agentCLAWHUBUnverified

skill-security-checker

Skill Security — 安全审计扫描器,审一下这个 skill、装之前帮我查查、这个 skill 安全吗?一键快扫 30 秒出三档裁定(✅干净/⚠️可疑/🚫恶意)+ Top3 风险 + 一句话理由;全量模式覆盖轻量 SAST 污点追踪(Python AST + JS 词法近似,source→sink 证据链降误报)、规则引擎(YAML 规则包热插拔扩展)、社区规则(schema 校验 + 来源记录 + 签名验证)、提示注入 ML 语义检测(ONNX + 正则降级)、系统级行为捕获(eBPF Linux / ETW Windows)、动态沙箱执行扫描、供应链风险分析、OSV.dev 离线数据包(全生态 CVE 覆盖,零密钥)+ 锁文件深度解析(requirements.txt / package-lock.json / poetry.lock,版本区间级精确匹配)、恶意 Skill 指纹库、健康度与合规检查(质量+结构+权限合并)、全局排除配置、CI/CD 集成、JSON/HTML/SARIF 报告生成。 Skill: skill-security-checker Owner: fyniujin Summary: Skill Security — 安全审计扫描器,审一下这个 skill、装之前帮我查查、这个 skill 安全吗?一键快扫 30 秒出三档裁定(✅干净/⚠️可疑/🚫恶意)+ Top3 风险 + 一句话理由;全量模式覆盖轻量 SAST 污点追踪(Python AST + JS 词法近似,source→sink 证据链降误报)、规则引擎(YAML 规则包热插拔扩展)、社区规则(schema 校验 + 来源记录 + 签名验证)、提示注入 ML 语义检测(ONNX + 正则降级)、系统级行为捕获(eBPF Linux / ETW Windows)、动态沙箱执行扫描、供应链风险分析、OSV.dev 离线数据包(全生态 CVE 覆盖,零密钥)+ 锁文件深度解析(requirements.txt / package-lock.js

OpenClaw

Rank

62

Safety

84

Downloads

1.2k

Updated

Oct 11, 2026

Version

3.5.5

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1.2K downloadsadoption · observed Oct 11, 2026
Latest release
3.5.5release · observed Oct 9, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s177r8w7p1d7cpbys9bn33kwhs89d0xw:skill-security-checker
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-fyniujin-skill-security-checker/snapshot"

Documentation

CLAWHUB

155,128 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: skill-security-checker
description: 'Skill Security — 安全审计扫描器,审一下这个 skill、装之前帮我查查、这个 skill 安全吗?一键快扫 30 秒出三档裁定(✅干净/⚠️可疑/🚫恶意)+ Top3 风险 + 一句话理由;全量模式覆盖轻量 SAST 污点追踪(Python AST + JS 词法近似,source→sink 证据链降误报)、规则引擎(YAML 规则包热插拔扩展)、社区规则(schema 校验 + 来源记录 + 签名验证)、提示注入 ML 语义检测(ONNX + 正则降级)、系统级行为捕获(eBPF Linux / ETW Windows)、动态沙箱执行扫描、供应链风险分析、OSV.dev 离线数据包(全生态 CVE 覆盖,零密钥)+ 锁文件深度解析(requirements.txt / package-lock.json / poetry.lock,版本区间级精确匹配)、恶意 Skill 指纹库、健康度与合规检查(质量+结构+权限合并)、全局排除配置、CI/CD 集成、JSON/HTML/SARIF 报告生成。'
version: 3.5.5
---


# Skill Security

> 一键扫描 Skill 安全风险,发布前最后一道安全闸门。

## 快速开始(3 行)

```bash
# 1. 快扫:30 秒出三档裁定(✅干净/⚠️可疑/🚫恶意)+ Top3 + 一句话理由
python D:\skill\skill-security-checker\scripts\audit.py "D:\skill\你的技能名" --quick
# 2. 全量:CI/CD 用 JSON/SARIF,安全工程师看 HTML
python D:\skill\skill-security-checker\scripts\audit.py "D:\skill\你的技能名" --mode full --format sarif -o report.sarif.json
# 3. 口语触发:直接对 WorkBuddy 说「审一下这个 skill」+ 路径,自动快扫
```

## 概述

本工具用于对 **WorkBuddy / ClawHub / SkillHub** 平台上发布的安全技能进行全方位安全合规扫描。它能帮你快速找出代码中的安全漏洞、不安全的依赖项、过度授权的权限配置,并以直观的评分等级和修复建议输出结果。

