{"id":"5ed45f12-60f1-451a-8a4a-c3d3e039e812","entityType":"agent","slug":"clawhub-cyzlmh-cmic-skill-scanner","name":"CMIC Skill Scanner","canonicalUrl":"https://www.xpersona.co/agent/clawhub-cyzlmh-cmic-skill-scanner","canonicalPath":"/agent/clawhub-cyzlmh-cmic-skill-scanner","generatedAt":"2026-10-10T10:44:15.725Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:02:56.004Z","emptyReason":null},"description":"使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner","sourceUrl":"https://clawhub.ai/cyzlmh/cmic-skill-scanner","homepage":"https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/cyzlmh/cmic-skill-scanner","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":64,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"CMIC Skill Scanner technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:02:56.004Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:02:56.004Z","emptyReason":null},"stars":null,"forks":null,"downloads":1573,"packageName":null,"latestVersion":"0.11.1","tractionLabel":"1.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:02:56.003Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T08:02:56.004Z","lastCrawledAt":"2026-10-10T08:02:56.003Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T08:02:56.003Z","lastVerifiedAt":null,"highlights":[{"version":"0.11.1","createdAt":"2026-07-27T06:42:46.293Z","changelog":"- Updated reference checksum filename and links in documentation from v0.11.0 to v0.11.1 for consistency with the new release. - Removed deprecated file: skill-card.md.","fileCount":4,"zipByteSize":4566},{"version":"0.11.0","createdAt":"2026-07-14T08:41:58.684Z","changelog":"- Added support for auto, native, and external scan engines, with auto mode preferring an external scanner if available. - Introduced optional LLM semantic review enabled via `--use-llm` for both native and external engines. - Updated documentation for LLM integration, redaction behavior, and native/external/auto engine modes. - Clarified security notice, trust boundaries, and explicit opt-in for network and LLM features. - Updated SHA256SUMS reference to v0.11.0; removed outdated skill-card.md file.","fileCount":4,"zipByteSize":4618},{"version":"0.9.0","createdAt":"2026-05-28T10:04:10.507Z","changelog":"- Updated Gitee Releases SHA256SUMS reference and links from v0.8.0 to v0.9.0 in documentation. - No functional or usage changes; documentation only.","fileCount":4,"zipByteSize":3537},{"version":"0.8.0","createdAt":"2026-04-21T17:31:57.764Z","changelog":"- Documentation updated: SKILL.md rewritten for clarity and brevity. - Emphasizes that this package contains only documentation—no binary is included. - Instructs users to download pre-built binaries or build from source, with direct links to Gitee Releases and verification instructions. - Retains all major feature and security notices, with reorganized information for easier reading. - Removes redundant detailed usage and expands on the trust model and verification steps.","fileCount":3,"zipByteSize":2348},{"version":"0.7.3","createdAt":"2026-04-21T16:27:00.388Z","changelog":"- License identifier in the manifest corrected from \"MIT\" to \"MIT-0\" for accuracy. - Obsolete hardcoded SHA-256 checksum and version removed from verification instructions; users are now directed to check the Gitee Release page for current checksums. - Documentation on verification updated to reduce risk of confusion and ensure users always reference the official checksum source.","fileCount":3,"zipByteSize":3455},{"version":"0.7.2","createdAt":"2026-04-21T16:11:45.368Z","changelog":"- Added explicit security notices about binary trust and mandatory checksum verification. - Documented and strongly recommended building from source for maximum security. - Clarified that network and external engine features are disabled by default and require explicit user configuration. - Expanded verification instructions and warnings for precompiled binaries. - Improved documentation of trust model, feature enablement, and default behaviors for safer usage.","fileCount":3,"zipByteSize":3513},{"version":"0.7.1","createdAt":"2026-04-21T16:01:38.817Z","changelog":"Skillscan-wrapper 0.7.1 removes bundled binaries and updates installation instructions. - The SKILL.md now directs users to download the scanner binary from the Gitee Release page, instead of providing it in the package. - Instructions are added for manual binary verification and execution permission setup. - All references to the internal assets/bin/skillscan path have been replaced with standalone usage (skillscan) in CLI examples. - Clarified that this package is now a documentation/reference wrapper only; no binary is shipped inside.","fileCount":3,"zipByteSize":2786},{"version":"0.7.0","createdAt":"2026-04-21T15:43:13.315Z","changelog":"**Major update with new binary integration and enhanced security workflow** - Replaces previous documentation with new instructions for the `skillscan-wrapper` tool and updates all content. - Introduces an embedded Rust engine binary (`assets/bin/skillscan`, version 0.7.0). - Adds options for bridging to external scanners with `--engine external`. - Details a clearer security model, emphasizing that only scan results are uploaded—never skill source or credentials. - Provides comprehensive usage examples, including enterprise integration and reporting to internal endpoints. - Updates license and attribution fields.","fileCount":3,"zipByteSize":2558}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s171nn815hk3s0ht69bn9d96hn858ye2:cmic-skill-scanner` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/cyzlmh/cmic-skill-scanner before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T10:44:15.724Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-cyzlmh-cmic-skill-scanner/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T08:02:56.004Z","emptyReason":null},"readme":"Skill: CMIC Skill Scanner\n\nOwner: cyzlmh\n\nSummary: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。\n\nTags: latest:0.11.1\n\nVersion history:\n\nv0.11.1 | 2026-07-27T06:42:46.293Z | auto\n\n- Updated reference checksum filename and links in documentation from v0.11.0 to v0.11.1 for consistency with the new release.\n- Removed deprecated file: skill-card.md.\n\nv0.11.0 | 2026-07-14T08:41:58.684Z | auto\n\n- Added support for auto, native, and external scan engines, with auto mode preferring an external scanner if available.\n- Introduced optional LLM semantic review enabled via `--use-llm` for both native and external engines.\n- Updated documentation for LLM integration, redaction behavior, and native/external/auto engine modes.\n- Clarified security notice, trust boundaries, and explicit opt-in for network and LLM features.\n- Updated SHA256SUMS reference to v0.11.0; removed outdated skill-card.md file.\n\nv0.9.0 | 2026-05-28T10:04:10.507Z | auto\n\n- Updated Gitee Releases SHA256SUMS reference and links from v0.8.0 to v0.9.0 in documentation.\n- No functional or usage changes; documentation only.\n\nv0.8.0 | 2026-04-21T17:31:57.764Z | auto\n\n- Documentation updated: SKILL.md rewritten for clarity and brevity.\n- Emphasizes that this package contains only documentation—no binary is included.\n- Instructs users to download pre-built binaries or build from source, with direct links to Gitee Releases and verification instructions.\n- Retains all major feature and security notices, with reorganized information for easier reading.