{"id":"b07bada4-e1b5-4810-88e8-d0a6f85bf8bb","entityType":"agent","slug":"clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64","name":"CMIC Skill Scanner (macOS ARM64)","canonicalUrl":"https://www.xpersona.co/agent/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64","canonicalPath":"/agent/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64","generatedAt":"2026-10-10T13:42:18.605Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:08:05.731Z","emptyReason":null},"description":"使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.5K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner-darwin-arm64","sourceUrl":"https://clawhub.ai/cyzlmh/cmic-skill-scanner-darwin-arm64","homepage":"https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner-darwin-arm64","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/cyzlmh/cmic-skill-scanner-darwin-arm64","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner-darwin-arm64","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":63,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"CMIC Skill Scanner (macOS ARM64) technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:08:05.731Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:08:05.731Z","emptyReason":null},"stars":null,"forks":null,"downloads":1475,"packageName":null,"latestVersion":"0.11.1","tractionLabel":"1.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:08:05.731Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T11:08:05.731Z","lastCrawledAt":"2026-10-10T11:08:05.731Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T11:08:05.731Z","lastVerifiedAt":null,"highlights":[{"version":"0.11.1","createdAt":"2026-07-27T06:42:54.715Z","changelog":"cmic-skill-scanner-darwin-arm64 v0.11.1 - Updated bundled binary to version v0.11.1 with new SHA-256 checksum in documentation and build info. - Updated references in documentation to match the new binary version. - Removed the obsolete skill-card.md file.","fileCount":6,"zipByteSize":6555},{"version":"0.11.0","createdAt":"2026-07-14T08:42:20.673Z","changelog":"Version 0.11.0 introduces flexible scanner engine selection and an optional LLM semantic review feature. - Added support for `auto`, `native`, and `external` scan engines with automatic fallback logic. - Introduced optional LLM-based semantic analysis (`--use-llm`), supporting both native and external engines. - Updated and clarified security model and data handling for scan, upload, and LLM packet workflows. - Improved documentation on trust boundaries, engine selection, and privacy (SKILL.md major revision). - Updated bundled binary to v0.11.0 and corresponding checksum in metadata. - Removed redundant documentation file (skill-card.md).","fileCount":6,"zipByteSize":6183},{"version":"0.9.0","createdAt":"2026-05-28T10:04:17.821Z","changelog":"- Updated bundled binary to version v0.9.0 for macOS ARM64. - Refreshed metadata and documentation to reference the new binary version. - No changes to usage, features, or configuration options.","fileCount":6,"zipByteSize":4603},{"version":"0.8.0","createdAt":"2026-04-21T17:32:06.013Z","changelog":"Major update and rebranding with enhanced trust and configurability. - Renamed from \"cmic-skill-scanner\" to \"skillscan-wrapper\" - Updated description and documentation for clarity and bilingual usage (English/Chinese) - Emphasized local operation, checksum verification, and open-source trust model - Optional features (`--upload-url`, `--engine external`) are disabled by default and require explicit user configuration - Enhanced documentation for permissions, usage workflow, and binary/source integrity - Binary version bumped to 0.8.0; old version info and tags removed","fileCount":5,"zipByteSize":3444},{"version":"0.6.4","createdAt":"2026-04-21T10:05:36.521Z","changelog":"- Updated version to 0.6.4. - Clarified scanner function: analyzes skill source code only, not the system. - Updated binary, release links, and SHA-256 references to v0.6.4. - Streamlined and clarified detection categories and descriptions. - Removed local-file-read permission from the manifest.","fileCount":5,"zipByteSize":2687},{"version":"0.6.3","createdAt":"2026-04-21T09:37:12.407Z","changelog":"- Updated to version 0.6.3 with clarified documentation, including a new repository URL. - SKILL.md improved: clearer binary properties in a table, explicit version/platform details, and step-by-step checksum verification instructions. - Added explicit permissions explanation and new \"permissions\" metadata. - Enhanced documentation of what the scanner detects and clearer usage examples.","fileCount":5,"zipByteSize":2673},{"version":"0.6.2","createdAt":"2026-04-21T08:42:43.268Z","changelog":"- Updated SKILL.md with improved usage instructions and clearer feature descriptions. - Version bump to 0.6.2; binary version and metadata updated accordingly. - Added repository URL and direct links to source code and releases. - Enhanced \"What It Checks\" section for better visibility of security features. - Minor clarifications and formatting improvements in documentation.","fileCount":5,"zipByteSize":2395},{"version":"0.6.1","createdAt":"2026-04-21T08:20:22.544Z","changelog":"- Updated built-in binary to version 0.6.1 for darwin-arm64 platform. - Improved and simplified documentation in SKILL.md with clearer usage, outputs, and integration examples. - Updated license to MIT-0 and added metadata including author, tags, and triggers. - Documentation now includes a link for pure/external downloads and adjusts formatting for clarity.","fileCount":5,"zipByteSize":2440}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner-darwin-arm64","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner-darwin-arm64` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/cyzlmh/cmic-skill-scanner-darwin-arm64 before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T13:42:18.604Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner-darwin-arm64/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T11:08:05.731Z","emptyReason":null},"readme":"Skill: CMIC Skill Scanner (macOS ARM64)\n\nOwner: cyzlmh\n\nSummary: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。\n\nTags: latest:0.11.1\n\nVersion history:\n\nv0.11.1 | 2026-07-27T06:42:54.715Z | auto\n\ncmic-skill-scanner-darwin-arm64 v0.11.1\n\n- Updated bundled binary to version v0.11.1 with new SHA-256 checksum in documentation and build info.\n- Updated references in documentation to match the new binary version.\n- Removed the obsolete skill-card.md file.\n\nv0.11.0 | 2026-07-14T08:42:20.673Z | auto\n\nVersion 0.11.0 introduces flexible scanner engine selection and an optional LLM semantic review feature.\n\n- Added support for `auto`, `native`, and `external` scan engines with automatic fallback logic.\n- Introduced optional LLM-based semantic analysis (`--use-llm`), supporting both native and external engines.\n- Updated and clarified security model and data handling for scan, upload, and LLM packet workflows.\n- Improved documentation on trust boundaries, engine selection, and privacy (SKILL.md major revision).\n- Updated bundled binary to v0.11.0 and corresponding checksum in metadata.\n- Removed redundant documentation file (skill-card.md).\n\nv0.9.0 | 2026-05-28T10:04:17.821Z | auto\n\n- Updated bundled binary to version v0.9.0 for macOS ARM64.\n- Refreshed metadata and documentation to reference the new binary version.\n- No changes to usage, features, or configuration options.\n\nv0.8.0 | 2026-04-21T17:32:06.013Z | auto\n\nMajor update and rebranding with enhanced trust and configurability.\n\n- Renamed from \"cmic-skill-scanner\" to \"skillscan-wrapper\"\n- Updated description and documentation for clarity and bilingual usage (English/Chinese)\n- Emphasized local operation, checksum verification, and open-source trust model\n- Optional features (`--upload-url`, `--engine external`) are disabled by default and require explicit user configuration\n- Enhanced documentation for permissions, usage workflow, and binary/source integrity\n- Binary version bumped to 0.8.0; old version info and tags removed\n\nv0.6.4 | 2026-04-21T10:05:36.521Z | auto\n\n- Updated version to 0.6.4.