{"id":"ed27e988-e51b-4fb8-9eab-8e6b913893e4","entityType":"agent","slug":"clawhub-jinyu12166-qa-security","name":"qa-security","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jinyu12166-qa-security","canonicalPath":"/agent/clawhub-jinyu12166-qa-security","generatedAt":"2026-10-10T03:52:35.828Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T22:00:51.837Z","emptyReason":null},"description":"Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification. Skill: qa-security Owner: jinyu12166 Summary: Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification. Tags: latest:1.0.27 Version history: v1.0.27 | 2026-07-28T12:48:07.412Z | user Version 1.1.0 - Switched to official clawtip wallet for payment processing. - Removed all references and data transmission to api.i","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17bk5y82fk590863n8fb20zvn8afqra:qa-security","sourceUrl":"https://clawhub.ai/jinyu12166/qa-security","homepage":"https://clawhub.ai/jinyu12166/skills/qa-security","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jinyu12166/qa-security","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jinyu12166/skills/qa-security","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":66,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verificati"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:00:51.837Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:00:51.837Z","emptyReason":null},"stars":null,"forks":null,"downloads":1950,"packageName":null,"latestVersion":"1.0.27","tractionLabel":"2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T22:00:51.837Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T22:00:51.837Z","lastCrawledAt":"2026-10-09T22:00:51.837Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T22:00:51.837Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.27","createdAt":"2026-07-28T12:48:07.412Z","changelog":"Version 1.1.0 - Switched to official clawtip wallet for payment processing. - Removed all references and data transmission to api.ideaidea.com.cn. - Updated workflow section for clarity and accuracy. - Added environment variable requirements and setup instructions. - Added scripts/sm4_utils.py; removed skill-card.md.","fileCount":7,"zipByteSize":8283},{"version":"1.0.26","createdAt":"2026-07-28T12:03:33.822Z","changelog":"Version 1.1.0 - Switched to the official clawtip wallet for payment; removed all references and network calls to api.ideaidea.com.cn. - Updated workflow in SKILL.md to align with official clawtip usage, including required environment variables and precise integration instructions. - Removed payment flow dependencies on skill-card.md and deprecated scripts. - Added scripts/sm4_utils.py for local encryption support. - Clarified that no remote HTTP requests are made except via the official clawtip wallet.","fileCount":7,"zipByteSize":8061},{"version":"1.0.25","createdAt":"2026-07-28T08:18:16.319Z","changelog":"- Updated service and data handling description for accuracy and clarity (per ClawHub audit) - Streamlined SKILL.md: removed excessive stdout fields, focused on required outputs only - Made workflow for order creation, payment, and service execution more explicit and concise - Added clear data flow and privacy disclosures - Bumped version to 1.0.24","fileCount":6,"zipByteSize":7133},{"version":"1.0.23","createdAt":"2026-07-26T10:26:01.606Z","changelog":"- Removed: skill-card.md file. - Added: scripts/__pycache__/file_utils.cpython-311.pyc (compiled Python file). - No user-facing logic or documentation changes in SKILL.md. - Internal file structure updated; functionality is unchanged.","fileCount":6,"zipByteSize":8609},{"version":"1.0.22","createdAt":"2026-07-26T09:30:17.817Z","changelog":"- Removed outdated documentation file skill-card.md. - Added Python bytecode cache file scripts/__pycache__/file_utils.cpython-311.pyc. - Updated privacy language in SKILL.md for greater clarity about payment credential transmission. - No functional changes to code or workflow.","fileCount":6,"zipByteSize":8572},{"version":"1.0.21","createdAt":"2026-07-21T13:57:59.784Z","changelog":"- Removed the file skill-card.md. - Added a workflow section to SKILL.md, detailing scripts and their arguments for create_order, pay, and service. - No other functional or content changes.","fileCount":6,"zipByteSize":8560},{"version":"1.0.20","createdAt":"2026-07-21T13:42:07.603Z","changelog":"- Added a workflow section to SKILL.md specifying the step-by-step order creation, payment verification, and service execution process. - No longer includes the skill-card.md file. - No user-facing functionality changes; metadata and documentation improved for integration clarity.","fileCount":6,"zipByteSize":8591},{"version":"1.0.19","createdAt":"2026-07-21T10:30:58.178Z","changelog":"- Clarified data transmission scope: user question text and encrypted payment credentials are now transmitted during order creation, with added user notification before transmission. - Updated documentation to reflect these privacy changes and improved process transparency. - Removed the skill-card.md file.","fileCount":6,"zipByteSize":8288}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17bk5y82fk590863n8fb20zvn8afqra:qa-security","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T03:52:35.827Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-qa-security/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T22:00:51.837Z","emptyReason":null},"readme":"Skill: qa-security\n\nOwner: jinyu12166\n\nSummary: Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification.\n\nTags: latest:1.0.27\n\nVersion history:\n\nv1.0.27 | 2026-07-28T12:48:07.412Z | user\n\nVersion 1.1.0\n\n- Switched to official clawtip wallet for payment processing.\n- Removed all references and data transmission to api.ideaidea.com.cn.\n- Updated workflow section for clarity and accuracy.\n- Added environment variable requirements and setup instructions.