\n- Removes redundant detailed usage and expands on the trust model and verification steps.\n\nv0.7.3 | 2026-04-21T16:27:00.388Z | auto\n\n- License identifier in the manifest corrected from \"MIT\" to \"MIT-0\" for accuracy.\n- Obsolete hardcoded SHA-256 checksum and version removed from verification instructions; users are now directed to check the Gitee Release page for current checksums.\n- Documentation on verification updated to reduce risk of confusion and ensure users always reference the official checksum source.\n\nv0.7.2 | 2026-04-21T16:11:45.368Z | auto\n\n- Added explicit security notices about binary trust and mandatory checksum verification.\n- Documented and strongly recommended building from source for maximum security.\n- Clarified that network and external engine features are disabled by default and require explicit user configuration.\n- Expanded verification instructions and warnings for precompiled binaries.\n- Improved documentation of trust model, feature enablement, and default behaviors for safer usage.\n\nv0.7.1 | 2026-04-21T16:01:38.817Z | auto\n\nSkillscan-wrapper 0.7.1 removes bundled binaries and updates installation instructions.\n\n- The SKILL.md now directs users to download the scanner binary from the Gitee Release page, instead of providing it in the package.\n- Instructions are added for manual binary verification and execution permission setup.\n- All references to the internal assets/bin/skillscan path have been replaced with standalone usage (skillscan) in CLI examples.\n- Clarified that this package is now a documentation/reference wrapper only; no binary is shipped inside.\n\nv0.7.0 | 2026-04-21T15:43:13.315Z | auto\n\n**Major update with new binary integration and enhanced security workflow**\n\n- Replaces previous documentation with new instructions for the `skillscan-wrapper` tool and updates all content.\n- Introduces an embedded Rust engine binary (`assets/bin/skillscan`, version 0.7.0).\n- Adds options for bridging to external scanners with `--engine external`.\n- Details a clearer security model, emphasizing that only scan results are uploaded—never skill source or credentials.\n- Provides comprehensive usage examples, including enterprise integration and reporting to internal endpoints.\n- Updates license and attribution fields.\n\nv0.6.4 | 2026-04-21T10:05:32.622Z | auto\n\n- Updated description for greater clarity and detail about what the scanner analyzes.\n- Expanded and clarified detection categories and examples in the documentation.\n- Removed the explicit permissions section and emphasized that the tool only reads specified source files.\n- Improved and reworded usage instructions and explanations for easier understanding.\n\nv0.6.3 | 2026-04-21T09:37:07.140Z | auto\n\n- Updated documentation in SKILL.md for clarity and scope, emphasizing open-source and release verification.\n- Added details about required permissions: the scanner reads only user-specified local files and does not access credentials or system files.\n- Updated repository and source code links to https://gitee.com/random_player/cmic-skill-scanner.\n- Modified download instructions: binaries now on Gitee Releases with checksum verification.\n- Expanded detection criteria to clarify categories of security checks performed.\n- Version bump to 0.6.3.\n\nv0.6.2 | 2026-04-21T08:42:37.304Z | auto\n\n- Updated description and metadata for clarity and accuracy.\n- Added repository link and clarified that this package does not include a binary file.\n- Provided updated links to platform-specific bundled binaries.\n- Simplified usage instructions and refocused scope on reference/package only.\n- Improved documentation of scanning features and security checks.\n\nv0.6.1 | 2026-04-21T08:20:17.011Z | auto\n\nSummary: Documentation update with new download links and enhanced usage instructions.\n\n- Updated download URLs and checksums for version 0.6.1.\n- Added detailed usage instructions and example commands.\n- Included a new section describing audit output and findings.\n- Provided guidance for enterprise integration and reporting.\n- No changes to core functionality; documentation improvements only.\n\nv0.6.0 | 2026-04-21T07:53:50.248Z | auto\n\n- Updated to version 0.6.0.\n- Download URLs now point to new v0.6.0 releases for all platforms.\n- Checksum verification link updated to v0.6.0 release files.\n\nv0.5.0 | 2026-04-21T07:13:47.454Z | auto\n\n- Updated to version 0.5.0 with new binary download links and checksum references.\n- Simplified documentation by removing installation and usage details from SKILL.md.\n- Reduced metadata tag list and removed some triggers.\n- INSTALL.md file removed.\n\nv0.4.0 | 2026-04-21T05:17:42.267Z | auto\n\n- Major update: switching to a binary-distributed model with required external download and stronger emphasis on verification.\n- Removed assets/build/build-info.json and references to internal binary checksums; installation now relies on official Gitee or bundled releases.\n- SKILL.md, INSTALL.md, and YAML updated to clarify installation steps and security practices, including clear binary download and verification instructions.\n- Added table of official download URLs for multiple platforms; recommends using platform-specific bundles.\n- Enterprise features and detection capabilities remain, but documentation is now more focused and concise.\n- Metadata adjusted: platform is no longer specified in SKILL.md; all platform binaries handled via external download.\n\nv0.2.0 | 2026-04-21T05:13:10.518Z | auto\n\n- Added detailed documentation describing security guarantees, usage instructions, and verification procedures.\n- Clarified permissions and user-controlled options for network access and file outputs.\n- Listed supported platforms and provided links for additional binary downloads.\n- Outlined detection capabilities and scan commands for various audit scenarios.\n- Emphasized source transparency and checksum verification for enhanced trust.\n\nArchive index:\n\nArchive v0.11.1: 4 files, 4566 bytes\n\nFiles: agents/openai.yaml (209b), skill-card.md (2352b), SKILL.md (5582b), _meta.json (138b)\n\nFile v0.11.1:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool scans locally by default and requires user trust in the binary you run. Native LLM review sends a bounded text packet to a user-configured endpoint; external LLM review follows the external scanner's data policy. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Reference Package (No Binary)\n\nThis package contains only documentation. Pre-built binaries are hosted on **Gitee Releases** (open source, verifiable).\n\n**Download from Gitee Releases:**\nhttps://gitee.com/random_player/cmic-skill-scanner/releases\n\n**Verify checksums before running:**\nSee https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.11.1/SHA256SUMS\n\n**Build from source (recommended for maximum security):**\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认 `auto` 模式会优先尝试本地可解析的 external scanner；没有可用 scanner 时回退到内置 native 引擎\n- 不安装 external scanner 也可以使用：单二进制会回退到 native\n- `--upload-url` 和 `--use-llm` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**Default behavior and trust boundaries:**\n- CMIC does NOT upload reports unless you configure `--upload-url`\n- CMIC does NOT configure an LLM endpoint unless you set `--use-llm`\n- `auto` may execute a locally resolved external scanner; use `--engine native` to prevent that\n- Does NOT access credentials or SSH configs as scan targets unless they are under the path you explicitly scan\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\nThis applies to report upload only. LLM review is a separate, explicit network feature; a resolved external scanner has its own dependency and network behavior.