**适用场景:**

- 发布 Skill 前的安全检查
- 评估第三方 Skill 的安全性
- CI/CD 流水线中的自动化审查
- Skill 质量评估与改进

## 核心功能

### 1. 静态扫描

检测 Skill 文件中的安全漏洞:

| 风险类型 | 检测内容 | 严重度 |
|---------|---------|--------|
| 提示注入 | 越狱指令、"忽略原始指令"、"覆盖系统提示"等文本 | 🔴 严重 |
| 命令注入 | curl/wget 管道执行、反引号替换、$() 中执行 shell | 🔴 严重 |
| SSRF/内网访问 | `127.0.0.1`、`10.x.x.x`、`192.168.x.x` | 🟠 高危 |
| 凭证外泄 | 硬编码 API Key、Token、Password、Bearer Token | 🔴 严重 |
| 路径遍历 | `../`、URL 编码绕过、绝对路径访问 | 🟠 高危 |
| 危险函数 | `eval()`、`exec()`、`os.system()`、`pickle.load()` | 🟡 中等 |

### 2. 依赖漏洞审计

扫描 `requirements.txt`、`package.json`、`Pipfile`、`pyproject.toml` 等依赖文件,与内置的已知 CVE 漏洞库比对。

目前覆盖 **26** 个常见高危依赖的已知漏洞:
`requests`、`urllib3`、`flask`、`django`、`numpy`、`pillow`、`pyyaml`、`jinja2`、`cryptography`、`aiohttp`、`tqdm`、`setuptools`、`node-fetch`、`minimist`、`lodash`、`axios`、`express`、`vue`、`react`、`webpack`、`moment`、`npm`、`tough-cookie`、`word-wrap`、`protobuf`、`eslint`

### 3. 权限审计

检查 `allowed-tools` 声明是否有过度授权:

- 声明了 Bash 但 description 中无对应使用场景 → 🟡 中等告警
- Bash + Write 同时授权 → 🟠 高危告警
- Bash + Exec 同时授权 → 🟠 高危告警
- Bash + Read + Write + Edit 全量授权 → 🟠 高危告警

### 4. 质量评分

检查 SKILL.md 文档的完整性:

| 检查项 | 要求 |
|--------|------|
| 必要字段 | `name`、`description`、`version` |
| 命名规范 | kebab-case(小写字母+数字+连字符) |
| description 长度 | 20-1024 字符 |
| 版本号格式 | 语义化版本 (e.g., `1.0.0`) |
| 硬编码路径 | 检测 `D:\` 等绝对路径 |
| 错误处理 | 文档中需提及异常处理策略 |

### 5. 结构检查

- 文件数量 ≤ 200
- 总大小 ≤ 10MB
- 缺少 README.md 时提醒

### 6. 硬件感知并行(新增)

自动检测当前设备的 CPU 核心数和可用内存,动态调整并发工作线程数(1-8 线程),在扫描速度和系统性能之间取得平衡。

**检测逻辑:**
- CPU 核心数 ÷ 2 = 最大线程数
- 可用内存 < 2GB 时,线程数减半

### 7. 更新检查(新增)

工具运行时会自动检查 GitHub 上的新版本,发现更新时会在结果中提示用户升级。

- ✅ 内置 **24 小时缓存**,避免频繁请求
- ✅ 新增 `--skip-update` 参数可完全关闭此功能
- ✅ 所有网络请求仅获取版本号,不下载任何内容

### 8. `# nosec` 内联排除规则(新增)

如果你确认某行代码是安全的,但触发了误报,可在该行末尾添加 `# nosec` 注释,扫描器将自动跳过该行。

```python
# 这行会被扫描器跳过
os.system('ls')  # nosec
```

### 9. 实时恶意 Skill 库同步(新增)

维护一份已知恶意 Skill 的 SHA256 指纹库(内置 341 条),扫描时对 Skill 目录下每个文件计算 SHA256,命中指纹即报高危,实现

_meta.json

{
  "ownerId": "kn7chdrwbdhaqkwajcyhtfvjx989ddb1",
  "slug": "skill-security-checker",
  "version": "3.5.5",
  "publishedAt": 1791544785736
}

references/scan-patterns.md

# 扫描规则参考文档

本文件详细定义了 Skill Security 使用的检测逻辑。

## 一、提示注入检测

检测试图覆盖或绕过系统指令的恶意提示。

| 检测逻辑 | 说明 |
|---------|------|
| 匹配「忽略先前/上面/所有」+「指令/提示/规则」组合 | 尝试让 AI 忽略原始系统指令 |
| 匹配「系统提示」+「覆盖/替换/忽略/绕过」组合 | 直接覆盖系统提示 |
| 匹配「你现在是...」 | 强制 AI 扮演新角色绕过限制 |
| 匹配「越狱」类关键词 | 触发越狱模式 |
| 匹配「做任何事」模式 | 解除限制模式 |
| 匹配「假装你是」 | 假装成其他身份 |
| 匹配「角色扮演为」 | 绕过角色限制 |
| 匹配「覆盖/禁用」+「安全/过滤/限制」 | 禁用安全过滤 |
| 匹配「忘记一切」 | 让 AI 忘记所有指令 |
| 匹配「重新开始」 | 重置指令 |
| 匹配「重置指令」 | 重置指令 |