\n- Added scripts/sm4_utils.py; removed skill-card.md.\n\nv1.0.26 | 2026-07-28T12:03:33.822Z | user\n\nVersion 1.1.0\n\n- Switched to the official clawtip wallet for payment; removed all references and network calls to api.ideaidea.com.cn.\n- Updated workflow in SKILL.md to align with official clawtip usage, including required environment variables and precise integration instructions.\n- Removed payment flow dependencies on skill-card.md and deprecated scripts.\n- Added scripts/sm4_utils.py for local encryption support.\n- Clarified that no remote HTTP requests are made except via the official clawtip wallet.\n\nv1.0.25 | 2026-07-28T08:18:16.319Z | user\n\n- Updated service and data handling description for accuracy and clarity (per ClawHub audit)\n- Streamlined SKILL.md: removed excessive stdout fields, focused on required outputs only\n- Made workflow for order creation, payment, and service execution more explicit and concise\n- Added clear data flow and privacy disclosures\n- Bumped version to 1.0.24\n\nv1.0.23 | 2026-07-26T10:26:01.606Z | user\n\n- Removed: skill-card.md file.\n- Added: scripts/__pycache__/file_utils.cpython-311.pyc (compiled Python file).\n- No user-facing logic or documentation changes in SKILL.md.\n- Internal file structure updated; functionality is unchanged.\n\nv1.0.22 | 2026-07-26T09:30:17.817Z | user\n\n- Removed outdated documentation file skill-card.md.\n- Added Python bytecode cache file scripts/__pycache__/file_utils.cpython-311.pyc.\n- Updated privacy language in SKILL.md for greater clarity about payment credential transmission.\n- No functional changes to code or workflow.\n\nv1.0.21 | 2026-07-21T13:57:59.784Z | user\n\n- Removed the file skill-card.md.\n- Added a workflow section to SKILL.md, detailing scripts and their arguments for create_order, pay, and service.\n- No other functional or content changes.\n\nv1.0.20 | 2026-07-21T13:42:07.603Z | user\n\n- Added a workflow section to SKILL.md specifying the step-by-step order creation, payment verification, and service execution process.\n- No longer includes the skill-card.md file.\n- No user-facing functionality changes; metadata and documentation improved for integration clarity.\n\nv1.0.19 | 2026-07-21T10:30:58.178Z | user\n\n- Clarified data transmission scope: user question text and encrypted payment credentials are now transmitted during order creation, with added user notification before transmission.\n- Updated documentation to reflect these privacy changes and improved process transparency.\n- Removed the skill-card.md file.\n\nv1.0.18 | 2026-07-20T15:52:47.106Z | user\n\n- SKILL.md was completely restructured: now features clear, capability-oriented service descriptions.\n- Clarified all analysis is performed locally; only order metadata (not source code or sensitive data) is transmitted for third-party verification.\n- Expanded details on vulnerability scanning, dependency security analysis, best practice reviews, and security-focused test strategy design.\n- Updated privacy and data handling statements for better transparency.\n- Removed the sample skill-card.md file.\n\nv1.0.17 | 2026-07-20T09:56:31.742Z | user\n\n- Removed the file: skill-card.md.\n- Expanded SKILL.md \"description\" field to mention payment flow and local storage behavior in both Chinese and English.\n- Added a note in \"Data Handling\" clarifying that user question text—including any embedded code snippets—is transmitted/stored.\n- Minor edits and clarifications in data retention and collection policies.\n- No changes to core functionality or payment workflow.\n\nv1.0.16 | 2026-07-20T09:13:02.898Z | user\n\n- Expanded the description to clarify paid process details and mention local order storage.\n- Updated data handling: clarified that user questions (including code if provided) are transmitted and stored as part of the order.\n- Slightly adjusted the \"Not collected\" list to specify database credentials, API keys, etc., and added notes on question content.\n- No functional changes to code or usage flow.\n\nv1.0.15 | 2026-07-20T08:20:27.482Z | user\n\n- Removed redundant file skill-card.md to streamline the skill package.\n- Updated and clarified documentation in SKILL.md, especially around data handling, user privacy, and clawtip payment workflow.\n- No changes to code logic or features.\n\nv1.0.14 | 2026-07-20T05:29:53.480Z | user\n\n- Removed the file skill-card.md. \n- No changes to core functionality or user workflow.\n\nv1.0.13 | 2026-07-20T02:30:12.427Z | user\n\n- Updated workflow and documentation for improved clarity and precision in payment and service execution stages.\n- Added explicit parameter requirements and output handling for order creation and service scripts.\n- Standardized payment flow to align with clawtip skill integration.\n- Improved error handling instructions for each stage.\n- Removed the sample file: skill-card.md.\n\nv1.0.12 | 2026-07-19T10:34:54.364Z | user\n\n- 移除 skill-card.md 文件，不再提供概要卡片文档。\n- 删除 scripts/service.py，已编译版本已替代源码。\n- 新增 scripts/__pycache__ 目录和相关 .pyc 编译文件（create_order 和 service）。\n- SKILL.md 文档微调，去除\"包含你的思考过程\"要求，其余流程和说明保持不变。\n\nv1.0.11 | 2026-07-19T10:01:22.282Z | user\n\nVersion 1.0.11\n\n- 重写和简化技能说明文档，结构更清晰，强调三阶段付费流程和安全边界\n- 精简和明确服务描述及适用说明\n- 移除 skill-card.md 文件\n- 新增 __pycache__ 下的脚本编译文件（create_order.pyc, service.pyc 等）\n\nv1.0.10 | 2026-07-19T09:26:09.142Z | user\n\nFix: remove auto-open browser; add file write warning; add language note\n\nv1.0.9 | 2026-07-19T07:33:16.057Z | user\n\n- 添加了4个 scripts/__pycache__ 下的 .pyc 文件，增强脚本可用性和兼容性。\n- 移除了 skill-card.md 文件，简化元数据存储。\n- 主要文档（SKILL.md）未发生内容变更。\n\nv1.0.8 | 2026-07-19T07:24:57.660Z | user\n\nFix: use server-hosted QR code (.png); fix image format\n\nv1.0.7 | 2026-07-19T07:10:46.619Z | user\n\nAdd auto QR code display; remove contact-developer step\n\nv1.0.6 | 2026-07-18T10:34:18.623Z | user\n\nRemoved hardcoded QR URLs\n\nv1.0.5 | 2026-07-18T10:07:43.144Z | user\n\nAdded quick QR payment option\n\nv1.0.4 | 2026-07-18T09:42:48.392Z | auto\n\n- 新增 ClawTip 钱包账户缺省时的“快捷扫码直付”支付通道说明，包括微信及支付宝收款码。