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## Optional LLM Review\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit `--use-llm` and works with `native`, `external`, and `auto`.\n\n```bash\nskillscan review /path/to/target --engine native --use-llm   --llm-endpoint http://localhost:11434/v1   --llm-model your-model\n```\n\nWith `native`, the endpoint receives static-finding summaries and up to 24 text files from the target package (up to 8 KiB each and 64 KiB total). Lines named `api_key`, `token`, `password`, `secret`, or `authorization` are redacted at a basic level. This is not a guarantee that all sensitive text is removed: use only a trusted endpoint and confirm the data-handling policy.\n\nWith a Cisco-compatible `external` engine, CMIC adds `--use-llm` and passes endpoint, model, and optional key to the child process through `SKILL_SCANNER_LLM_*` variables; the external scanner controls its own packet, redaction, and failure behavior. `auto` tries that external LLM first and falls back to native if the external process fails. API keys are never written to the scan command or report.\n\nIf the native LLM request fails, the native static result is still returned and `engine.fallback_reason` records the reason.\n\n## 外部引擎集成\n\nDefault `auto` mode tries a locally resolved external scanner first and falls back to native when it is unavailable or fails. Use `--engine external` to require the external result, or `--engine native` to run only the built-in engine.\n\nCMIC passes the target path to a user-configured local tool. The tool runs with the current user's process permissions; trust the external tool and its configuration separately. CMIC only configures the external LLM endpoint when `--use-llm` is explicitly set; the tool may otherwise bootstrap dependencies or use its own network configuration.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary / external tool | To run the selected scanner engine; `auto` may invoke a locally resolved external scanner |\n| Network (optional) | `--upload-url` sends a JSON report; native `--use-llm` sends a bounded text packet; external `--use-llm` follows the external tool's data policy |\n\nFile v0.11.1:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.11.1\",\n  \"publishedAt\": 1785134566293\n}\n\nFile v0.11.1:skill-card.md\n\n## Description:\n\nAudits local skill packages or archives with auto, native, or external scanner engines and can optionally enable LLM-assisted semantic review.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[cyzlmh](https://clawhub.ai/user/cyzlmh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill before installing local skills, archives, or release bundles to review scanner findings and risk level. It helps inspect target files locally by default, with optional configured report upload or LLM review.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Downloaded binaries require trust in the release host and may not match the reviewed source.\n\nMitigation: Build from source when possible, or verify the published SHA-256 checksum before running a binary.\n\nRisk: The default auto engine may execute a locally resolved external scanner with the current user's permissions.\n\nMitigation: Use `--engine native` when you want to prevent external scanner execution.\n\nRisk: Optional LLM review or report upload can send scan data to a configured endpoint.\n\nMitigation: Use `--use-llm` and `--upload-url` only with trusted endpoints and scan only directories intended for inspection.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner)\n- [Gitee Releases](https://gitee.com/random_player/cmic-skill-scanner/releases)\n- [Release SHA256SUMS](https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.11.1/SHA256SUMS)\n- [Gitee Source Repository](https://gitee.com/random_player/cmic-skill-scanner.git)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown reports with inline shell commands and risk findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can write local report files to an output directory; optional upload and LLM review require explicit endpoint configuration.]\n\n## Skill Version(s):\n\n0.11.1 (source: server-resolved release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.11.1:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.\n\nArchive v0.11.0: 4 files, 4618 bytes\n\nFiles: agents/openai.yaml (209b), skill-card.md (2575b), SKILL.md (5582b), _meta.json (138b)\n\nFile v0.11.0:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool scans locally by default and requires user trust in the binary you run. Native LLM review sends a bounded text packet to a user-configured endpoint; external LLM review follows the external scanner's data policy. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Reference Package (No Binary)\n\nThis package contains only documentation. Pre-built binaries are hosted on **Gitee Releases** (open source, verifiable).\n\n**Download from Gitee Releases:**\nhttps://gitee.com/random_player/cmic-skill-scanner/releases\n\n**Verify checksums before running:**\nSee https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.11.0/SHA256SUMS\n\n**Build from source (recommended for maximum security):**\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认 `auto` 模式会优先尝试本地可解析的 external scanner；没有可用 scanner 时回退到内置 native 引擎\n- 不安装 external scanner 也可以使用：单二进制会回退到 native\n- `--upload-url` 和 `--use-llm` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**Default behavior and trust boundaries:**\n- CMIC does NOT upload reports unless you configure `--upload-url`\n- CMIC does NOT configure an LLM endpoint unless you set `--use-llm`\n- `auto` may execute a locally resolved external scanner; use `--engine native` to prevent that\n- Does NOT access credentials or SSH configs as scan targets unless they are under the path you explicitly scan\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\nThis applies to report upload only. LLM review is a separate, explicit network feature; a resolved external scanner has its own dependency and network behavior.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## Optional LLM Review\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit `--use-llm` and works with `native`, `external`, and `auto`.\n\n```bash\nskillscan review /path/to/target --engine native --use-llm   --llm-endpoint http://localhost:11434/v1   --llm-model your-model\n```\n\nWith `native`, the endpoint receives static-finding summaries and up to 24 text files from the target package (up to 8 KiB each and 64 KiB total). Lines named `api_key`, `token`, `password`, `secret`, or `authorization` are redacted at a basic level. This is not a guarantee that all sensitive text is removed: use only a trusted endpoint and confirm the data-handling policy.\n\nWith a Cisco-compatible `external` engine, CMIC adds `--use-llm` and passes endpoint, model, and optional key to the child process through `SKILL_SCANNER_LLM_*` variables; the external scanner controls its own packet, redaction, and failure behavior. `auto` tries that external LLM first and falls back to native if the external process fails. API keys are never written to the scan command or report.