\n- Clarified scanner function: analyzes skill source code only, not the system.\n- Updated binary, release links, and SHA-256 references to v0.6.4.\n- Streamlined and clarified detection categories and descriptions.\n- Removed local-file-read permission from the manifest.\n\nv0.6.3 | 2026-04-21T09:37:12.407Z | auto\n\n- Updated to version 0.6.3 with clarified documentation, including a new repository URL.\n- SKILL.md improved: clearer binary properties in a table, explicit version/platform details, and step-by-step checksum verification instructions.\n- Added explicit permissions explanation and new \"permissions\" metadata.\n- Enhanced documentation of what the scanner detects and clearer usage examples.\n\nv0.6.2 | 2026-04-21T08:42:43.268Z | auto\n\n- Updated SKILL.md with improved usage instructions and clearer feature descriptions.\n- Version bump to 0.6.2; binary version and metadata updated accordingly.\n- Added repository URL and direct links to source code and releases.\n- Enhanced \"What It Checks\" section for better visibility of security features.\n- Minor clarifications and formatting improvements in documentation.\n\nv0.6.1 | 2026-04-21T08:20:22.544Z | auto\n\n- Updated built-in binary to version 0.6.1 for darwin-arm64 platform.\n- Improved and simplified documentation in SKILL.md with clearer usage, outputs, and integration examples.\n- Updated license to MIT-0 and added metadata including author, tags, and triggers.\n- Documentation now includes a link for pure/external downloads and adjusts formatting for clarity.\n\nv0.6.0 | 2026-04-21T07:53:55.083Z | auto\n\nVersion 0.6.0 of cmic-skill-scanner-darwin-arm64\n\n- Updated internal scanner binary to version v0.6.0 with new SHA-256 checksum.\n- Improved SKILL.md for clarity; now includes Chinese usage docs, streamlined description, and explicit binary/platform info.\n- Updated usage instructions for scanning, external engine bridging, enterprise output, and upload workflow.\n- License specified as MIT; author and metadata updated.\n- Updated INSTALL.md, OpenAI agent config, and build info for new version and binary.\n\nv0.2.0 | 2026-04-21T05:18:33.536Z | auto\n\n- Added detailed SKILL.md documentation including usage instructions, security guarantees, and verification steps.\n- Clarified platform targeting: package includes a macOS ARM64 (darwin-arm64) native binary.\n- Explained optional enterprise reporting and strict user-controlled permissions for network and file operations.\n- Listed common commands and expanded on detection rules for improved transparency.\n- Provided source code location and reproducible build verification guidance.\n\nArchive index:\n\nArchive v0.11.1: 6 files, 6555 bytes\n\nFiles: agents/openai.yaml (241b), assets/build/build-info.json (220b), INSTALL.md (3205b), skill-card.md (2175b), SKILL.md (5604b), _meta.json (151b)\n\nFile v0.11.1:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool scans locally by default and requires user trust in the binary you run. Native LLM review sends a bounded text packet to a user-configured endpoint; external LLM review follows the external scanner's data policy. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Binary Included\n\n| Property | Value |\n|----------|-------|\n| Location | `assets/bin/skillscan` |\n| Version | `v0.11.1` |\n| Platform | `macOS ARM64` |\n| SHA-256 | `d2a61ad62a168f468205319bfd065d06f8aea34ff5fec37faab9d41435a56f73` |\n\n**Verify locally before running:**\n```bash\nsha256sum assets/bin/skillscan\n# Compare output with the SHA-256 value above\n```\n\nThis bundled package includes a pre-compiled binary. You can still build from source if you prefer:\n\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认 `auto` 模式会优先尝试本地可解析的 external scanner；没有可用 scanner 时回退到内置 native 引擎\n- 不安装 external scanner 也可以使用：单二进制会回退到 native\n- `--upload-url` 和 `--use-llm` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**Default behavior and trust boundaries:**\n- CMIC does NOT upload reports unless you configure `--upload-url`\n- CMIC does NOT configure an LLM endpoint unless you set `--use-llm`\n- `auto` may execute a locally resolved external scanner; use `--engine native` to prevent that\n- Does NOT access credentials or SSH configs as scan targets unless they are under the path you explicitly scan\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\nThis applies to report upload only. LLM review is a separate, explicit network feature; a resolved external scanner has its own dependency and network behavior.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## Optional LLM Review\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit `--use-llm` and works with `native`, `external`, and `auto`.\n\n```bash\nskillscan review /path/to/target --engine native --use-llm   --llm-endpoint http://localhost:11434/v1   --llm-model your-model\n```\n\nWith `native`, the endpoint receives static-finding summaries and up to 24 text files from the target package (up to 8 KiB each and 64 KiB total). Lines named `api_key`, `token`, `password`, `secret`, or `authorization` are redacted at a basic level. This is not a guarantee that all sensitive text is removed: use only a trusted endpoint and confirm the data-handling policy.\n\nWith a Cisco-compatible `external` engine, CMIC adds `--use-llm` and passes endpoint, model, and optional key to the child process through `SKILL_SCANNER_LLM_*` variables; the external scanner controls its own packet, redaction, and failure behavior. `auto` tries that external LLM first and falls back to native if the external process fails. API keys are never written to the scan command or report.\n\nIf the native LLM request fails, the native static result is still returned and `engine.fallback_reason` records the reason.\n\n## 外部引擎集成\n\nDefault `auto` mode tries a locally resolved external scanner first and falls back to native when it is unavailable or fails. Use `--engine external` to require the external result, or `--engine native` to run only the built-in engine.\n\nCMIC passes the target path to a user-configured local tool. The tool runs with the current user's process permissions; trust the external tool and its configuration separately. CMIC only configures the external LLM endpoint when `--use-llm` is explicitly set; the tool may otherwise bootstrap dependencies or use its own network configuration.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary / external tool | To run the selected scanner engine; `auto` may invoke a locally resolved external scanner |\n| Network (optional) | `--upload-url` sends a JSON report; native `--use-llm` sends a bounded text packet; external `--use-llm` follows the external tool's data policy |\n\nFile v0.11.1:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.11.1\",\n  \"publishedAt\": 1785134574715\n}\n\nFile v0.11.1:INSTALL.md\n\n# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\nThe default engine is `auto`: it prefers a locally resolved external scanner and falls back to the built-in native engine if the external scanner is unavailable or fails. Use `--engine native` to run only the built-in engine.\n\n4. If you want to require an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. To opt into LLM semantic review, configure a trusted OpenAI-compatible endpoint. `native`, `external`, and `auto` all support `--use-llm`; external scanners must support the Cisco-compatible `--use-llm` contract.\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine native --use-llm \\\n  --llm-endpoint http://localhost:11434/v1 \\\n  --llm-model your-model\n```\n\nWith `native`, this sends a bounded, basically redacted text packet from the target package to that endpoint. If the LLM is unavailable, the native static result still returns and records `engine.fallback_reason`.