\n- 优化支付流程，用户可在未注册 ClawTip 的情况下直接扫码付款并提交订单号，提升灵活性。\n- 移除 skill-card.md 文件。\n\nv1.0.3 | 2026-07-18T04:11:55.917Z | auto\n\n- 增强文档安全性和合规说明，明确支付过程中不会上传用户原始需求、代码、数据库信息或日志到服务端。\n- 优化使用流程描述，细化三阶段订单及支付指引，补充了交互和告知场景提示。\n- 更新“适用场景”和“交付范围”，突出验收建议、风险分级和执行指导。\n- 强化安全边界，增加用户敏感信息脱敏和本地文件授权提示。\n- 清理和精简依赖项说明，去除无效或重复内容。\n- 移除 skill-card.md 文件，保持文档一致性。\n\nv1.0.2 | 2026-07-16T14:24:53.710Z | auto\n\n- Updated dependency from mangogen-user-guide to ecosystem-quickstart.\n- Instructions for first-time use and onboarding now reference ecosystem-quickstart.\n- Minor copy changes in usage steps and deliverable scope.\n- No logic or functionality changes.\n\nv1.0.1 | 2026-07-16T14:20:20.331Z | user\n\nAdd requires hint for clawtip-skill and user guide\n\nv1.0.0 | 2026-07-16T11:20:30.013Z | auto\n\nInitial release of qa-security skill.\n\n- Provides paid testing and security audit services for one-time delivery scenarios, including test plans, code reviews, vulnerability checks, and risk assessments.\n- Structured in three payment phases: order creation, payment via clawtip, and post-payment service execution.\n- Supports coverage suggestions, audit checklists, risk reports, pre-launch acceptance, and incident analysis frameworks.\n- Requires outbound network, credential, and filesystem access.\n- All user interactions conducted in Chinese.\n\nArchive index:\n\nArchive v1.0.27: 7 files, 8283 bytes\n\nFiles: scripts/create_order.py (3216b), scripts/file_utils.py (2170b), scripts/service.py (1880b), scripts/sm4_utils.py (3302b), skill-card.md (2219b), SKILL.md (2815b), _meta.json (131b)\n\nFile v1.0.27:SKILL.md\n\n---\nname: \"qa-security\"\nversion: \"1.1.0\"\ndescription: >\n  Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# qa-security\n\n请使用中文与用户交互。\n\n## 技能概述\n\n代码质量审计与安全审查服务，覆盖漏洞识别模式、依赖风险评估、安全最佳实践和测试策略设计。付费服务，通过 clawtip 完成支付验证后由 AI 交付审核结果。\n\n**直接执行：** 如用户已提供带支付凭证的订单号，直接跳到第三阶段。\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥（十六进制，32 字符） |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n\n**失败：** `订单创建失败: <详情>` → 终止工作流。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n> [!CAUTION]\n> 技能名称必须严格等于 `clawtip`，不允许替代。\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n| 字段 | 值 | 说明 |\n|------|-----|------|\n| PAY_STATUS | SUCCESS / ERROR | 支付验证状态 |\n| ERROR_INFO | 错误描述 | 失败时的错误原因 |\n\n---\n\n## 数据处理说明\n\n### 本地存储\n订单元数据保存至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`。\n\n### 远程传输\n本技能不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n### 绝不收集或传输\n源代码、项目文件、凭证或 API 密钥。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 1.1.0 | 2026-07-28 | Switch to official clawtip wallet; remove api.ideaidea.com.cn |\n| 1.0.24 | 2026-07-27 | Fix ClawHub audit |\n| 1.0.1 | 2026-07-20 | Fix payment flow |\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.27:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.27\",\n  \"publishedAt\": 1785242887412\n}\n\nFile v1.0.27:skill-card.md\n\n## Description:\n\nCode quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment with AI-delivered service access via clawtip verification.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jinyu12166](https://clawhub.ai/user/jinyu12166)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use qa-security to request code quality audits, security review guidance, vulnerability pattern analysis, dependency risk assessment, and testing strategy suggestions after completing the clawtip payment workflow.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill uses a paid clawtip workflow with credential access, network permission, persistent local order files, and external payment tooling.\n\nMitigation: Install only when that payment and permission posture is acceptable for the environment, and review the payment flow before use.\n\nRisk: The local payment verification is weak according to the security guidance.\n\nMitigation: Treat payment authorization as low-assurance until the publisher strengthens credential validation and dependency integrity.\n\nRisk: The initial question may contain sensitive project details, source code, or secrets.\n\nMitigation: Avoid including secrets, source code, credentials, or sensitive project information in the initial consultation question.\n\n## Reference(s):\n\n- [qa-security ClawHub skill page](https://clawhub.ai/jinyu12166/skills/qa-security)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, shell commands, configuration]\n\n**Output Format:** [Markdown guidance with shell commands and payment status text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Paid clawtip workflow; order metadata is written locally before service authorization.]\n\n## Skill Version(s):\n\n1.0.27 (source: server release metadata; artifact frontmatter lists 1.1.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.26: 7 files, 8061 bytes\n\nFiles: scripts/create_order.py (2921b), scripts/file_utils.py (2170b), scripts/service.py (1880b), scripts/sm4_utils.py (3302b), skill-card.md (2103b), SKILL.md (2815b), _meta.json (131b)\n\nFile v1.0.26:SKILL.md\n\n---\nname: \"qa-security\"\nversion: \"1.1.0\"\ndescription: >\n  Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# qa-security\n\n请使用中文与用户交互。\n\n## 技能概述\n\n代码质量审计与安全审查服务，覆盖漏洞识别模式、依赖风险评估、安全最佳实践和测试策略设计。付费服务，通过 clawtip 完成支付验证后由 AI 交付审核结果。\n\n**直接执行：** 如用户已提供带支付凭证的订单号，直接跳到第三阶段。\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥（十六进制，32 字符） |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n\n**失败：** `订单创建失败: <详情>` → 终止工作流。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n> [!CAUTION]\n> 技能名称必须严格等于 `clawtip`，不允许替代。\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n| 字段 | 值 | 说明 |\n|------|-----|------|\n| PAY_STATUS | SUCCESS / ERROR | 支付验证状态 |\n| ERROR_INFO | 错误描述 | 失败时的错误原因 |\n\n---\n\n## 数据处理说明\n\n### 本地存储\n订单元数据保存至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`。