\n\nIf the native LLM request fails, the native static result is still returned and `engine.fallback_reason` records the reason.\n\n## 外部引擎集成\n\nDefault `auto` mode tries a locally resolved external scanner first and falls back to native when it is unavailable or fails. Use `--engine external` to require the external result, or `--engine native` to run only the built-in engine.\n\nCMIC passes the target path to a user-configured local tool. The tool runs with the current user's process permissions; trust the external tool and its configuration separately. CMIC only configures the external LLM endpoint when `--use-llm` is explicitly set; the tool may otherwise bootstrap dependencies or use its own network configuration.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary / external tool | To run the selected scanner engine; `auto` may invoke a locally resolved external scanner |\n| Network (optional) | `--upload-url` sends a JSON report; native `--use-llm` sends a bounded text packet; external `--use-llm` follows the external tool's data policy |\n\nFile v0.11.0:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.11.0\",\n  \"publishedAt\": 1784018518684\n}\n\nFile v0.11.0:skill-card.md\n\n## Description: <br>\nAudits local skill packages or archives with auto, native, or external scan engines and can optionally use LLM semantic review. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[cyzlmh](https://clawhub.ai/user/cyzlmh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operators use this skill before installing a local skill package, archive, or release bundle to run a quick security scan and review findings and risk level. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Downloaded or locally resolved scanner binaries require trust in the release host or local tool configuration. <br>\nMitigation: Verify the published SHA-256 checksum before running a binary, or build from source after reviewing the code. <br>\nRisk: Auto mode may invoke a locally resolved external scanner with the current user's permissions. <br>\nMitigation: Use the native engine when external scanner execution is not intended, and review any external scanner configuration before use. <br>\nRisk: Optional upload and LLM review can transmit scan reports or bounded text packets when explicitly enabled. <br>\nMitigation: Keep network features disabled unless needed, use trusted endpoints, and review the target contents and endpoint data policy before enabling them. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill listing](https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner) <br>\n- [Publisher profile](https://clawhub.ai/user/cyzlmh) <br>\n- [Gitee releases](https://gitee.com/random_player/cmic-skill-scanner/releases) <br>\n- [v0.11.0 SHA256SUMS](https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.11.0/SHA256SUMS) <br>\n- [Source repository clone URL](https://gitee.com/random_player/cmic-skill-scanner.git) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and scan-result summaries] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include findings, risk level, engine status, and local report paths when an output directory is requested.] <br>\n\n## Skill Version(s): <br>\n0.11.0 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.11.0:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.\n\nArchive v0.9.0: 4 files, 3537 bytes\n\nFiles: agents/openai.yaml (209b), skill-card.md (2343b), SKILL.md (3251b), _meta.json (137b)\n\nFile v0.9.0:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用内置 Rust 引擎审计待安装的 skill 包或归档，并可选桥接外部 scanner。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool operates **locally** and requires user trust in the binary you run. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Reference Package (No Binary)\n\nThis package contains only documentation. Pre-built binaries are hosted on **Gitee Releases** (open source, verifiable).\n\n**Download from Gitee Releases:**\nhttps://gitee.com/random_player/cmic-skill-scanner/releases\n\n**Verify checksums before running:**\nSee https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.9.0/SHA256SUMS\n\n**Build from source (recommended for maximum security):**\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认不需要任何外部依赖\n- `--upload-url` 和 `--engine external` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**What the tool does NOT do by default:**\n- Does NOT upload data anywhere\n- Does NOT connect to the network\n- Does NOT access credentials, SSH configs, or environment variables\n- Does NOT execute external tools unless you explicitly configure `--engine external`\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## 外部引擎集成 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--engine external`.\n\nDelegates pattern-matching to a user-configured local tool. This runs **locally** — no remote calls are made.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary | To run the scanner engine |\n| Network (optional) | **Only if `--upload-url` is explicitly configured** |\n\nFile v0.9.0:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.9.0\",\n  \"publishedAt\": 1779962650507\n}\n\nFile v0.9.0:skill-card.md\n\n## Description: <br>\nAudits local skill packages or archives with a built-in Rust scanner, with optional delegation to a user-configured external scanner. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[cyzlmh](https://clawhub.ai/user/cyzlmh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill before installing local skills, archives, or release bundles to run a quick local scan and review findings, completeness, and risk level. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The workflow depends on a local scanner binary that must be trusted before execution. <br>\nMitigation: Build from source when possible, or verify the release checksum before running the binary. <br>\nRisk: Optional report upload can send a structured findings report and supplied instance identifier to a configured endpoint. <br>\nMitigation: Leave upload disabled unless the endpoint is intentional and trusted; review the configured upload URL before use. <br>\nRisk: Optional external-engine mode delegates scanning to another local tool. <br>\nMitigation: Enable external-engine mode only for a trusted local scanner and review its configuration before use. <br>\n\n\n## Reference(s): <br>\n- [Gitee Releases](https://gitee.com/random_player/cmic-skill-scanner/releases) <br>\n- [v0.9.0 SHA256SUMS](https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.9.0/SHA256SUMS) <br>\n- [Source Repository](https://gitee.com/random_player/cmic-skill-scanner.git) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, files, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with shell command examples and optional local report files] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Optional report upload and external-engine behavior are disabled unless explicitly configured.] <br>\n\n## Skill Version(s): <br>\n0.9.0 (source: release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.9.0:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.\n\nArchive v0.8.0: 3 files, 2348 bytes\n\nFiles: agents/openai.yaml (209b), SKILL.md (3251b), _meta.json (137b)\n\nFile v0.8.0:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用内置 Rust 引擎审计待安装的 skill 包或归档，并可选桥接外部 scanner。