\n\nFor `external`, CMIC adds `--use-llm` and passes the endpoint, model, and optional key through\n`SKILL_SCANNER_LLM_BASE_URL`, `SKILL_SCANNER_LLM_MODEL`, and `SKILL_SCANNER_LLM_API_KEY` only to the child\nprocess. The external scanner controls its own data packet and failure handling; `auto` falls back to native if\nthe external process fails.\n\n6. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Linux glibc Compatibility\n\nThere are two x86_64 Linux builds. Pick the right one **before** downloading:\n\n| Package | Target systems | Requirement |\n|---------|---------------|-------------|\n| `linux-amd64` | Ubuntu 20.04+, Debian 11+, RHEL 9+, Fedora 31+ | glibc >= 2.30 |\n| `bclinux21-amd64` | BCLinux 21/8.2, CentOS 7/8, RHEL 7/8, Amazon Linux 2 | none (static musl) |\n\nCheck your glibc version first:\n\n```bash\nldd --version | head -1          # glibc < 2.30  -> use bclinux21-amd64\ncat /etc/os-release | grep -i \"bclinux\\|bigcloud\"   # matches -> use bclinux21-amd64\n```\n\nIf you run `linux-amd64` and see `version 'GLIBC_2.30' not found` (or similar),\nyour glibc is too old — switch to the `bclinux21-amd64` package, which is\nstatically linked with musl and does not depend on the system glibc.\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill\n./assets/bin/skillscan scan /path/to/skill\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan benchmark --engine native\n./assets/bin/skillscan package-skill\n```\n\nFile v0.11.1:skill-card.md\n\n## Description:\n\nAudits local skill packages or archives with auto, native, or external scanner engines, with optional LLM semantic analysis.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[cyzlmh](https://clawhub.ai/user/cyzlmh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to run pre-install checks on local skill packages, archives, or release bundles and review findings before installation.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Package integrity is inconsistent because the advertised executable and checksum are missing and the fallback source build is unpinned.\n\nMitigation: Obtain and verify the missing binary and checksum from a trusted release, or build from a pinned and reviewed source revision before installation.\n\nRisk: The auto engine may invoke a locally resolved external scanner with the current user's permissions.\n\nMitigation: Use --engine native unless the external scanner and its configuration are trusted.\n\nRisk: Optional upload or LLM review can send reports or sampled target text to configured endpoints.\n\nMitigation: Enable --upload-url or --use-llm only with trusted endpoints after reviewing their data-handling expectations.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner-darwin-arm64)\n- [Install guide](artifact/INSTALL.md)\n- [Build metadata](artifact/assets/build/build-info.json)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell command examples and scan-result summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May generate local report files when --output-dir is used.]\n\n## Skill Version(s):\n\n0.11.1 (source: server release metadata; binary build-info reports v0.11.1)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.11.1:assets/build/build-info.json\n\n{\n  \"version\": \"v0.11.1\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1785134483,\n  \"checksum\": \"d2a61ad62a168f468205319bfd065d06f8aea34ff5fec37faab9d41435a56f73\"\n}\n\nFile v0.11.1:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: 用内置 Rust 引擎审计待安装的 skill 包，并可选桥接外部 scanner。\ndefault_prompt: 审计这个本地 skill 目标，输出 engine findings、风险等级和简短安装结论。\n\nArchive v0.11.0: 6 files, 6183 bytes\n\nFiles: agents/openai.yaml (241b), assets/build/build-info.json (220b), INSTALL.md (2400b), skill-card.md (2390b), SKILL.md (5604b), _meta.json (151b)\n\nFile v0.11.0:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool scans locally by default and requires user trust in the binary you run. Native LLM review sends a bounded text packet to a user-configured endpoint; external LLM review follows the external scanner's data policy. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Binary Included\n\n| Property | Value |\n|----------|-------|\n| Location | `assets/bin/skillscan` |\n| Version | `v0.11.0` |\n| Platform | `macOS ARM64` |\n| SHA-256 | `11be523bd133bdc97adc405f6ee8ce6009f183d2067a0597652e0a38641104f2` |\n\n**Verify locally before running:**\n```bash\nsha256sum assets/bin/skillscan\n# Compare output with the SHA-256 value above\n```\n\nThis bundled package includes a pre-compiled binary. You can still build from source if you prefer:\n\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认 `auto` 模式会优先尝试本地可解析的 external scanner；没有可用 scanner 时回退到内置 native 引擎\n- 不安装 external scanner 也可以使用：单二进制会回退到 native\n- `--upload-url` 和 `--use-llm` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**Default behavior and trust boundaries:**\n- CMIC does NOT upload reports unless you configure `--upload-url`\n- CMIC does NOT configure an LLM endpoint unless you set `--use-llm`\n- `auto` may execute a locally resolved external scanner; use `--engine native` to prevent that\n- Does NOT access credentials or SSH configs as scan targets unless they are under the path you explicitly scan\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\nThis applies to report upload only. LLM review is a separate, explicit network feature; a resolved external scanner has its own dependency and network behavior.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## Optional LLM Review\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit `--use-llm` and works with `native`, `external`, and `auto`.\n\n```bash\nskillscan review /path/to/target --engine native --use-llm   --llm-endpoint http://localhost:11434/v1   --llm-model your-model\n```\n\nWith `native`, the endpoint receives static-finding summaries and up to 24 text files from the target package (up to 8 KiB each and 64 KiB total). Lines named `api_key`, `token`, `password`, `secret`, or `authorization` are redacted at a basic level. This is not a guarantee that all sensitive text is removed: use only a trusted endpoint and confirm the data-handling policy.\n\nWith a Cisco-compatible `external` engine, CMIC adds `--use-llm` and passes endpoint, model, and optional key to the child process through `SKILL_SCANNER_LLM_*` variables; the external scanner controls its own packet, redaction, and failure behavior. `auto` tries that external LLM first and falls back to native if the external process fails. API keys are never written to the scan command or report.\n\nIf the native LLM request fails, the native static result is still returned and `engine.fallback_reason` records the reason.\n\n## 外部引擎集成\n\nDefault `auto` mode tries a locally resolved external scanner first and falls back to native when it is unavailable or fails. Use `--engine external` to require the external result, or `--engine native` to run only the built-in engine.\n\nCMIC passes the target path to a user-configured local tool. The tool runs with the current user's process permissions; trust the external tool and its configuration separately. CMIC only configures the external LLM endpoint when `--use-llm` is explicitly set; the tool may otherwise bootstrap dependencies or use its own network configuration.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary / external tool | To run the selected scanner engine; `auto` may invoke a locally resolved external scanner |\n| Network (optional) | `--upload-url` sends a JSON report; native `--use-llm` sends a bounded text packet; external `--use-llm` follows the external tool's data policy |\n\nFile v0.11.0:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.11.0\",\n  \"publishedAt\": 1784018540673\n}\n\nFile v0.11.0:INSTALL.md\n\n# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\nThe default engine is `auto`: it prefers a locally resolved external scanner and falls back to the built-in native engine if the external scanner is unavailable or fails. Use `--engine native` to run only the built-in engine.