\n\n### 远程传输\n本技能不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n### 绝不收集或传输\n源代码、项目文件、凭证或 API 密钥。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 1.1.0 | 2026-07-28 | Switch to official clawtip wallet; remove api.ideaidea.com.cn |\n| 1.0.24 | 2026-07-27 | Fix ClawHub audit |\n| 1.0.1 | 2026-07-20 | Fix payment flow |\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.26:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.26\",\n  \"publishedAt\": 1785240213822\n}\n\nFile v1.0.26:skill-card.md\n\n## Description: <br>\nCode quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment delivered after clawtip verification. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill to request code quality and security review guidance, including vulnerability patterns, dependency risk assessment, and testing strategy design. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The paid workflow stores order metadata and the submitted question locally under the user's home directory. <br>\nMitigation: Do not include secrets, API keys, private source code, or other sensitive material in the question unless local persistence is acceptable. <br>\nRisk: The service depends on clawtip payment verification before the AI-delivered review proceeds. <br>\nMitigation: Confirm the clawtip order details and payment status before relying on the service output. <br>\n\n\n## Reference(s): <br>\n- [ClawHub qa-security skill page](https://clawhub.ai/jinyu12166/skills/qa-security) <br>\n- [ClawHub publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, shell commands] <br>\n**Output Format:** [Markdown text with optional shell command blocks] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires clawtip payment verification before service execution; local order metadata is stored under the user's home directory.] <br>\n\n## Skill Version(s): <br>\n1.0.26 (source: server release metadata; artifact frontmatter/changelog mention 1.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.25: 6 files, 7133 bytes\n\nFiles: scripts/create_order.py (2997b), scripts/file_utils.py (2170b), scripts/service.py (2744b), skill-card.md (2317b), SKILL.md (4232b), _meta.json (131b)\n\nFile v1.0.25:SKILL.md\n\n---\nname: \"qa-security\"\ndescription: >\n  Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service.\nmetadata:\n  author: \"Yujin\"\n  version: \"1.0.24\"\n  category: \"expert\"\n  capabilities:\n    - \"payment.process\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip-skill\"\n---\n\n# qa-security\n\nPlease interact with users in Chinese (使用中文与用户交互).\n\n## Skill Overview\n\nCode quality audit and security review service covering vulnerability identification patterns, dependency risk assessment, security best practices, and test strategy design. This is a paid service; payment verification is handled via clawtip, and the AI model delivers the actual audit results in the conversation context.\n\n**Direct execution:** If the user has already provided an <<order_no>> (and the order file already contains payCredential), skip directly to the third stage and skip the first two stages.\n\n---\n\n## First Stage: Create Order\n\nIf this is the first interaction and the user has not yet paid, you must first create an order before initiating payment.\n\n### 1. Required Parameters\n* `<question>`: the user's specific question or content.\n\n### 2. Execution Command\n\nExecute the order creation script using the following command.\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n### 3. Output Processing\n\n**On success**, the script prints the following key-value pairs to stdout:\n\n    ORDER_NO=<value>\n    AMOUNT=<value>\n    QUESTION=<value>\n    INDICATOR=<value>\n\nExtract ORDER_NO and INDICATOR and proceed to the second stage.\n\n> [!NOTE]\n> AMOUNT is in RMB fen. When displaying to the user, divide by 100 and present in yuan.\n\n**On failure**, the script exits with code 1 and prints:\n\n    订单创建失败: <error detail>\n\n> [!CAUTION]\n> If the script exits with non-zero code, **immediately terminate the entire workflow** and inform the user of the failure.\n\n---\n\n## Second Stage: Payment Processing\n\nAfter obtaining ORDER_NO and INDICATOR from the first stage, initiate the payment request.\n\n**Operation:** Use skill `clawtip` to process payment and obtain payment credentials. If this skill does not exist, install it first.\n\n**Parameters required by `clawtip`:**\n\n    {\n      \"order_no\": \"<ORDER_NO from first stage>\",\n      \"indicator\": \"<INDICATOR from first stage>\"\n    }\n\n---\n\n## Third Stage: Service Execution\n\nAfter successful payment and obtaining payCredential, resume interaction and execute the service script.\n\n### 1. Required Parameters\n* `<order_no>`: the order number generated in the first stage.\n\n### 2. Execution Command\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n### 3. Output Processing\n\nExtract the PAY_STATUS value (format: `PAY_STATUS: <value>`).\n\n| Field | Enum | Output Format |\n|-------|------|---------------|\n| PAY_STATUS | SUCCESS, PROCESSING, FAIL, ERROR | `PAY_STATUS: SUCCESS` |\n| ERROR_INFO | N/A | `ERROR_INFO: <reason>` |\n\n---\n\n## Data Handling\n\n### Local Storage\nOrder metadata is saved to `~/.openclaw/skills/orders/{indicator}/{order_no}.json` as required by clawtip payment flow. Fields: skill-id, order_no, amount, question, encrypted_data (SM4 encrypted), pay_to, description, slug, resource_url.\n\n### Remote Transmission\n- **Phase 1:** Sends slug and user question text to `https://api.ideaidea.com.cn` via HTTPS for order creation.\n- **Phase 2:** clawtip reads the local order file, processes payment, writes payCredential back to the same file.\n- **Phase 3:** Sends slug, order_no, and encrypted payCredential to `https://api.ideaidea.com.cn` for verification.\n\n### Not Collected or Transmitted\n- No source code, project files, database credentials, environment variables, or API keys are read or uploaded.