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool operates **locally** and requires user trust in the binary you run. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Reference Package (No Binary)\n\nThis package contains only documentation. Pre-built binaries are hosted on **Gitee Releases** (open source, verifiable).\n\n**Download from Gitee Releases:**\nhttps://gitee.com/random_player/cmic-skill-scanner/releases\n\n**Verify checksums before running:**\nSee https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.8.0/SHA256SUMS\n\n**Build from source (recommended for maximum security):**\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认不需要任何外部依赖\n- `--upload-url` 和 `--engine external` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**What the tool does NOT do by default:**\n- Does NOT upload data anywhere\n- Does NOT connect to the network\n- Does NOT access credentials, SSH configs, or environment variables\n- Does NOT execute external tools unless you explicitly configure `--engine external`\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## 外部引擎集成 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--engine external`.\n\nDelegates pattern-matching to a user-configured local tool. This runs **locally** — no remote calls are made.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary | To run the scanner engine |\n| Network (optional) | **Only if `--upload-url` is explicitly configured** |\n\nFile v0.8.0:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.8.0\",\n  \"publishedAt\": 1776792717764\n}\n\nFile v0.8.0:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.\n\nArchive v0.7.3: 3 files, 3455 bytes\n\nFiles: agents/openai.yaml (209b), SKILL.md (5895b), _meta.json (137b)\n\nFile v0.7.3:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用内置 Rust 引擎审计待安装的 skill 包或归档，并可选桥接外部 scanner。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool operates **locally** and requires user trust in the binary you run. **Always verify the checksum after downloading** (see below). For maximum security, build from source (recommended).\n\n## 安装\n\n### Method 1: Build from Source (Recommended)\n\nThis package is open-source (MIT-0). The recommended way to obtain the binary is to build it yourself, so you can verify every line of code:\n\n```bash\ngit clone https://gitee.com/cmic-team/cmic-skill-scanner.git\ncd cmic-skill-scanner\ncargo build --release\n# Binary will be at: target/release/skillscan\n```\n\nBuilding from source ensures:\n- You can audit all code before execution\n- No reliance on external binary distribution\n- Reproducible builds\n\n### Method 2: Precompiled Binary (Convenience Only)\n\nIf you prefer a prebuilt binary, download from the Gitee Release page:\n\n**下载地址**: https://gitee.com/cmic-team/cmic-skill-scanner/releases\n\n> **⚠️ IMPORTANT: You MUST verify the binary after downloading.** The precompiled binary is provided as a convenience only. By downloading it, you accept the risk of trusting an externally-hosted executable.\n\nDownload the appropriate binary for your platform. On Linux/macOS, make it executable:\n\n```bash\nchmod +x skillscan\n```\n\n## 🔒 Verification (Mandatory for Precompiled Binaries)\n\n**⚠️ VERIFICATION IS MANDATORY.** Skipping this step means you are trusting an arbitrary binary without verification.\n\nAfter downloading, **always** verify the checksum before first use:\n\n```bash\nsha256sum skillscan\n```\n\nCompare the output against the published checksum on the Gitee Release page.\n\n> **If the checksums do not match, DELETE the binary immediately and do not run it.** An mismatched checksum indicates potential tampering.\n\nCheck the Gitee Release page for the **expected SHA-256 checksum** and **version** of the binary you download. Always verify against that official source.\n\n## 前置条件\n\n- 默认不需要任何外部依赖\n- `--upload-url` 和 `--engine external` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) reference package**. The binary download is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Precompiled binary | You trust the release host | SHA-256 checksum |\n\n**What the tool does NOT do by default:**\n- Does NOT upload data anywhere\n- Does NOT connect to the network\n- Does NOT access credentials, SSH configs, or environment variables\n- Does NOT execute external tools unless you explicitly configure `--engine external`\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：\n   - 输入类型\n   - 完整度\n   - engine 执行状态\n   - findings\n\n3. 如果输入只是 HTML 页面或其他非 scanner-ready 形式，先获取完整本地包再重试。\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\n### About --upload-url\n\n**Default behavior**: Disabled. No network calls are made unless you explicitly provide `--upload-url`.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n**Security recommendation**: Only use `--upload-url` with trusted internal infrastructure endpoints.\n\n### About --instance-id\n\nA user-supplied label you choose (e.g., `prod-a1`, `dev-workstation`) for correlating reports across multiple hosts. This is not telemetry — it's a human-readable tag you control entirely. This is only sent if `--upload-url` is configured.\n\n### Example with upload\n\n```bash\nskillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\n## 外部引擎集成 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--engine external`.\n\n### About --engine external\n\n**Default behavior**: Disabled. The built-in Rust engine is used unless you explicitly set `--engine external`.\n\n**How it works**: Delegates pattern-matching to a user-configured local tool already installed on your system (e.g., your company's internal scanner). This runs **locally** — no remote calls are made.\n\n**What it can access**: Only the files that skillscan itself reads (the target skill paths you specified). The external engine cannot expand beyond what skillscan reads.\n\n**Typical use case**: Organizations with custom rule sets or compliance checks that run through their own tooling pipeline.\n\n### Example with external engine\n\n```bash\nskillscan review /path/to/target --engine external --format markdown\n```\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary | To run the scanner engine |\n| Network (optional) | **Only if `--upload-url` is explicitly configured** — sends JSON report only, to user-controlled endpoint |\n\nFile v0.7.3:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.7.3\",\n  \"publishedAt\": 1776788820388\n}\n\nFile v0.7.3:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.\n\nArchive v0.7.2: 3 files, 3513 bytes\n\nFiles: agents/openai.yaml (209b), SKILL.md (5924b), _meta.json (137b)\n\nFile v0.7.2:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用内置 Rust 引擎审计待安装的 skill 包或归档，并可选桥接外部 scanner。\nlicense: MIT\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool operates **locally** and requires user trust in the binary you run. **Always verify the checksum after downloading** (see below). For maximum security, build from source (recommended).\n\n## 安装\n\n### Method 1: Build from Source (Recommended)\n\nThis package is open-source (MIT-0). The recommended way to obtain the binary is to build it yourself, so you can verify every line of code:\n\n```bash\ngit clone https://gitee.com/cmic-team/cmic-skill-scanner.git\ncd cmic-skill-scanner\ncargo build --release\n# Binary will be at: target/release/skillscan\n```\n\nBuilding from source ensures:\n- You can audit all code before execution\n- No reliance on external binary distribution\n- Reproducible builds\n\n### Method 2: Precompiled Binary (Convenience Only)\n\nIf you prefer a prebuilt binary, download from the Gitee Release page:\n\n**下载地址**: https://gitee.com/cmic-team/cmic-skill-scanner/releases\n\n> **⚠️ IMPORTANT: You MUST verify the binary after downloading.