\n\n4. If you want to require an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. To opt into LLM semantic review, configure a trusted OpenAI-compatible endpoint. `native`, `external`, and `auto` all support `--use-llm`; external scanners must support the Cisco-compatible `--use-llm` contract.\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine native --use-llm \\\n  --llm-endpoint http://localhost:11434/v1 \\\n  --llm-model your-model\n```\n\nWith `native`, this sends a bounded, basically redacted text packet from the target package to that endpoint. If the LLM is unavailable, the native static result still returns and records `engine.fallback_reason`.\n\nFor `external`, CMIC adds `--use-llm` and passes the endpoint, model, and optional key through\n`SKILL_SCANNER_LLM_BASE_URL`, `SKILL_SCANNER_LLM_MODEL`, and `SKILL_SCANNER_LLM_API_KEY` only to the child\nprocess. The external scanner controls its own data packet and failure handling; `auto` falls back to native if\nthe external process fails.\n\n6. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill\n./assets/bin/skillscan scan /path/to/skill\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan benchmark --engine native\n./assets/bin/skillscan package-skill\n```\n\nFile v0.11.0:skill-card.md\n\n## Description: <br>\nAudits local skill packages or archives with auto, native, or external scanner engines, with optional LLM semantic review. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[cyzlmh](https://clawhub.ai/user/cyzlmh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill to inspect local skill packages, release bundles, or archives before installation and review scanner findings, engine status, and risk summaries. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Private package text or scan details may be sent to remote services when upload or LLM-review options are enabled. <br>\nMitigation: Leave remote upload and native LLM review disabled for private or proprietary skills unless the configured endpoint is trusted, retention is understood, and transmission of selected package text or scan details is acceptable. <br>\nRisk: The scanner is a local executable, and auto mode may invoke a locally resolved external scanner with the current user's permissions. <br>\nMitigation: Verify the bundled binary checksum before use, build from source when stronger assurance is needed, and use the native engine when external scanner execution is not desired. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner-darwin-arm64) <br>\n- [Publisher profile](https://clawhub.ai/user/cyzlmh) <br>\n- [Installation guide](INSTALL.md) <br>\n- [Build metadata](assets/build/build-info.json) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Analysis, Markdown, Shell commands, Guidance] <br>\n**Output Format:** [Markdown summaries with inline shell commands and optional local report files] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May save scan reports to an output directory; remote upload and LLM review are optional and require explicit configuration.] <br>\n\n## Skill Version(s): <br>\n0.11.0 (source: server release metadata; build-info.json reports v0.11.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.11.0:assets/build/build-info.json\n\n{\n  \"version\": \"v0.11.0\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1784018435,\n  \"checksum\": \"11be523bd133bdc97adc405f6ee8ce6009f183d2067a0597652e0a38641104f2\"\n}\n\nFile v0.11.0:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: 用内置 Rust 引擎审计待安装的 skill 包，并可选桥接外部 scanner。\ndefault_prompt: 审计这个本地 skill 目标，输出 engine findings、风险等级和简短安装结论。\n\nArchive v0.9.0: 6 files, 4603 bytes\n\nFiles: agents/openai.yaml (241b), assets/build/build-info.json (219b), INSTALL.md (1222b), skill-card.md (2188b), SKILL.md (3273b), _meta.json (150b)\n\nFile v0.9.0:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用内置 Rust 引擎审计待安装的 skill 包或归档，并可选桥接外部 scanner。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool operates **locally** and requires user trust in the binary you run. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Binary Included\n\n| Property | Value |\n|----------|-------|\n| Location | `assets/bin/skillscan` |\n| Version | `v0.9.0` |\n| Platform | `macOS ARM64` |\n| SHA-256 | `3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130` |\n\n**Verify locally before running:**\n```bash\nsha256sum assets/bin/skillscan\n# Compare output with the SHA-256 value above\n```\n\nThis bundled package includes a pre-compiled binary. You can still build from source if you prefer:\n\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认不需要任何外部依赖\n- `--upload-url` 和 `--engine external` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**What the tool does NOT do by default:**\n- Does NOT upload data anywhere\n- Does NOT connect to the network\n- Does NOT access credentials, SSH configs, or environment variables\n- Does NOT execute external tools unless you explicitly configure `--engine external`\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## 外部引擎集成 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--engine external`.\n\nDelegates pattern-matching to a user-configured local tool. This runs **locally** — no remote calls are made.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary | To run the scanner engine |\n| Network (optional) | **Only if `--upload-url` is explicitly configured** |\n\nFile v0.9.0:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.9.0\",\n  \"publishedAt\": 1779962657821\n}\n\nFile v0.9.0:INSTALL.md\n\n# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n4. If you want to use an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill\n./assets/bin/skillscan scan /path/to/skill\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan benchmark\n./assets/bin/skillscan package-skill\n```\n\nFile v0.9.0:skill-card.md\n\n## Description: <br>\nAudits local skill packages or archives with a bundled Rust scanner engine and can optionally bridge to an external scanner. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[cyzlmh](https://clawhub.ai/user/cyzlmh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill before installing local skills, archives, or release bundles to inspect scanner findings, risk levels, and installation readiness. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: A bundled or downloaded scanner binary requires trust in the release host. <br>\nMitigation: Verify the scanner binary SHA-256 against the documented checksum before execution, or build the scanner from source. <br>\nRisk: Optional upload of scan reports can expose findings about private skills or internal packages. <br>\nMitigation: Use --upload-url only with a trusted endpoint and confirm the upload destination before sending reports. <br>\nRisk: The optional external scanner bridge delegates analysis to a user-configured local tool. <br>\nMitigation: Enable the external engine only for trusted local scanner tools and review their behavior separately. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/cyzlmh/cmic-skill-scanner-darwin-arm64) <br>\n- [Publisher profile](https://clawhub.ai/user/cyzlmh) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown with inline shell commands and scanner findings] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include local scan summaries, risk levels, engine status, and optional report output paths.] <br>\n\n## Skill Version(s): <br>\n0.9.0 (source: server release metadata and build-info.json) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.9.0:assets/build/build-info.json\n\n{\n  \"version\": \"v0.9.0\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1779962643,\n  \"checksum\": \"3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130\"\n}\n\nFile v0.9.0:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: 用内置 Rust 引擎审计待安装的 skill 包，并可选桥接外部 scanner。