\n- Service results are delivered by the AI model in the conversation context.\n\n---\n\n## Version History\n\n| Version | Date | Notes |\n|:---|:---|:---|\n| 1.0.24 | 2026-07-27 | Fix ClawHub audit: accurate service description, remove excessive stdout fields, add data handling disclosure |\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard |\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.25:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.25\",\n  \"publishedAt\": 1785226696319\n}\n\nFile v1.0.25:skill-card.md\n\n## Description: <br>\nCode quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this paid skill to request Chinese-language code quality audits, security review guidance, vulnerability identification patterns, dependency risk assessment, security best practices, and test strategy design. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: User questions, order numbers, and encrypted payment credentials are transmitted to api.ideaidea.com.cn and order records are stored locally. <br>\nMitigation: Use the skill only when that paid external workflow and local order storage are acceptable, and avoid entering secrets, private source code, credentials, or sensitive vulnerability details. <br>\nRisk: The skill depends on clawtip payment processing before service execution. <br>\nMitigation: Confirm the clawtip dependency is available and review the order and payment status outputs before relying on the delivered audit guidance. <br>\n\n\n## Reference(s): <br>\n- [qa-security ClawHub skill page](https://clawhub.ai/jinyu12166/skills/qa-security) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [External payment and service API endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Shell commands, Configuration] <br>\n**Output Format:** [Markdown guidance with payment workflow command output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The service creates and verifies a paid order before the agent delivers audit guidance in the conversation context.] <br>\n\n## Skill Version(s): <br>\n1.0.25 (source: server release metadata; artifact frontmatter lists 1.0.24) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.23: 6 files, 8609 bytes\n\nFiles: scripts/create_order.py (3568b), scripts/file_utils.py (2170b), scripts/service.py (3207b), skill-card.md (2809b), SKILL.md (5572b), _meta.json (131b)\n\nFile v1.0.23:SKILL.md\n\n---\r\nname: \"qa-security\"\r\ndescription: >\r\n  Code quality audit, vulnerability scanning, dependency security analysis, and test strategy design. Analysis is performed locally. User question text and encrypted payment credentials are transmitted via HTTPS to api.ideaidea.com.cn (clawtip verification service) for order creation and fulfillment. No source code, credentials, or project files are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"1.1.0\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# qa-security\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供代码质量审计与安全审查服务，覆盖代码漏洞扫描、依赖安全分析、测试策略设计和安全最佳实践审查。所有代码审计与安全分析在 AI 本地完成。身份验证通过 clawtip 第三方服务进行，仅问题描述文本（用于生成服务内容）和订单元数据通过 HTTPS 传输。\r\n\r\n### 核心能力\r\n\r\n**代码漏洞扫描**\r\n- 常见 Web 漏洞检测（SQL 注入、XSS、CSRF、SSRF、命令注入）\r\n- 输入验证与输出编码的完整性审查\r\n- 认证与授权逻辑的缺陷检测\r\n- 会话管理、JWT、OAuth 配置的安全审查\r\n- 敏感数据（密钥、凭据、PII）的明文存储检测\r\n\r\n**依赖安全分析**\r\n- 第三方依赖版本审查与已知 CVE 对照\r\n- 过时/弃用包的识别与升级路径建议\r\n- 供应链风险评估（依赖深度、维护活跃度、许可证兼容性）\r\n- 最小依赖原则审查（是否存在可移除的冗余依赖）\r\n\r\n**安全最佳实践审查**\r\n- OWASP Top 10 对齐度评估\r\n- 安全编码规范（参数化查询、输出编码、CSP 头等）\r\n- 加密实现审查（算法选择、密钥管理、盐值使用）\r\n- 安全配置检查（CORS、Cookie 属性、TLS 配置）\r\n\r\n**测试策略设计**\r\n- 基于代码特征和风险面生成测试计划\r\n- 单元测试覆盖率提升路径\r\n- 集成测试与端到端测试的边界划分\r\n- 安全测试用例设计（模糊测试、渗透测试场景）\r\n- CI/CD 流水线中的质量门禁配置建议\r\n\r\n**风险分级与修复优先级**\r\n- 按 CVSS 思路对发现的问题进行严重性分级\r\n- 输出风险矩阵（可能性 × 影响程度）\r\n- 生成按优先级排序的修复路线图\r\n- 每个问题附带可执行的修复代码示例\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我审查这个用户登录模块的安全性\"\r\n- \"检查项目里的依赖有没有已知漏洞\"\r\n- \"我们的 API 接口有认证漏洞吗\"\r\n- \"给这个支付模块设计一套安全测试用例\"\r\n- \"上线前的安全审查清单帮我看一下\"\r\n\r\n### 分析流程\r\n\r\n1. **问题诊断**：AI 根据您的描述和代码片段进行风险面分析\r\n2. **本地审计**：所有代码审查、依赖分析、策略设计在本地完成\r\n3. **分级输出**：问题按严重性排序，附带修复方案和优先级\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 代码审查、漏洞分析、依赖检查由 AI 在本地完成\r\n- 测试策略和安全建议在本地生成\r\n- 所有文件读取和分析均在本地执行\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 绝不收集或传输\r\n- 源代码文件内容和项目结构\r\n- 数据库连接信息、API 密钥、环境变量\r\n- 依赖包清单的具体内容（分析在本地完成）\r\n- 任何形式的安全凭据（支付流程必需的加密支付凭证除外，仅通过 HTTPS 传输至 api.ideaidea.com.cn）\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n输出 `ORDER_NO`、`AMOUNT`、`QUESTION`、`INDICATOR`。AMOUNT 单位为人民币分。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入 `order_no` 和 `indicator`。\r\n\r\n### 第三阶段：获取审计服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付安全审计与测试策略结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 1.1.0 | 2026-07-20 | Restructured SKILL.md: capability-first layout with detailed service descriptions. Updated UA headers to skill-specific identifiers. |\r\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard |\r\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.23:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.23\",\n  \"publishedAt\": 1785061561606\n}\n\nFile v1.0.23:skill-card.md\n\n## Description: <br>\nProvides code quality audit, vulnerability scanning, dependency security analysis, and test strategy guidance while sending user question text and encrypted payment verification data to api.ideaidea.com.cn for paid order creation and fulfillment. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security-minded teams use this skill to request Chinese-language code security review, dependency risk analysis, secure coding recommendations, and test strategy guidance. It is suited for pre-release security review and remediation planning when users accept the paid verification workflow and external disclosure boundaries. