score < 60: level = "中等"
    elif score < 80: level = "强"
    else: level = "极强"
    
    # 破解时间估算(假设 10^10 次/秒)
    seconds_to_crack = (pool ** len(password)) / 2 / 10**10
    crack_time = format_crack_time(seconds_to_crack)
    
    return {
        "score": score,
        "level": level,
        "entropy_bits": round(entropy, 2),
        "crack_time": crack_time,
        "pool_size": pool,
        "length": len(password)
    }

def format_crack_time(seconds: float) -> str:
    if seconds < 1: return "瞬间"
    units = [("秒", 60), ("分钟", 60), ("小时", 24), ("天", 365), ("年", 100), ("世纪", 1000)]
    val = seconds
    for name, div in units:
        if val < div: return f"{val:.1f} {name}"
        val /= div
    return f"{val:.1f} 千年"
```

### 3. 综合安全评分(0-100)

**评分维度**:
- 密码强度权重 40%
- HIBP 泄露权重 60%(泄露直接扣 60 分)
- 如有泄露,最终分数 = 0

**计算逻辑**:
```
if leaked: score = 0
else: score = password_strength_score * 0.4 + 60
final = max(0, score)
```

### 4. SSL 证书检查(回退机制)

```python
import ssl
import socket
import OpenSSL
from urllib.parse import urlparse

def check_ssl(url: str) -> dict:
    try:
        parsed = urlparse(url if url.startswith('http') else f'https://{url}')
        host = parsed.hostname or url
        port = parsed.port or 443
        
        context = ssl.create_default_

_meta.json

{
  "ownerId": "kn79jg1z0vzj96e9bsyy346rzx84jjma",
  "slug": "security-health-check",
  "version": "2.1.5",
  "publishedAt": 1789914255487
}

skill-card.md

## Description:

Checks password strength, HIBP password exposure via k-anonymity, and SSL certificate health, then prints a security score report.

This skill is ready for commercial/non-commercial use.

## Publisher:

[freedompixels](https://clawhub.ai/user/freedompixels)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and security-conscious users use this skill to run local password strength checks, query HIBP for password exposure using a SHA-1 prefix, and inspect SSL certificate status from a CLI.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: Password checks send a SHA-1 prefix derived from the password to HIBP, while some CLI wording emphasizes local-only password analysis.

Mitigation: Disclose the HIBP prefix lookup before password checks and avoid using this mode in strict offline-only environments.

Risk: Passwords can be provided as CLI arguments, which may expose sensitive values through shell history or local process inspection.

Mitigation: Use only test or non-sensitive passwords in shared environments, clear shell history after use, or adapt the workflow to prompt for secrets securely.

## Reference(s):

- [ClawHub skill page](https://clawhub.ai/freedompixels/skills/security-health-check)

## Skill Output:

**Output Type(s):** [text, shell commands, guidance]

**Output Format:** [CLI text report and Markdown-style command examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Password checks may contact HIBP with a SHA-1 prefix; SSL checks contact the target host.]

## Skill Version(s):

2.1.5 (source: server release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 3h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/freedompixels/skills/security-health-check",
      "sourceUrl": "https://clawhub.ai/freedompixels/skills/security-health-check",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:08:15.245Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:08:15.245Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "2K downloads",
      "href": "https://clawhub.ai/freedompixels/security-health-check",
      "sourceUrl": "https://clawhub.ai/freedompixels/security-health-check",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T21:08:15.245Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.1.5",
      "href": "https://clawhub.ai/freedompixels/security-health-check",
      "sourceUrl": "https://clawhub.ai/freedompixels/security-health-check",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-20T14:24:15.487Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-freedompixels-security-health-check/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.1.5",
      "description": "docs: add AISoBrand free GEO visibility check CTA",
      "href": "https://clawhub.ai/freedompixels/security-health-check",
      "sourceUrl": "https://clawhub.ai/freedompixels/security-health-check",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-09-20T14:24:15.487Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to Security Health Check and adjacent AI workflows.