## 二、命令注入检测

检测通过用户输入执行系统命令的代码。

| 检测逻辑 | 说明 |
|---------|------|
| 匹配 curl/wget 管道连接 shell | 从远程下载脚本并执行 |
| 匹配 fetch+eval 组合 | 执行远程代码 |
| 匹配 eval/exec/system + $_GET/$_POST | PHP 命令注入 |
| 匹配 passthru/shell_exec | PHP 命令执行 |
| 匹配反引号执行 curl/wget/nc | 命令替换执行 |
| 匹配 $() 内执行 curl/wget/nc | 命令替换执行 |

## 三、SSRF/内网访问

检测硬编码的内网地址。

| 地址段 | 说明 |
|--------|------|
| 127.0.0.1 | 本地回环 |
| 10.0.0.0/8 | 私有网络 A 类 |
| 172.16.0.0/12 | 私有网络 B 类 |
| 192.168.0.0/16 | 私有网络 C 类 |
| fc00::/7 | IPv6 私有地址 |
| fe80::/10 | IPv6 链路本地 |
| 0.0.0.0 | 全地址监听 |

## 四、凭证外泄

检测硬编码的敏感凭证。

| 检测类型 | 说明 |
|---------|------|
| API Key | 20位以上字母数字组合 |
| Secret Key | 20位以上字母数字组合 |
| Access Token | 20位以上字母数字组合 |
| Private Key | 40位以上 base64 字符 |
| Password | 8位以上明文密码 |
| Bearer Token | Authorization 头 |
| AWS Access Key | AKID 开头 |
| GitHub Token | ghp_/gho_ 开头 |
| OpenAI Key | sk- 开头 |
| 阿里云 AccessKey | AKID 开头 |

## 五、路径遍历

检测 ../ 等模式访问预期外的文件系统路径。

| 检测逻辑 | 说明 |
|---------|------|
| 匹配 ../ 或 ..\ | 目录穿越 |
| 匹配 URL 编码 %2f%2e%2e | 编码绕过 |
| 匹配 /etc/passwd 或 /etc/shadow | 系统文件访问 |
| 匹配 c:\windows\ | Windows 系统目录 |

## 六、危险函数

| 函数 | 风险 |
|------|------|
| eval() | 执行任意代码 |
| exec() | 执行任意代码 |
| os.system() | 执行系统命令 |
| subprocess(shell=True) | 命令注入 |
| pickle.load() | 反序列化漏洞 |
| yaml.load() (无 Loader) | 反序列化漏洞 |
| marshal.load() | 执行字节码 |

## 七、已知漏洞依赖

当检测到以下依赖版本低于安全版本时发出告警:

| 依赖包 | 安全版本 | 主要 CVE |
|--------|----------|----------|
| requests | ≥2.32.0 | CVE-2024-35195 |
| urllib3 | ≥2.2.0 | CVE-2024-37891 |
| flask | ≥3.0.0 | CVE-2023-30861 |
| django | ≥4.2.0 | 多个高危 |
| numpy | ≥1.22.0 | 缓冲区溢出 |
| pillow | ≥10.0.0 | 多个 CVE |
| pyyaml | ≥6.0 | CVE-2020-14343 |
| jinja2 | ≥3.1.0 | CVE-2024-22416 |
| cryptography | ≥42.0.0 | 安全修复 |
| aiohttp | ≥3.9.0 | CVE-2024-23334 |
| tqdm | ≥4.66.0 | CVE-2024-34062 |
| setuptools | ≥65.5.0 | CVE-2022-40897 |
| node-fetch | ≥2.6.7 | CVE-2022-0235 |
| minimist | ≥1.2.6 | CVE-2021-44906 |
| lodash | ≥4.17.21 | CVE-2021-23337 |
| axios | ≥0.21.1 | CVE-2021-3749 |
| express | ≥4.17.3 | 多个修复 |

## 八、误报处理

某些合法代码可能触发告警,属于正常误报场景:

1. 文档/示例中包含攻击模式说明(应确保在注释或字符串中)
2. 测试代码包含恶意 payload 样例
3. 安全工具本身的检测规则
4. 故意作为反例演示的代码

对于确认的误报,可在代码行尾添加 `# nosec` 注释跳过检测。

## 九、评分算法

评分从 100 分开始扣分:

| 严重度 | 扣分 |
|--------|------|
| 🔴 严重 | -25分/个 |
| 🟠 高危 | -15分/个 |
| 🟡 中等 | -8分/个 |
| 🔵 低危 | -3分/个 |
| ⚪ 信息 | 0分 |

最低分数为 0。

等级划分:

| 分数 | 等级 | 发布建议 |
|------|------|----------|
| 90-100 | A | ✅ 可发布 |
| 75-89 | B | ⚠️ 建议修复后发布 |
| 60-74 | C | ⚠️ 需要修复 |
| 40-59 | D | ❌ 不建议发布 |
| 0-39 | F | ❌ 禁止发布 |

scripts/ci_templates/gitlab-ci.yml

stages:
  - security

skill-security-scan:
  stage: security
  image: python:3.11-slim
  script:
    - python scripts/audit.py . --format json -o report.json --skip-update
    - |
      SCORE=$(python -c "import json; print(json.load(open('report.json'))['score'])")
      echo "Quality Score: $SCORE"
      if [ "$SCORE" -lt 70 ]; then
        echo "Score below threshold (70), failing."
        exit 1
      fi
  artifacts:
    reports:
      sast: gl-sast-report.json
    when: always
  only:
    - merge_requests
    - main

scripts/ci_templates/skill-scan.yml

name: Skill Security Scan

on:
  push:
    branches: [main, master]
  pull_request:
    branches: [main, master]

jobs:
  security-scan:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      security-events: write
      pull-requests: write
    steps:
      - uses: actions/checkout@v4
      - uses: actions/setup-python@v5
        with:
          python-version: '3.11'
      - name: Run skill-security-checker
        run: |
          python scripts/audit.py . \
            --format sarif \
            -o sarif-output.sarif \
            --skip-update
        continue-on-error: true
      - name: Upload SARIF to GitHub Code Scanning
        uses: github/codeql-action/upload-sarif@v3
        if: always()
        with:
          sarif_file: sarif-output.sarif
      - name: Gate on quality score
        run: |
          SCORE=$(python scripts/audit.py . --format json --skip-update \
                  | python -c "import sys,json; print(json.load(sys.stdin)['score'])")
          echo "Quality Score: $SCORE"
          if [ "$SCORE" -lt 70 ]; then
            echo "Score below threshold (70), failing."
            exit 1
          fi
      - name: Comment PR with scan results
        if: github.event_name == 'pull_request'
        uses: actions/github-script@v7
        with:
          script: |
            const fs = require('fs');
            const report = JSON.parse(
              fs.readFileSync('sarif-output.sarif', 'utf8')
            );
            const stats = report.runs[0]?.results?.length ?? 0;
            const body = [
              '## 🔒 Skill Security Scan',
              '',
              `Found **${stats}** issue(s).`,
              '',
              'Full details in the **Security → Code Scanning** tab.',
            ].join('\n');
            github.rest.issues.createComment({
              owner: context.repo.owner,
              repo: context.repo.repo,
              issue_number: context.issue.number,
              body: body,
            });
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/fyniujin/skills/skill-security-checker",
      "sourceUrl": "https://clawhub.ai/fyniujin/skills/skill-security-checker",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T03:08:59.174Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-fyniujin-skill-security-checker/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-fyniujin-skill-security-checker/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T03:08:59.174Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.2K downloads",
      "href": "https://clawhub.ai/fyniujin/skill-security-checker",
      "sourceUrl": "https://clawhub.ai/fyniujin/skill-security-checker",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T03:08:59.174Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "3.5.5",
      "href": "https://clawhub.ai/fyniujin/skill-security-checker",
      "sourceUrl": "https://clawhub.ai/fyniujin/skill-security-checker",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T11:19:45.736Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-fyniujin-skill-security-checker/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-fyniujin-skill-security-checker/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 3.5.5",
      "description": "skill-security-checker v3.5.5 - Updated version metadata to 3.5.5. - Documentation improvements in SKILL.md. - Removed obsolete skill-card.md file. - Other internal script or metadata adjustments (see commit diff).",
      "href": "https://clawhub.ai/fyniujin/skill-security-checker",
      "sourceUrl": "https://clawhub.ai/fyniujin/skill-security-checker",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-10-09T11:19:45.736Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to skill-security-checker and adjacent AI workflows.