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: User question text and encrypted payment verification data are sent to api.ideaidea.com.cn. <br>\nMitigation: Avoid putting source code, secrets, vulnerability details, private project information, or other sensitive content in the question text unless external disclosure is acceptable. <br>\nRisk: Server evidence reports inconsistent privacy wording and a suspicious security verdict. <br>\nMitigation: Confirm the data handling disclosures before deployment and align user-facing wording with the actual external verification behavior. <br>\nRisk: Server guidance says the service script is broken before relying on the paid workflow. <br>\nMitigation: Fix and retest the service fulfillment script before using the paid verification flow in production. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/qa-security) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [External verification service](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Guidance] <br>\n**Output Format:** [Markdown or plain-text security review with remediation guidance and command examples; payment scripts also emit key-value status lines and JSON_RESULT output.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires clawtip payment verification; user question text and encrypted payment credential data are sent to the external verification service.] <br>\n\n## Skill Version(s): <br>\n1.0.23 (source: server release metadata; artifact frontmatter metadata.version is 1.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.22: 6 files, 8572 bytes\n\nFiles: scripts/create_order.py (3629b), scripts/file_utils.py (2170b), scripts/service.py (3207b), skill-card.md (2525b), SKILL.md (5572b), _meta.json (131b)\n\nFile v1.0.22:SKILL.md\n\n---\r\nname: \"qa-security\"\r\ndescription: >\r\n  Code quality audit, vulnerability scanning, dependency security analysis, and test strategy design. Analysis is performed locally. User question text and encrypted payment credentials are transmitted via HTTPS to api.ideaidea.com.cn (clawtip verification service) for order creation and fulfillment. No source code, credentials, or project files are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"1.1.0\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# qa-security\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供代码质量审计与安全审查服务，覆盖代码漏洞扫描、依赖安全分析、测试策略设计和安全最佳实践审查。所有代码审计与安全分析在 AI 本地完成。身份验证通过 clawtip 第三方服务进行，仅问题描述文本（用于生成服务内容）和订单元数据通过 HTTPS 传输。\r\n\r\n### 核心能力\r\n\r\n**代码漏洞扫描**\r\n- 常见 Web 漏洞检测（SQL 注入、XSS、CSRF、SSRF、命令注入）\r\n- 输入验证与输出编码的完整性审查\r\n- 认证与授权逻辑的缺陷检测\r\n- 会话管理、JWT、OAuth 配置的安全审查\r\n- 敏感数据（密钥、凭据、PII）的明文存储检测\r\n\r\n**依赖安全分析**\r\n- 第三方依赖版本审查与已知 CVE 对照\r\n- 过时/弃用包的识别与升级路径建议\r\n- 供应链风险评估（依赖深度、维护活跃度、许可证兼容性）\r\n- 最小依赖原则审查（是否存在可移除的冗余依赖）\r\n\r\n**安全最佳实践审查**\r\n- OWASP Top 10 对齐度评估\r\n- 安全编码规范（参数化查询、输出编码、CSP 头等）\r\n- 加密实现审查（算法选择、密钥管理、盐值使用）\r\n- 安全配置检查（CORS、Cookie 属性、TLS 配置）\r\n\r\n**测试策略设计**\r\n- 基于代码特征和风险面生成测试计划\r\n- 单元测试覆盖率提升路径\r\n- 集成测试与端到端测试的边界划分\r\n- 安全测试用例设计（模糊测试、渗透测试场景）\r\n- CI/CD 流水线中的质量门禁配置建议\r\n\r\n**风险分级与修复优先级**\r\n- 按 CVSS 思路对发现的问题进行严重性分级\r\n- 输出风险矩阵（可能性 × 影响程度）\r\n- 生成按优先级排序的修复路线图\r\n- 每个问题附带可执行的修复代码示例\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我审查这个用户登录模块的安全性\"\r\n- \"检查项目里的依赖有没有已知漏洞\"\r\n- \"我们的 API 接口有认证漏洞吗\"\r\n- \"给这个支付模块设计一套安全测试用例\"\r\n- \"上线前的安全审查清单帮我看一下\"\r\n\r\n### 分析流程\r\n\r\n1. **问题诊断**：AI 根据您的描述和代码片段进行风险面分析\r\n2. **本地审计**：所有代码审查、依赖分析、策略设计在本地完成\r\n3. **分级输出**：问题按严重性排序，附带修复方案和优先级\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 代码审查、漏洞分析、依赖检查由 AI 在本地完成\r\n- 测试策略和安全建议在本地生成\r\n- 所有文件读取和分析均在本地执行\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 绝不收集或传输\r\n- 源代码文件内容和项目结构\r\n- 数据库连接信息、API 密钥、环境变量\r\n- 依赖包清单的具体内容（分析在本地完成）\r\n- 任何形式的安全凭据（支付流程必需的加密支付凭证除外，仅通过 HTTPS 传输至 api.ideaidea.com.cn）\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n输出 `ORDER_NO`、`AMOUNT`、`QUESTION`、`INDICATOR`。AMOUNT 单位为人民币分。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入 `order_no` 和 `indicator`。\r\n\r\n### 第三阶段：获取审计服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付安全审计与测试策略结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 1.1.0 | 2026-07-20 | Restructured SKILL.md: capability-first layout with detailed service descriptions. Updated UA headers to skill-specific identifiers. |\r\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard |\r\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.22:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.22\",\n  \"publishedAt\": 1785058217817\n}\n\nFile v1.0.22:skill-card.md\n\n## Description: <br>\nCode quality audit, vulnerability scanning, dependency security analysis, and test strategy design, with local analysis and HTTPS transmission of question text and encrypted payment credentials to api.ideaidea.com.cn for order creation and fulfillment. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill to review code quality, identify likely vulnerabilities, analyze dependency risk, and design test strategies before release. It is also used for security best-practice checks and prioritized remediation guidance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Question text and payment verification data are sent to api.ideaidea.com.cn, and order metadata is stored locally. <br>\nMitigation: Use only non-sensitive prompts for order creation, avoid including source code, secrets, incident details, or sensitive findings, and review local order files according to your retention policy. <br>\nRisk: The release evidence reports unsupported encryption claims and inconsistent disclosures about question and payment data handling. <br>\nMitigation: Treat the privacy and encryption claims as unverified until the publisher clarifies encryption behavior, retention, and handling of payment-related data. <br>\n\n\n## Reference(s): <br>\n- [ClawHub qa-security skill page](https://clawhub.ai/jinyu12166/skills/qa-security) <br>\n- [Clawtip verification service endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, code, shell commands, configuration] <br>\n**Output Format:** [Markdown with security findings, prioritized remediation guidance, code examples, shell commands, and JSON status lines from helper scripts] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The helper scripts create order metadata locally and print order or payment status fields for the agent workflow.] <br>\n\n## Skill Version(s): <br>\n1.0.22 (source: ClawHub release metadata; artifact frontmatter lists 1.