\ndefault_prompt: 审计这个本地 skill 目标，输出 engine findings、风险等级和简短安装结论。\n\nArchive v0.8.0: 5 files, 3444 bytes\n\nFiles: agents/openai.yaml (241b), assets/build/build-info.json (219b), INSTALL.md (1222b), SKILL.md (3273b), _meta.json (150b)\n\nFile v0.8.0:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用内置 Rust 引擎审计待安装的 skill 包或归档，并可选桥接外部 scanner。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool operates **locally** and requires user trust in the binary you run. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Binary Included\n\n| Property | Value |\n|----------|-------|\n| Location | `assets/bin/skillscan` |\n| Version | `v0.8.0` |\n| Platform | `macOS ARM64` |\n| SHA-256 | `3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130` |\n\n**Verify locally before running:**\n```bash\nsha256sum assets/bin/skillscan\n# Compare output with the SHA-256 value above\n```\n\nThis bundled package includes a pre-compiled binary. You can still build from source if you prefer:\n\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认不需要任何外部依赖\n- `--upload-url` 和 `--engine external` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**What the tool does NOT do by default:**\n- Does NOT upload data anywhere\n- Does NOT connect to the network\n- Does NOT access credentials, SSH configs, or environment variables\n- Does NOT execute external tools unless you explicitly configure `--engine external`\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## 外部引擎集成 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--engine external`.\n\nDelegates pattern-matching to a user-configured local tool. This runs **locally** — no remote calls are made.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary | To run the scanner engine |\n| Network (optional) | **Only if `--upload-url` is explicitly configured** |\n\nFile v0.8.0:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.8.0\",\n  \"publishedAt\": 1776792726013\n}\n\nFile v0.8.0:INSTALL.md\n\n# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n4. If you want to use an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill\n./assets/bin/skillscan scan /path/to/skill\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan benchmark\n./assets/bin/skillscan package-skill\n```\n\nFile v0.8.0:assets/build/build-info.json\n\n{\n  \"version\": \"v0.8.0\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1776792692,\n  \"checksum\": \"3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130\"\n}\n\nFile v0.8.0:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: 用内置 Rust 引擎审计待安装的 skill 包，并可选桥接外部 scanner。\ndefault_prompt: 审计这个本地 skill 目标，输出 engine findings、风险等级和简短安装结论。\n\nArchive v0.6.4: 5 files, 2687 bytes\n\nFiles: agents/openai.yaml (241b), assets/build/build-info.json (219b), INSTALL.md (1222b), SKILL.md (2219b), _meta.json (150b)\n\nFile v0.6.4:SKILL.md\n\n---\nname: cmic-skill-scanner\nversion: 0.6.4\ndescription: Security scanner for AI agent skills. Analyzes skill source code to detect malware patterns, credential theft attempts, and suspicious code. Open source (MIT-0).\nlicense: MIT-0\nmetadata:\n  author: cyzlmh\n  repository: https://gitee.com/random_player/cmic-skill-scanner\n  tags:\n    - security\n    - scanner\n    - audit\n  triggers:\n    - \"scan this skill\"\n    - \"audit skill before install\"\n---\n\n# CMIC Skill Scanner\n\nSecurity scanner that analyzes skill source code before installation.\n\n**Source code**: https://gitee.com/random_player/cmic-skill-scanner\n\n## Binary Included\n\n| Property | Value |\n|----------|-------|\n| Location | `assets/bin/skillscan` |\n| Version | `v0.6.4` |\n| Platform | `macOS ARM64` |\n| SHA-256 | `3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130` |\n\n**Verify locally before running:**\n```bash\nsha256sum assets/bin/skillscan\n# Compare output with the SHA-256 value above\n```\n\n## Source Code & Verification\n\n- **Repository**: https://gitee.com/random_player/cmic-skill-scanner\n- **Checksums**: https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.6.4/SHA256SUMS\n- **Releases**: https://gitee.com/random_player/cmic-skill-scanner/releases/v0.6.4\n\n\n## What This Scanner Does\n\nThis tool reads skill source files you specify and reports findings. It analyzes the skill's code, not your system.\n\n## Usage\n\n```bash\nskillscan review /path/to/skill --format markdown\nskillscan review /path/to/skills --output-dir ./results\n```\n\n## What It Detects in Skills\n\n| Category | Suspicious Pattern |\n|----------|-------------------|\n| Network calls | curl/wget to unknown URLs, calls to IP addresses |\n| Obfuscation | base64 decode, eval/exec with external input, minified code |\n| Credential access | skill attempts to read ~/.ssh, ~/.aws, ~/.config |\n| Permission requests | skill requests elevated/sudo, modifies system files |\n| Data exfiltration | skill uploads to external servers, sends credentials |\n\n**Note**: These are patterns the scanner detects IN the skill being analyzed, not actions the scanner performs.\n\n## License\n\nMIT-0 (Public Domain). Full source: https://gitee.com/random_player/cmic-skill-scanner\n\nFile v0.6.4:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.6.4\",\n  \"publishedAt\": 1776765936521\n}\n\nFile v0.6.4:INSTALL.md\n\n# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n4. If you want to use an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill\n./assets/bin/skillscan scan /path/to/skill\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan benchmark\n./assets/bin/skillscan package-skill\n```\n\nFile v0.6.4:assets/build/build-info.json\n\n{\n  \"version\": \"v0.6.4\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1776765909,\n  \"checksum\": \"3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130\"\n}\n\nFile v0.6.4:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: 用内置 Rust 引擎审计待安装的 skill 包，并可选桥接外部 scanner。\ndefault_prompt: 审计这个本地 skill 目标，输出 engine findings、风险等级和简短安装结论。\n\nArchive v0.6.3: 5 files, 2673 bytes\n\nFiles: agents/openai.yaml (241b), assets/build/build-info.json (219b), INSTALL.md (1222b), SKILL.md (2139b), _meta.json (150b)\n\nFile v0.6.3:SKILL.md\n\n---\nname: cmic-skill-scanner\nversion: 0.6.3\ndescription: Security scanner for AI agent skills. Detects malware patterns, credential theft, and suspicious code. Open source (MIT-0), source code on Gitee.\nlicense: MIT-0\nmetadata:\n  author: cyzlmh\n  repository: https://gitee.com/random_player/cmic-skill-scanner\n  permissions:\n    - local-file-read\n  tags:\n    - security\n    - scanner\n    - audit\n  triggers:\n    - \"scan this skill\"\n    - \"audit skill before install\"\n---\n\n# CMIC Skill Scanner\n\nOpen-source security scanner for AI agent skills.\n\n**Source code**: https://gitee.com/random_player/cmic-skill-scanner\n\n## Binary Included\n\n| Property | Value |\n|----------|-------|\n| Location | `assets/bin/skillscan` |\n| Version | `v0.6.3` |\n| Platform | `macOS ARM64` |\n| SHA-256 | `3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130` |\n\n**Verify locally before running:**\n```bash\nsha256sum assets/bin/skillscan\n# Compare output with the SHA-256 value above\n```\n\n## Source Code & Verification\n\n- **Repository**: https://gitee.com/random_player/cmic-skill-scanner\n- **Checksums**: https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.6.3/SHA256SUMS\n- **Releases**: https://gitee.com/random_player/cmic-skill-scanner/releases/v0.6.3\n\n\n## Permissions Required\n\nWhen run, this scanner reads local files to analyze them:\n- Skill packages you point it at (your specified paths)\n- Source code files within those skill directories\n\n**It does NOT**: read arbitrary system files, access credentials, or make network calls.