** The precompiled binary is provided as a convenience only. By downloading it, you accept the risk of trusting an externally-hosted executable.\n\nDownload the appropriate binary for your platform. On Linux/macOS, make it executable:\n\n```bash\nchmod +x skillscan\n```\n\n## 🔒 Verification (Mandatory for Precompiled Binaries)\n\n**⚠️ VERIFICATION IS MANDATORY.** Skipping this step means you are trusting an arbitrary binary without verification.\n\nAfter downloading, **always** verify the checksum before first use:\n\n```bash\nsha256sum skillscan\n```\n\nCompare the output against the published checksum:\n\n- **Expected SHA-256**: `a3f1e2b4c5d6e7f8a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4`\n- **Version**: `0.7.0`\n\n> **If the checksums do not match, DELETE the binary immediately and do not run it.** An mismatched checksum indicates potential tampering.\n\nThe checksum is published on the Gitee Release page. Always verify against that official source.\n\n## 前置条件\n\n- 默认不需要任何外部依赖\n- `--upload-url` 和 `--engine external` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) reference package**. The binary download is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Precompiled binary | You trust the release host | SHA-256 checksum |\n\n**What the tool does NOT do by default:**\n- Does NOT upload data anywhere\n- Does NOT connect to the network\n- Does NOT access credentials, SSH configs, or environment variables\n- Does NOT execute external tools unless you explicitly configure `--engine external`\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：\n   - 输入类型\n   - 完整度\n   - engine 执行状态\n   - findings\n\n3. 如果输入只是 HTML 页面或其他非 scanner-ready 形式，先获取完整本地包再重试。\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\n### About --upload-url\n\n**Default behavior**: Disabled. No network calls are made unless you explicitly provide `--upload-url`.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n**Security recommendation**: Only use `--upload-url` with trusted internal infrastructure endpoints.\n\n### About --instance-id\n\nA user-supplied label you choose (e.g., `prod-a1`, `dev-workstation`) for correlating reports across multiple hosts. This is not telemetry — it's a human-readable tag you control entirely. This is only sent if `--upload-url` is configured.\n\n### Example with upload\n\n```bash\nskillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\n## 外部引擎集成 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--engine external`.\n\n### About --engine external\n\n**Default behavior**: Disabled. The built-in Rust engine is used unless you explicitly set `--engine external`.\n\n**How it works**: Delegates pattern-matching to a user-configured local tool already installed on your system (e.g., your company's internal scanner). This runs **locally** — no remote calls are made.\n\n**What it can access**: Only the files that skillscan itself reads (the target skill paths you specified). The external engine cannot expand beyond what skillscan reads.\n\n**Typical use case**: Organizations with custom rule sets or compliance checks that run through their own tooling pipeline.\n\n### Example with external engine\n\n```bash\nskillscan review /path/to/target --engine external --format markdown\n```\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary | To run the scanner engine |\n| Network (optional) | **Only if `--upload-url` is explicitly configured** — sends JSON report only, to user-controlled endpoint |\n\nFile v0.7.2:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.7.2\",\n  \"publishedAt\": 1776787905368\n}\n\nFile v0.7.2:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.\n\nArchive v0.7.1: 3 files, 2786 bytes\n\nFiles: agents/openai.yaml (209b), SKILL.md (3926b), _meta.json (137b)\n\nFile v0.7.1:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用内置 Rust 引擎审计待安装的 skill 包或归档，并可选桥接外部 scanner。\nlicense: MIT\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## 安装\n\n此包为纯参考包（不含二进制）。请从 Gitee Release 页面下载对应平台的预编译二进制：\n\n**下载地址**: https://gitee.com/cmic-team/cmic-skill-scanner/releases\n\n下载后确保 `skillscan` 可执行（Linux/macOS 上执行 `chmod +x skillscan`）。\n\n### 验证安装\n\n下载完成后，可通过以下方式验证版本和完整性：\n\n```bash\nskillscan --version\nsha256sum skillscan  # 对比 Gitee Release 页面上的 a3f1e2b4c5d6e7f8a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4\n```\n\n- 版本: `0.7.0`\n- SHA-256: `a3f1e2b4c5d6e7f8a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4`（请以 Gitee Release 页面公布值为准）\n\n## 前置条件\n\n- 默认不需要任何外部依赖\n- 如果要桥接外部 scanner，再额外提供 `--engine external` 或 `--engine auto`\n\n## 安全模型\n\n**本地-only operation**: 二进制只读取用户显式指定的文件路径。它不会访问系统凭据、SSH/AWS 配置文件、环境变量或其他配置文件。\n\n**What is NOT transmitted**: 此工具不会上传 skill 源代码、凭据或系统配置。上传的仅是结构化的扫描结果 JSON 报告。\n\n**What IS transmitted** (when `--upload-url` is used):\n- Structured JSON report containing scan findings (patterns detected, severity, file paths)\n- Instance identifier for multi-host report correlation (user-supplied label, not hardware telemetry)\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/target --engine external --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：\n   - 输入类型\n   - 完整度\n   - engine 执行状态\n   - findings\n\n3. 如果输入只是 HTML 页面或其他非 scanner-ready 形式，先获取完整本地包再重试。\n\n## 企业集成\n\n如果要扫描一个目录下的全部 skill，并把结果落盘：\n\n```bash\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n如果还要上报扫描结果到内部 SIEM/SOC：\n\n```bash\nskillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\n### About --upload-url\n\n**What gets sent**: A structured JSON report containing detection findings (no skill source code, no credentials, no system config)\n\n**About --instance-id**: A user-supplied label you choose (e.g., `prod-a1`, `dev-workstation`) for correlating reports across multiple hosts. This is not telemetry — it's a human-readable tag you control entirely.\n\n**Security recommendation**: Only use `--upload-url` with trusted internal infrastructure endpoints.\n\n### About --engine external\n\n**How it works**: Delegates pattern-matching to a user-configured local tool already installed on the system (e.g., your company's internal scanner). This runs locally — no remote calls are made.\n\n**What it can access**: Only the files that skillscan itself reads (the target skill paths you specified). The external engine cannot expand beyond what skillscan reads.\n\n**Typical use case**: Organizations with custom rule sets or compliance checks that run through their own tooling pipeline.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary | To run the scanner engine |\n| Network (optional) | Only if `--upload-url` is configured — sends JSON report only, to user-controlled endpoint |\n\nFile v0.7.1:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.7.1\",\n  \"publishedAt\": 1776787298817\n}\n\nFile v0.7.1:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.\n\nArchive v0.7.0: 3 files, 2558 bytes\n\nFiles: agents/openai.yaml (209b), SKILL.md (3487b), _meta.json (137b)\n\nFile v0.7.0:SKILL.md\n\n---\nname: skillscan-wrapper\ndescription: 使用内置 Rust 引擎审计待安装的 skill 包或归档，并可选桥接外部 scanner。