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.21: 6 files, 8560 bytes\n\nFiles: scripts/create_order.py (3629b), scripts/file_utils.py (2170b), scripts/service.py (3194b), skill-card.md (2524b), SKILL.md (5467b), _meta.json (131b)\n\nFile v1.0.21:SKILL.md\n\n---\r\nname: \"qa-security\"\r\ndescription: >\r\n  Code quality audit, vulnerability scanning, dependency security analysis, and test strategy design. Analysis is performed locally. User question text and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No source code, credentials, or project files are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"1.1.0\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# qa-security\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供代码质量审计与安全审查服务，覆盖代码漏洞扫描、依赖安全分析、测试策略设计和安全最佳实践审查。所有代码审计与安全分析在 AI 本地完成。身份验证通过 clawtip 第三方服务进行，仅问题描述文本（用于生成服务内容）和订单元数据通过 HTTPS 传输。\r\n\r\n### 核心能力\r\n\r\n**代码漏洞扫描**\r\n- 常见 Web 漏洞检测（SQL 注入、XSS、CSRF、SSRF、命令注入）\r\n- 输入验证与输出编码的完整性审查\r\n- 认证与授权逻辑的缺陷检测\r\n- 会话管理、JWT、OAuth 配置的安全审查\r\n- 敏感数据（密钥、凭据、PII）的明文存储检测\r\n\r\n**依赖安全分析**\r\n- 第三方依赖版本审查与已知 CVE 对照\r\n- 过时/弃用包的识别与升级路径建议\r\n- 供应链风险评估（依赖深度、维护活跃度、许可证兼容性）\r\n- 最小依赖原则审查（是否存在可移除的冗余依赖）\r\n\r\n**安全最佳实践审查**\r\n- OWASP Top 10 对齐度评估\r\n- 安全编码规范（参数化查询、输出编码、CSP 头等）\r\n- 加密实现审查（算法选择、密钥管理、盐值使用）\r\n- 安全配置检查（CORS、Cookie 属性、TLS 配置）\r\n\r\n**测试策略设计**\r\n- 基于代码特征和风险面生成测试计划\r\n- 单元测试覆盖率提升路径\r\n- 集成测试与端到端测试的边界划分\r\n- 安全测试用例设计（模糊测试、渗透测试场景）\r\n- CI/CD 流水线中的质量门禁配置建议\r\n\r\n**风险分级与修复优先级**\r\n- 按 CVSS 思路对发现的问题进行严重性分级\r\n- 输出风险矩阵（可能性 × 影响程度）\r\n- 生成按优先级排序的修复路线图\r\n- 每个问题附带可执行的修复代码示例\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我审查这个用户登录模块的安全性\"\r\n- \"检查项目里的依赖有没有已知漏洞\"\r\n- \"我们的 API 接口有认证漏洞吗\"\r\n- \"给这个支付模块设计一套安全测试用例\"\r\n- \"上线前的安全审查清单帮我看一下\"\r\n\r\n### 分析流程\r\n\r\n1. **问题诊断**：AI 根据您的描述和代码片段进行风险面分析\r\n2. **本地审计**：所有代码审查、依赖分析、策略设计在本地完成\r\n3. **分级输出**：问题按严重性排序，附带修复方案和优先级\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 代码审查、漏洞分析、依赖检查由 AI 在本地完成\r\n- 测试策略和安全建议在本地生成\r\n- 所有文件读取和分析均在本地执行\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 绝不收集或传输\r\n- 源代码文件内容和项目结构\r\n- 数据库连接信息、API 密钥、环境变量\r\n- 依赖包清单的具体内容（分析在本地完成）\r\n- 任何形式的安全凭据\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n输出 `ORDER_NO`、`AMOUNT`、`QUESTION`、`INDICATOR`。AMOUNT 单位为人民币分。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入 `order_no` 和 `indicator`。\r\n\r\n### 第三阶段：获取审计服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付安全审计与测试策略结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 1.1.0 | 2026-07-20 | Restructured SKILL.md: capability-first layout with detailed service descriptions. Updated UA headers to skill-specific identifiers. |\r\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard |\r\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.21:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.21\",\n  \"publishedAt\": 1784642279784\n}\n\nFile v1.0.21:skill-card.md\n\n## Description: <br>\nQa Security helps agents review code quality, vulnerability risk, dependencies, and test strategy while using a third-party Clawtip service for order creation and payment verification. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to request local security review, dependency analysis, remediation guidance, and security test planning for code they are evaluating. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill sends question text and encrypted payment credential data to api.ideaidea.com.cn. <br>\nMitigation: Use only when that transfer is acceptable, and keep source code, secrets, customer data, and private vulnerability details out of the question text. <br>\nRisk: Server security evidence marks the release as suspicious because the paid verification flow has limited user control and ambiguous privacy wording. <br>\nMitigation: Review the skill before installation and confirm the payment verification behavior matches the intended deployment policy. <br>\nRisk: Server-resolved provenance is unavailable for this release. <br>\nMitigation: Do not rely on inferred repository origin; use the provided release metadata and file hashes when reviewing the artifact. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill listing](https://clawhub.ai/jinyu12166/skills/qa-security) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [Third-party verification endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown or plain text guidance with optional code and shell command examples; workflow scripts also emit key-value and JSON result lines.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May require Clawtip order creation and payment verification before service delivery.] <br>\n\n## Skill Version(s): <br>\n1.0.21 (source: server release metadata; artifact frontmatter reports 1.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.20: 6 files, 8591 bytes\n\nFiles: scripts/create_order.py (3629b), scripts/file_utils.py (2170b), scripts/service.py (3204b), skill-card.md (2611b), SKILL.md (5467b), _meta.json (131b)\n\nFile v1.0.20:SKILL.md\n\n---\r\nname: \"qa-security\"\r\ndescription: >\r\n  Code quality audit, vulnerability scanning, dependency security analysis, and test strategy design. Analysis is performed locally. User question text and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No source code, credentials, or project files are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"1.1.0\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# qa-security\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供代码质量审计与安全审查服务，覆盖代码漏洞扫描、依赖安全分析、测试策略设计和安全最佳实践审查。所有代码审计与安全分析在 AI 本地完成。身份验证通过 clawtip 第三方服务进行，仅问题描述文本（用于生成服务内容）和订单元数据通过 HTTPS 传输。