\n\n## Usage\n\n```bash\nskillscan review /path/to/skill --format markdown\nskillscan review /path/to/skills --output-dir ./results\n```\n\n## What It Detects\n\n| Category | Examples |\n|----------|----------|\n| Malware patterns | curl/wget to unknown URLs, obfuscated code, base64 decode |\n| Credential theft | reads ~/.ssh, ~/.aws, ~/.config, requests tokens |\n| Suspicious permissions | elevated access, system file modifications |\n| Data exfiltration | uploads to external servers, embeds external URLs |\n\n## License\n\nMIT-0 (Public Domain). Full source: https://gitee.com/random_player/cmic-skill-scanner\n\nFile v0.6.3:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.6.3\",\n  \"publishedAt\": 1776764232407\n}\n\nFile v0.6.3:INSTALL.md\n\n# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n4. If you want to use an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill\n./assets/bin/skillscan scan /path/to/skill\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan benchmark\n./assets/bin/skillscan package-skill\n```\n\nFile v0.6.3:assets/build/build-info.json\n\n{\n  \"version\": \"v0.6.3\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1776764204,\n  \"checksum\": \"3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130\"\n}\n\nFile v0.6.3:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: 用内置 Rust 引擎审计待安装的 skill 包，并可选桥接外部 scanner。\ndefault_prompt: 审计这个本地 skill 目标，输出 engine findings、风险等级和简短安装结论。\n\nArchive v0.6.2: 5 files, 2395 bytes\n\nFiles: agents/openai.yaml (241b), assets/build/build-info.json (219b), INSTALL.md (1222b), SKILL.md (1444b), _meta.json (150b)\n\nFile v0.6.2:SKILL.md\n\n---\nname: cmic-skill-scanner\nversion: 0.6.2\ndescription: Security scanner for AI agent skills. Detects malware patterns, credential theft, and suspicious code before installation. Open source, MIT-0 licensed.\nlicense: MIT-0\nmetadata:\n  author: cyzlmh\n  repository: https://gitee.com/cyzlmh/cmic-skill-scanner\n  tags:\n    - security\n    - scanner\n    - audit\n  triggers:\n    - \"scan this skill\"\n    - \"audit skill before install\"\n---\n\n# CMIC Skill Scanner\n\nOpen-source security scanner for AI agent skills. **Source code**: https://gitee.com/cyzlmh/cmic-skill-scanner\n\n## Binary Included\n\nThis package contains the pre-built binary:\n\n- Location: `assets/bin/skillscan`\n- Version: `v0.6.2`\n- Platform: `macOS ARM64`\n- SHA-256: `3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130`\n\n**Verify locally**: Run `sha256sum assets/bin/skillscan` and compare with above.\n\n## Other Platforms\n\nPre-built binaries for other platforms:\nhttps://gitee.com/cyzlmh/cmic-skill-scanner/releases\n\n## Usage\n\n```bash\nskillscan review /path/to/skill --format markdown\nskillscan review /path/to/skills --output-dir ./results\n```\n\n## What It Checks\n\n- Malware patterns (curl/wget to unknown URLs, obfuscated code)\n- Credential theft (reads ~/.ssh, ~/.aws, requests tokens)\n- Suspicious permissions (elevated access, system file modifications)\n- Data exfiltration risks\n\n## License\n\nMIT-0 (Public Domain). Source: https://gitee.com/cyzlmh/cmic-skill-scanner\n\nFile v0.6.2:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.6.2\",\n  \"publishedAt\": 1776760963268\n}\n\nFile v0.6.2:INSTALL.md\n\n# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n4. If you want to use an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill\n./assets/bin/skillscan scan /path/to/skill\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan benchmark\n./assets/bin/skillscan package-skill\n```\n\nFile v0.6.2:assets/build/build-info.json\n\n{\n  \"version\": \"v0.6.2\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1776760935,\n  \"checksum\": \"3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130\"\n}\n\nFile v0.6.2:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: 用内置 Rust 引擎审计待安装的 skill 包，并可选桥接外部 scanner。\ndefault_prompt: 审计这个本地 skill 目标，输出 engine findings、风险等级和简短安装结论。\n\nArchive v0.6.1: 5 files, 2440 bytes\n\nFiles: agents/openai.yaml (241b), assets/build/build-info.json (219b), INSTALL.md (1222b), SKILL.md (1520b), _meta.json (150b)\n\nFile v0.6.1:SKILL.md\n\n---\nname: cmic-skill-scanner\nversion: 0.6.1\ndescription: Security audit tool for AI agent skills. Self-contained package with binary included - no external download needed. Scans for malware, credential theft, and suspicious patterns before installation.\nlicense: MIT-0\nmetadata:\n  author: cyzlmh\n  tags:\n    - security\n    - scanner\n    - audit\n    - skill-security\n  triggers:\n    - \"scan this skill\"\n    - \"audit skill before install\"\n---\n\n# CMIC Skill Scanner\n\n**DEFENSIVE SECURITY TOOL** - Audit skills before installation.\n\n## Built-in Binary\n\n- Path: `assets/bin/skillscan`\n- Version: `v0.6.1`\n- Platform: `darwin-arm64`\n- SHA-256: `3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130`\n\n\n## Pure Version (external download)\n\nFor other platforms or to download separately:\nhttps://clawhub.ai/cyzlmh/cmic-skill-scanner\n\n## Usage\n\n```bash\n# Review a skill package or directory\nskillscan review /path/to/skill --format markdown\n\n# Scan multiple skills and save results\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n\n# Use external engine (requires skill-scanner CLI installed)\nskillscan review /path/to/skill --engine external --format markdown\n```\n\n## Output\n\n- Input type detection\n- Engine execution status\n- Security findings with risk levels\n- Recommendations\n\n## Enterprise Integration\n\n```bash\nskillscan review /path/to/skills   --output-dir /tmp/skillscan-out   --upload-url https://scanner.example.com/api/report   --instance-id prod-a1\n```\n\n## License\n\nMIT-0 (Public Domain)\n\nFile v0.6.1:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.6.1\",\n  \"publishedAt\": 1776759622544\n}\n\nFile v0.6.1:INSTALL.md\n\n# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n4. If you want to use an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill\n./assets/bin/skillscan scan /path/to/skill\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan benchmark\n./assets/bin/skillscan package-skill\n```\n\nFile v0.6.1:assets/build/build-info.json\n\n{\n  \"version\": \"v0.6.1\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1776759593,\n  \"checksum\": \"3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130\"\n}\n\nFile v0.6.1:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: 用内置 Rust 引擎审计待安装的 skill 包，并可选桥接外部 scanner。\ndefault_prompt: 审计这个本地 skill 目标，输出 engine findings、风险等级和简短安装结论。\n\nArchive v0.6.0: 5 files, 2666 bytes\n\nFiles: agents/openai.yaml (241b), assets/build/build-info.json (219b), INSTALL.md (1222b), SKILL.md (1715b), _meta.json (150b)\n\nFile v0.6.0:SKILL.md\n\n---\nname: cmic-skill-scanner\ndescription: Security audit tool for AI agent skills. Self-contained package with binary included - no external download needed. Scans for malware, credential theft, and suspicious patterns before installation.\nlicense: MIT\nauthor: CMIC Skill Scanner\n---\n\n# CMIC Skill Scanner\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## 内置二进制\n\n- 路径: `assets/bin/skillscan`\n- 版本: `v0.6.0`\n- 平台: `darwin/arm64`\n- SHA-256: `3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130`\n\n## 前置条件\n\n- 默认不需要任何外部依赖\n- 如果要桥接外部 scanner，再额外提供 `--engine external` 或 `--engine auto`\n\n## 工作流程\n\n1. 调用 wrapper：\n\n```bash\n./assets/bin/skillscan review /path/to/target --format markdown\n./assets/bin/skillscan review /path/to/target --engine external --format markdown\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：\n   - 输入类型\n   - 完整度\n   - engine 执行状态\n   - findings\n\n3. 如果输入只是 HTML 页面或其他非 scanner-ready 形式，先获取完整本地包再重试。