\nlicense: MIT\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## 内置二进制\n\n- 路径: `assets/bin/skillscan`\n- 版本: `0.7.0`\n- 平台: `darwin/aarch64`\n- SHA-256: `a3f1e2b4c5d6e7f8a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4`\n\n## 前置条件\n\n- 默认不需要任何外部依赖\n- 如果要桥接外部 scanner，再额外提供 `--engine external` 或 `--engine auto`\n\n## 安全模型\n\n**本地-only operation**: 二进制只读取用户显式指定的文件路径。它不会访问系统凭据、SSH/AWS 配置文件、环境变量或其他配置文件。\n\n**What is NOT transmitted**: 此工具不会上传 skill 源代码、凭据或系统配置。上传的仅是结构化的扫描结果 JSON 报告。\n\n**What IS transmitted** (when `--upload-url` is used):\n- Structured JSON report containing scan findings (patterns detected, severity, file paths)\n- Instance identifier for multi-host report correlation (user-supplied label, not hardware telemetry)\n\n## 工作流程\n\n1. 调用 wrapper：\n\n```bash\n./assets/bin/skillscan review /path/to/target --format markdown\n./assets/bin/skillscan review /path/to/target --engine external --format markdown\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：\n   - 输入类型\n   - 完整度\n   - engine 执行状态\n   - findings\n\n3. 如果输入只是 HTML 页面或其他非 scanner-ready 形式，先获取完整本地包再重试。\n\n## 企业集成\n\n如果要扫描一个目录下的全部 skill，并把结果落盘：\n\n```bash\n./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n如果还要上报扫描结果到内部 SIEM/SOC：\n\n```bash\n./assets/bin/skillscan review /path/to/skills \\\n  --output-dir /tmp/skillscan-out \\\n  --upload-url https://scanner.example.com/api/report \\\n  --instance-id prod-a1\n```\n\n### About --upload-url\n\n**What gets sent**: A structured JSON report containing detection findings (no skill source code, no credentials, no system config)\n\n**About --instance-id**: A user-supplied label you choose (e.g., `prod-a1`, `dev-workstation`) for correlating reports across multiple hosts. This is not telemetry — it's a human-readable tag you control entirely.\n\n**Security recommendation**: Only use `--upload-url` with trusted internal infrastructure endpoints.\n\n### About --engine external\n\n**How it works**: Delegates pattern-matching to a user-configured local tool already installed on the system (e.g., your company's internal scanner). This runs locally — no remote calls are made.\n\n**What it can access**: Only the files that skillscan itself reads (the target skill paths you specified). The external engine cannot expand beyond what skillscan reads.\n\n**Typical use case**: Organizations with custom rule sets or compliance checks that run through their own tooling pipeline.\n\n## Permissions Required\n\n| Scope | Reason |\n|-------|--------|\n| Read files in target path | To analyze skill source code for patterns |\n| Write to `--output-dir` | To save scan reports locally |\n| Execute binary | To run the scanner engine |\n| Network (optional) | Only if `--upload-url` is configured — sends JSON report only, to user-controlled endpoint |\n\nFile v0.7.0:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.7.0\",\n  \"publishedAt\": 1776786193315\n}\n\nFile v0.7.0:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.\n\nArchive v0.6.4: 3 files, 1657 bytes\n\nFiles: agents/openai.yaml (209b), SKILL.md (2168b), _meta.json (137b)\n\nFile v0.6.4:SKILL.md\n\n---\nname: cmic-skill-scanner\nversion: 0.6.4\ndescription: Security scanner for AI agent skills. Analyzes skill source code to detect malware patterns, credential theft attempts, and suspicious code. Open source (MIT-0).\nlicense: MIT-0\nmetadata:\n  author: cyzlmh\n  repository: https://gitee.com/random_player/cmic-skill-scanner\n  tags:\n    - security\n    - scanner\n    - audit\n  triggers:\n    - \"scan this skill\"\n    - \"audit skill before install\"\n---\n\n# CMIC Skill Scanner\n\nSecurity scanner that analyzes skill source code before installation.\n\n**Source code**: https://gitee.com/random_player/cmic-skill-scanner\n\n## Reference Package (No Binary)\n\nThis package contains only documentation. Pre-built binaries are hosted on **Gitee Releases** (open source, verifiable).\n\n**Download from Gitee Releases:**\nhttps://gitee.com/cyzlmh/cmic-skill-scanner/releases\n\n**Verify checksums before running:**\nSee https://gitee.com/cyzlmh/cmic-skill-scanner/raw/main/releases/v0.6.0/SHA256SUMS\n\n## Source Code\n\nhttps://gitee.com/cyzlmh/cmic-skill-scanner\n\nClone and build from source for full transparency:\n```bash\ngit clone https://gitee.com/cyzlmh/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## What This Scanner Does\n\nThis tool reads skill source files you specify and reports findings. It analyzes the skill's code, not your system.\n\n## Usage\n\n```bash\nskillscan review /path/to/skill --format markdown\nskillscan review /path/to/skills --output-dir ./results\n```\n\n## What It Detects in Skills\n\n| Category | Suspicious Pattern |\n|----------|-------------------|\n| Network calls | curl/wget to unknown URLs, calls to IP addresses |\n| Obfuscation | base64 decode, eval/exec with external input, minified code |\n| Credential access | skill attempts to read ~/.ssh, ~/.aws, ~/.config |\n| Permission requests | skill requests elevated/sudo, modifies system files |\n| Data exfiltration | skill uploads to external servers, sends credentials |\n\n**Note**: These are patterns the scanner detects IN the skill being analyzed, not actions the scanner performs.\n\n## License\n\nMIT-0 (Public Domain). Full source: https://gitee.com/random_player/cmic-skill-scanner\n\nFile v0.6.4:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.6.4\",\n  \"publishedAt\": 1776765932622\n}\n\nFile v0.6.4:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.\n\nArchive v0.6.3: 3 files, 1641 bytes\n\nFiles: agents/openai.yaml (209b), SKILL.md (2088b), _meta.json (137b)\n\nFile v0.6.3:SKILL.md\n\n---\nname: cmic-skill-scanner\nversion: 0.6.3\ndescription: Security scanner for AI agent skills. Detects malware patterns, credential theft, and suspicious code. Open source (MIT-0), source code on Gitee.\nlicense: MIT-0\nmetadata:\n  author: cyzlmh\n  repository: https://gitee.com/random_player/cmic-skill-scanner\n  permissions:\n    - local-file-read\n  tags:\n    - security\n    - scanner\n    - audit\n  triggers:\n    - \"scan this skill\"\n    - \"audit skill before install\"\n---\n\n# CMIC Skill Scanner\n\nOpen-source security scanner for AI agent skills.\n\n**Source code**: https://gitee.com/random_player/cmic-skill-scanner\n\n## Reference Package (No Binary)\n\nThis package contains only documentation. Pre-built binaries are hosted on **Gitee Releases** (open source, verifiable).\n\n**Download from Gitee Releases:**\nhttps://gitee.com/cyzlmh/cmic-skill-scanner/releases\n\n**Verify checksums before running:**\nSee https://gitee.com/cyzlmh/cmic-skill-scanner/raw/main/releases/v0.6.0/SHA256SUMS\n\n## Source Code\n\nhttps://gitee.com/cyzlmh/cmic-skill-scanner\n\nClone and build from source for full transparency:\n```bash\ngit clone https://gitee.com/cyzlmh/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## Permissions Required\n\nWhen run, this scanner reads local files to analyze them:\n- Skill packages you point it at (your specified paths)\n- Source code files within those skill directories\n\n**It does NOT**: read arbitrary system files, access credentials, or make network calls.