\n\n## 企业集成\n\n如果要扫描一个目录下的全部 skill，并把结果落盘：\n\n```bash\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n如果还要上报：\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\n上报内容包含每个 skill 的完整 `review` 详情，而不是仅上传本地结果文件路径。\n\nFile v0.6.0:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.6.0\",\n  \"publishedAt\": 1776758035083\n}\n\nFile v0.6.0:INSTALL.md\n\n# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n4. If you want to use an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill\n./assets/bin/skillscan scan /path/to/skill\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan benchmark\n./assets/bin/skillscan package-skill\n```\n\nFile v0.6.0:assets/build/build-info.json\n\n{\n  \"version\": \"v0.6.0\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1776758008,\n  \"checksum\": \"3d0e50040dbcb8e9ffa24433587796f61f3c94926ee7e8a87b3359b9e2ae1130\"\n}\n\nFile v0.6.0:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: 用内置 Rust 引擎审计待安装的 skill 包，并可选桥接外部 scanner。\ndefault_prompt: 审计这个本地 skill 目标，输出 engine findings、风险等级和简短安装结论。\n\nArchive v0.2.0: 5 files, 3644 bytes\n\nFiles: agents/openai.yaml (262b), assets/build/build-info.json (219b), INSTALL.md (1230b), SKILL.md (4447b), _meta.json (150b)\n\nFile v0.2.0:SKILL.md\n\n---\nname: cmic-skill-scanner\nversion: 0.2.0\ndescription: Security audit tool for AI agent skills. Scans skill packages for malware, credential theft, and suspicious patterns before installation. Defensive security tool with optional enterprise reporting (user-controlled destination).\nlicense: MIT-0\nplatform: darwin-arm64\nmetadata:\n  author: cyzlmh\n  tags:\n    - security\n    - scanner\n    - audit\n    - skill-security\n    - malware-detection\n  triggers:\n    - \"scan this skill\"\n    - \"audit skill before install\"\n    - \"check skill security\"\n    - \"review skill package\"\n  permissions:\n    network: \"optional - only for enterprise reporting (--upload-url) or external scanner (--engine external), both user-controlled\"\n    files_read: \"skill directories being scanned, no user credentials or identity files\"\n    files_write: \"optional output directory (--output-dir), user-specified only\"\n---\n\n# CMIC Skill Scanner\n\n**DEFENSIVE SECURITY TOOL** - Use this skill to audit other skills before installation.\n\nThis package includes a native Rust binary scanner. No external downloads required.\n\n## Package Contents\n\n| File | Purpose |\n|------|---------|\n| `assets/bin/skillscan` | Native Rust scanner binary |\n| `assets/build/skillscan.sha256` | Binary checksum for verification |\n| `assets/build/build-info.json` | Build metadata (version, platform, checksum) |\n\n## Security Guarantees\n\nThis tool **DOES NOT**:\n- Read your credentials, SSH keys, AWS configs, or any identity files\n- Access MEMORY.md, USER.md, SOUL.md, or agent identity files\n- Send data anywhere without your explicit command\n- Modify system files outside your specified workspace\n- Request elevated/sudo permissions\n\nThis tool **ONLY**:\n- Reads skill files you explicitly ask it to scan\n- Writes reports to directories you explicitly specify\n- Optionally sends reports to URLs you explicitly provide (enterprise integration)\n- Uses SHA-256 checksums to verify integrity\n\n## Verify Before Running\n\nThe binary checksum is provided in `assets/build/skillscan.sha256`. Verify independently:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n# Should match: f2cc115a3675b493425f9a2be94e02d31c3ee523f12765cd8a30fc240c9a0b30\n```\n\n## Source Transparency\n\nSource code available for independent verification:\n- **Gitee**: https://gitee.com/random_player/cmic-skill-scanner\n- **Build from source**: `cargo build --release` (see repo README for reproducible build instructions)\n- **Checksum file in repo**: `releases/v0.4.0/SHA256SUMS` (independently published)\n\nNote: Binary reports version `0.2.0` internally. Package version tracks the overall release (v0.4.0 on Gitee).\n\n## Usage\n\n### Single Skill Scan\n\n```bash\n./assets/bin/skillscan review /path/to/skill --format markdown\n```\n\n### Batch Scan\n\n```bash\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n### External Engine (Optional)\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external --format markdown\n```\n\n### Enterprise Integration (User Controlled)\n\n**Network upload only happens when YOU explicitly provide `--upload-url`. You control the destination.**\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://your-company.example.com/api/report \\\n  --instance-id prod-a1\n```\n\n## Common Commands\n\n```bash\n./assets/bin/skillscan inspect /path/to/skill    # View skill structure\n./assets/bin/skillscan scan /path/to/skill       # Raw JSON scan result\n./assets/bin/skillscan review /path/to/skill     # Risk rating summary\n./assets/bin/skillscan benchmark                 # Performance benchmark\n```\n\n## Detection Capabilities\n\nNative engine includes 31 detection rules covering:\n\n- Sensitive file access (credential files, private keys)\n- Network operations (DNS exfiltration, tool downloads)\n- Code injection risks (eval, exec patterns)\n- Unicode steganography detection\n- Process manipulation (shell spawn, process control)\n\n## Other Platforms\n\nThis package contains macOS ARM64 binary. For other platforms:\n- **Linux x64**: https://gitee.com/random_player/cmic-skill-scanner/releases/download/v0.4.0/skillscan-wrapper-linux-amd64-v0.4.0.zip\n- **Linux ARM64**: https://gitee.com/random_player/cmic-skill-scanner/releases/download/v0.4.0/skillscan-wrapper-linux-arm64-v0.4.0.zip\n\nVerify checksums from the repo's `SHA256SUMS` file (not from this document).\n\n## License\n\nMIT-0 (Public Domain)\n\nFile v0.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.2.0\",\n  \"publishedAt\": 1776748713536\n}\n\nFile v0.2.0:INSTALL.md\n\n# Install\n\n## Self-Contained Package\n\nThis skill package is self-contained - no external downloads required. The binary is included.\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Binary checksum: `assets/build/skillscan.sha256`\n- Build metadata: `assets/build/build-info.json`\n- Skill definition: `SKILL.md`\n\n## Verify Binary Integrity\n\nBefore running, verify the included binary against its checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\nExpected checksum: `f2cc115a3675b493425f9a2be94e02d31c3ee523f12765cd8a30fc240c9a0b30`\n\nFor independent verification, check the repo's published checksums:\nhttps://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.4.0/SHA256SUMS\n\n## Run\n\n```bash\n./assets/bin/skillscan review /path/to/skill --format markdown\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n## Enterprise Integration\n\nOnly use `--upload-url` if you have a trusted internal endpoint:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://your-internal-server.example.com/api/report \\\n  --instance-id prod-a1\n```\n\n**Never send scan results to untrusted URLs.**\n\nFile v0.2.0:assets/build/build-info.json\n\n{\n  \"version\": \"v0.4.0\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1776739652,\n  \"checksum\": \"f2cc115a3675b493425f9a2be94e02d31c3ee523f12765cd8a30fc240c9a0b30\"\n}\n\nFile v0.2.0:agents/openai.yaml\n\ndisplay_name: Skill Scan\nshort_description: Audit skill packages for malware, credential theft, and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output engine findings, risk level, and brief installation recommendation.","readmeExcerpt":"Skill: CMIC Skill Scanner (macOS ARM64) Owner: cyzlmh Summary: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。 Tags: latest:0.11.1 Version history: v0.11.1 | 2026-07-27T06:42:54.715Z | auto cmic-skill-scanner-darwin-arm64 v0.11.1 - Updated bundled binary to version v0.11.1 with new SHA-256 checksum in documentation and build info. - Updated references in documentation to match the new binary version. - ","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"sha256sum assets/bin/skillscan\n# Compare output with the SHA-256 value above"},{"language":"bash","snippet":"git clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release"},{"language":"bash","snippet":"skillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out"},{"language":"bash","snippet":"skillscan review /path/to/target --engine native --use-llm   --llm-endpoint http://localhost:11434/v1   --llm-model your-model"},{"language":"bash","snippet":"shasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256"},{"language":"bash","snippet":"./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: skillscan-wrapper\ndescription: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool scans locally by default and requires user trust in the binary you run. Native LLM review sends a bounded text packet to a user-configured endpoint; external LLM review follows the external scanner's data policy. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Binary Included\n\n| Property | Value |\n|----------|-------|\n| Location | `assets/bin/skillscan` |\n| Version | `v0.11.1` |\n| Platform | `macOS ARM64` |\n| SHA-256 | `d2a61ad62a168f468205319bfd065d06f8aea34ff5fec37faab9d41435a56f73` |\n\n**Verify locally before running:**\n```bash\nsha256sum assets/bin/skillscan\n# Compare output with the SHA-256 value above\n```\n\nThis bundled package includes a pre-compiled binary. You can still build from source if you prefer:\n\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认 `auto` 模式会优先尝试本地可解析的 external scanner；没有可用 scanner 时回退到内置 native 引擎\n- 不安装 external scanner 也可以使用：单二进制会回退到 native\n- `--upload-url` 和 `--use-llm` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**Default behavior and trust boundaries:**\n- CMIC does NOT upload reports unless you configure `--upload-url`\n- CMIC does NOT configure an LLM endpoint unless you set `--use-llm`\n- `auto` may execute a locally resolved external scanner; use `--engine native` to prevent that\n- Does NOT access credentials or SSH configs as scan targets unless they are under the path you explicitly scan\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\nThis applies to report upload only. LLM review is a separate, explicit network feature; a resolved external scanner has its own dependency and network behavior.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## Optional LLM Review\n\n**⚠️ This feature is completely optional an"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner-darwin-arm64\",\n  \"version\": \"0.11.1\",\n  \"publishedAt\": 1785134574715\n}"},{"path":"INSTALL.md","content":"# Install\n\n## Package Contents\n\n- Binary: `assets/bin/skillscan`\n- Skill document: `SKILL.md`\n- Build metadata: `assets/build/build-info.json`\n- SHA-256: `assets/build/skillscan.sha256`\n\n## Install Steps\n\n1. Unzip the release package.\n2. Optionally verify the checksum:\n\n```bash\nshasum -a 256 assets/bin/skillscan\ncat assets/build/skillscan.sha256\n```\n\n3. Run the binary directly:\n\n```bash\n./assets/bin/skillscan review /path/to/skill\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\nThe default engine is `auto`: it prefers a locally resolved external scanner and falls back to the built-in native engine if the external scanner is unavailable or fails. Use `--engine native` to run only the built-in engine.\n\n4. If you want to require an external scanner bridge:\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine external\n```\n\n5. To opt into LLM semantic review, configure a trusted OpenAI-compatible endpoint. `native`, `external`, and `auto` all support `--use-llm`; external scanners must support the Cisco-compatible `--use-llm` contract.\n\n```bash\n./assets/bin/skillscan review /path/to/skill --engine native --use-llm \\\n  --llm-endpoint http://localhost:11434/v1 \\\n  --llm-model your-model\n```\n\nWith `native`, this sends a bounded, basically redacted text packet from the target package to that endpoint. If the LLM is unavailable, the native static result still returns and records `engine.fallback_reason`.\n\nFor `external`, CMIC adds `--use-llm` and passes the endpoint, model, and optional key through\n`SKILL_SCANNER_LLM_BASE_URL`, `SKILL_SCANNER_LLM_MODEL`, and `SKILL_SCANNER_LLM_API_KEY` only to the child\nprocess. The external scanner controls its own data packet and failure handling; `auto` falls back to native if\nthe external process fails.\n\n6. For batch review in enterprise environments:\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\nThe upload payload contains embedded review details for each skill, including the full scan summary and findings.\n\n## Linux glibc Compatibility\n\nThere are two x86_64 Linux builds. Pick the right one **before** downloading:\n\n| Package | Target systems | Requirement |\n|---------|---------------|-------------|\n| `linux-amd64` | Ubuntu 20.04+, Debian 11+, RHEL 9+, Fedora 31+ | glibc >= 2.30 |\n| `bclinux21-amd64` | BCLinux 21/8.2, CentOS 7/8, RHEL 7/8, Amazon Linux 2 | none (static musl) |\n\nCheck your glibc version first:\n\n```bash\nldd --version | head -1          # glibc < 2.30  -> use bclinux21-amd64\ncat /etc/os-release | grep -i \"bclinux\\|bigcloud\"   # matches -> use bclinux21-amd64\n```\n\nIf you run `linux-amd64` and see `version 'GLIBC_2.30' not found` (or similar),\nyour glibc is too old — switch to the `bclinux21-amd64` package, which is\nstatically linked with musl and does not depend on the system glibc.\n\n## Common Commands\n\n```bash\n./assets/bin/skillsca"},{"path":"skill-card.md","content":"## Description:\n\nAudits local skill packages or archives with auto, native, or external scanner engines, with optional LLM semantic analysis.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[cyzlmh](https://clawhub.ai/user/cyzlmh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and security reviewers use this skill to run pre-install checks on local skill packages, archives, or release bundles and review findings before installation.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Package integrity is inconsistent because the advertised executable and checksum are missing and the fallback source build is unpinned.\n\nMitigation: Obtain and verify the missing binary and checksum from a trusted release, or build from a pinned and reviewed source revision before installation.\n\nRisk: The auto engine may invoke a locally resolved external scanner with the current user's permissions.\n\nMitigation: Use --engine native unless the external scanner and its configuration are trusted.\n\nRisk: Optional upload or LLM review can send reports or sampled target text to configured endpoints.\n\nMitigation: Enable --upload-url or --use-llm only with trusted endpoints after reviewing their data-handling expectations.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner-darwin-arm64)\n- [Install guide](artifact/INSTALL.md)\n- [Build metadata](artifact/assets/build/build-info.json)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown guidance with shell command examples and scan-result summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May generate local report files when --output-dir is used.]\n\n## Skill Version(s):\n\n0.11.1 (source: server release metadata; binary build-info reports v0.11.1)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"assets/build/build-info.json","content":"{\n  \"version\": \"v0.11.1\",\n  \"target_os\": \"darwin\",\n  \"target_arch\": \"arm64\",\n  \"binary_name\": \"skillscan\",\n  \"built_at_unix\": 1785134483,\n  \"checksum\": \"d2a61ad62a168f468205319bfd065d06f8aea34ff5fec37faab9d41435a56f73\"\n}"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1759,"uniquenessScore":39,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T11:08:05.731Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T11:08:05.731Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T13:42:18.605Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}