\n\n## Usage\n\n```bash\nskillscan review /path/to/skill --format markdown\nskillscan review /path/to/skills --output-dir ./results\n```\n\n## What It Detects\n\n| Category | Examples |\n|----------|----------|\n| Malware patterns | curl/wget to unknown URLs, obfuscated code, base64 decode |\n| Credential theft | reads ~/.ssh, ~/.aws, ~/.config, requests tokens |\n| Suspicious permissions | elevated access, system file modifications |\n| Data exfiltration | uploads to external servers, embeds external URLs |\n\n## License\n\nMIT-0 (Public Domain). Full source: https://gitee.com/random_player/cmic-skill-scanner\n\nFile v0.6.3:_meta.json\n\n{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.6.3\",\n  \"publishedAt\": 1776764227140\n}\n\nFile v0.6.3:agents/openai.yaml\n\ndisplay_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level.","readmeExcerpt":"Skill: CMIC Skill Scanner Owner: cyzlmh Summary: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。 Tags: latest:0.11.1 Version history: v0.11.1 | 2026-07-27T06:42:46.293Z | auto - Updated reference checksum filename and links in documentation from v0.11.0 to v0.11.1 for consistency with the new release. - Removed deprecated file: skill-card.md. v0.11.0 | 2026-07-14T08:41:58.684Z | auto - Added support for","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"git clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release"},{"language":"bash","snippet":"skillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out"},{"language":"bash","snippet":"skillscan review /path/to/target --engine native --use-llm   --llm-endpoint http://localhost:11434/v1   --llm-model your-model"},{"language":"bash","snippet":"git clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release"},{"language":"bash","snippet":"skillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out"},{"language":"bash","snippet":"skillscan review /path/to/target --engine native --use-llm   --llm-endpoint http://localhost:11434/v1   --llm-model your-model"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: skillscan-wrapper\ndescription: 使用 auto、native 或 external 引擎审计待安装的 skill 包或归档，并可选启用 LLM 语义分析。\nlicense: MIT-0\nauthor: CMIC Skill Scanner\n---\n\n# Skill Scan Wrapper\n\n当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时，使用这个 skill。\n\n## ⚠️ Security Notice\n\nThis tool scans locally by default and requires user trust in the binary you run. Native LLM review sends a bounded text packet to a user-configured endpoint; external LLM review follows the external scanner's data policy. **Always verify the checksum after downloading**. For maximum security, build from source (recommended).\n\n## Reference Package (No Binary)\n\nThis package contains only documentation. Pre-built binaries are hosted on **Gitee Releases** (open source, verifiable).\n\n**Download from Gitee Releases:**\nhttps://gitee.com/random_player/cmic-skill-scanner/releases\n\n**Verify checksums before running:**\nSee https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.11.1/SHA256SUMS\n\n**Build from source (recommended for maximum security):**\n```bash\ngit clone https://gitee.com/random_player/cmic-skill-scanner.git\ncd cmic-skill-scanner && cargo build --release\n```\n\n\n## 前置条件\n\n- 默认 `auto` 模式会优先尝试本地可解析的 external scanner；没有可用 scanner 时回退到内置 native 引擎\n- 不安装 external scanner 也可以使用：单二进制会回退到 native\n- `--upload-url` 和 `--use-llm` 功能**默认禁用**，仅在用户显式配置时启用\n\n## 信任模型\n\nThis is an **open-source (MIT-0) package**. The binary (bundled or downloaded) is a **convenience only** — it does not grant any additional trust.\n\n**Your options:**\n\n| Approach | Trust Requirement | Verification |\n|----------|------------------|--------------|\n| Build from source | None (you control everything) | Manual code review |\n| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |\n\n**Default behavior and trust boundaries:**\n- CMIC does NOT upload reports unless you configure `--upload-url`\n- CMIC does NOT configure an LLM endpoint unless you set `--use-llm`\n- `auto` may execute a locally resolved external scanner; use `--engine native` to prevent that\n- Does NOT access credentials or SSH configs as scan targets unless they are under the path you explicitly scan\n\n## 工作流程\n\n1. 调用 skillscan：\n\n```bash\nskillscan review /path/to/target --format markdown\nskillscan review /path/to/skills --output-dir /tmp/skillscan-out\n```\n\n2. 阅读输出中的：输入类型、完整度、engine 执行状态、findings\n\n## 网络上传功能 (默认禁用)\n\n**⚠️ This feature is completely optional and disabled by default.** It requires explicit user configuration via `--upload-url`.\n\nThis applies to report upload only. LLM review is a separate, explicit network feature; a resolved external scanner has its own dependency and network behavior.\n\n**What gets sent** (only when you configure `--upload-url`):\n- A structured JSON report containing detection findings\n- An instance identifier you supply via `--instance-id`\n- **No skill source code, credentials, or system configuration is ever transmitted**\n\n## Optional LLM Review\n\n**⚠️ This feature is completely optional and disabled by default."},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7aj9m1ysjv99m3c7zjkj193d822ydj\",\n  \"slug\": \"cmic-skill-scanner\",\n  \"version\": \"0.11.1\",\n  \"publishedAt\": 1785134566293\n}"},{"path":"skill-card.md","content":"## Description:\n\nAudits local skill packages or archives with auto, native, or external scanner engines and can optionally enable LLM-assisted semantic review.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[cyzlmh](https://clawhub.ai/user/cyzlmh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill before installing local skills, archives, or release bundles to review scanner findings and risk level. It helps inspect target files locally by default, with optional configured report upload or LLM review.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Downloaded binaries require trust in the release host and may not match the reviewed source.\n\nMitigation: Build from source when possible, or verify the published SHA-256 checksum before running a binary.\n\nRisk: The default auto engine may execute a locally resolved external scanner with the current user's permissions.\n\nMitigation: Use `--engine native` when you want to prevent external scanner execution.\n\nRisk: Optional LLM review or report upload can send scan data to a configured endpoint.\n\nMitigation: Use `--use-llm` and `--upload-url` only with trusted endpoints and scan only directories intended for inspection.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/cyzlmh/skills/cmic-skill-scanner)\n- [Gitee Releases](https://gitee.com/random_player/cmic-skill-scanner/releases)\n- [Release SHA256SUMS](https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.11.1/SHA256SUMS)\n- [Gitee Source Repository](https://gitee.com/random_player/cmic-skill-scanner.git)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, guidance]\n\n**Output Format:** [Markdown reports with inline shell commands and risk findings]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can write local report files to an output directory; optional upload and LLM review require explicit endpoint configuration.]\n\n## Skill Version(s):\n\n0.11.1 (source: server-resolved release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"agents/openai.yaml","content":"display_name: CMIC Skill Scanner\nshort_description: Audit skill packages for malware and suspicious patterns before installation.\ndefault_prompt: Audit this local skill target, output findings and risk level."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1501,"uniquenessScore":42,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T08:02:56.004Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T08:02:56.004Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T10:44:15.725Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}