\r\n\r\n### 核心能力\r\n\r\n**代码漏洞扫描**\r\n- 常见 Web 漏洞检测（SQL 注入、XSS、CSRF、SSRF、命令注入）\r\n- 输入验证与输出编码的完整性审查\r\n- 认证与授权逻辑的缺陷检测\r\n- 会话管理、JWT、OAuth 配置的安全审查\r\n- 敏感数据（密钥、凭据、PII）的明文存储检测\r\n\r\n**依赖安全分析**\r\n- 第三方依赖版本审查与已知 CVE 对照\r\n- 过时/弃用包的识别与升级路径建议\r\n- 供应链风险评估（依赖深度、维护活跃度、许可证兼容性）\r\n- 最小依赖原则审查（是否存在可移除的冗余依赖）\r\n\r\n**安全最佳实践审查**\r\n- OWASP Top 10 对齐度评估\r\n- 安全编码规范（参数化查询、输出编码、CSP 头等）\r\n- 加密实现审查（算法选择、密钥管理、盐值使用）\r\n- 安全配置检查（CORS、Cookie 属性、TLS 配置）\r\n\r\n**测试策略设计**\r\n- 基于代码特征和风险面生成测试计划\r\n- 单元测试覆盖率提升路径\r\n- 集成测试与端到端测试的边界划分\r\n- 安全测试用例设计（模糊测试、渗透测试场景）\r\n- CI/CD 流水线中的质量门禁配置建议\r\n\r\n**风险分级与修复优先级**\r\n- 按 CVSS 思路对发现的问题进行严重性分级\r\n- 输出风险矩阵（可能性 × 影响程度）\r\n- 生成按优先级排序的修复路线图\r\n- 每个问题附带可执行的修复代码示例\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我审查这个用户登录模块的安全性\"\r\n- \"检查项目里的依赖有没有已知漏洞\"\r\n- \"我们的 API 接口有认证漏洞吗\"\r\n- \"给这个支付模块设计一套安全测试用例\"\r\n- \"上线前的安全审查清单帮我看一下\"\r\n\r\n### 分析流程\r\n\r\n1. **问题诊断**：AI 根据您的描述和代码片段进行风险面分析\r\n2. **本地审计**：所有代码审查、依赖分析、策略设计在本地完成\r\n3. **分级输出**：问题按严重性排序，附带修复方案和优先级\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 代码审查、漏洞分析、依赖检查由 AI 在本地完成\r\n- 测试策略和安全建议在本地生成\r\n- 所有文件读取和分析均在本地执行\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 绝不收集或传输\r\n- 源代码文件内容和项目结构\r\n- 数据库连接信息、API 密钥、环境变量\r\n- 依赖包清单的具体内容（分析在本地完成）\r\n- 任何形式的安全凭据\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n输出 `ORDER_NO`、`AMOUNT`、`QUESTION`、`INDICATOR`。AMOUNT 单位为人民币分。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入 `order_no` 和 `indicator`。\r\n\r\n### 第三阶段：获取审计服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付安全审计与测试策略结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 1.1.0 | 2026-07-20 | Restructured SKILL.md: capability-first layout with detailed service descriptions. Updated UA headers to skill-specific identifiers. |\r\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard |\r\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.20:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.20\",\n  \"publishedAt\": 1784641327603\n}\n\nFile v1.0.20:skill-card.md\n\n## Description: <br>\nProvides local code quality auditing, vulnerability review, dependency security analysis, and test strategy guidance while using a third-party Clawtip payment-verification service. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill to assess code snippets or project descriptions for vulnerabilities, dependency issues, secure coding gaps, and test strategy improvements. It is suited for local advisory review workflows where payment verification through the disclosed third-party service is acceptable. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Question text, order details, and encrypted payment credentials are sent to the disclosed third-party verification service. <br>\nMitigation: Avoid putting secrets, proprietary code, credentials, or sensitive project details in the question text before creating an order. <br>\nRisk: Order metadata is stored locally as part of the payment-verification flow. <br>\nMitigation: Review local order storage before use in sensitive environments and remove stored order files when they are no longer needed. <br>\nRisk: The security guidance notes a service.py indentation error that may prevent reliable verification flow execution. <br>\nMitigation: Expect verification failures until the publisher corrects the script, and review script behavior before relying on paid fulfillment. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill listing](https://clawhub.ai/jinyu12166/skills/qa-security) <br>\n- [Clawtip verification service endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, code, shell commands] <br>\n**Output Format:** [Markdown with prioritized findings, remediation examples, and optional inline shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include risk ranking, test strategy recommendations, dependency review notes, and secure coding suggestions after payment verification succeeds.] <br>\n\n## Skill Version(s): <br>\n1.0.20 (source: server release metadata; artifact metadata reports 1.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.19: 6 files, 8288 bytes\n\nFiles: scripts/create_order.py (3383b), scripts/file_utils.py (2170b), scripts/service.py (2899b), skill-card.md (2297b), SKILL.md (5156b), _meta.json (131b)\n\nFile v1.0.19:SKILL.md\n\n---\r\nname: \"qa-security\"\r\ndescription: >\r\n  Code quality audit, vulnerability scanning, dependency security analysis, and test strategy design. Analysis is performed locally. User question text and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No source code, credentials, or project files are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"1.1.0\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n---\r\n\r\n# qa-security\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供代码质量审计与安全审查服务，覆盖代码漏洞扫描、依赖安全分析、测试策略设计和安全最佳实践审查。所有代码审计与安全分析在 AI 本地完成。身份验证通过 clawtip 第三方服务进行，仅问题描述文本（用于生成服务内容）和订单元数据通过 HTTPS 传输。\r\n\r\n### 核心能力\r\n\r\n**代码漏洞扫描**\r\n- 常见 Web 漏洞检测（SQL 注入、XSS、CSRF、SSRF、命令注入）\r\n- 输入验证与输出编码的完整性审查\r\n- 认证与授权逻辑的缺陷检测\r\n- 会话管理、JWT、OAuth 配置的安全审查\r\n- 敏感数据（密钥、凭据、PII）的明文存储检测\r\n\r\n**依赖安全分析**\r\n- 第三方依赖版本审查与已知 CVE 对照\r\n- 过时/弃用包的识别与升级路径建议\r\n- 供应链风险评估（依赖深度、维护活跃度、许可证兼容性）\r\n- 最小依赖原则审查（是否存在可移除的冗余依赖）\r\n\r\n**安全最佳实践审查**\r\n- OWASP Top 10 对齐度评估\r\n- 安全编码规范（参数化查询、输出编码、CSP 头等）\r\n- 加密实现审查（算法选择、密钥管理、盐值使用）\r\n- 安全配置检查（CORS、Cookie 属性、TLS 配置）\r\n\r\n**测试策略设计**\r\n- 基于代码特征和风险面生成测试计划\r\n- 单元测试覆盖率提升路径\r\n- 集成测试与端到端测试的边界划分\r\n- 安全测试用例设计（模糊测试、渗透测试场景）\r\n- CI/CD 流水线中的质量门禁配置建议\r\n\r\n**风险分级与修复优先级**\r\n- 按 CVSS 思路对发现的问题进行严重性分级\r\n- 输出风险矩阵（可能性 × 影响程度）\r\n- 生成按优先级排序的修复路线图\r\n- 每个问题附带可执行的修复代码示例\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我审查这个用户登录模块的安全性\"\r\n- \"检查项目里的依赖有没有已知漏洞\"\r\n- \"我们的 API 接口有认证漏洞吗\"\r\n- \"给这个支付模块设计一套安全测试用例\"\r\n- \"上线前的安全审查清单帮我看一下\"\r\n\r\n### 分析流程\r\n\r\n1. **问题诊断**：AI 根据您的描述和代码片段进行风险面分析\r\n2. **本地审计**：所有代码审查、依赖分析、策略设计在本地完成\r\n3. **分级输出**：问题按严重性排序，附带修复方案和优先级\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 代码审查、漏洞分析、依赖检查由 AI 在本地完成\r\n- 测试策略和安全建议在本地生成\r\n- 所有文件读取和分析均在本地执行\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 绝不收集或传输\r\n- 源代码文件内容和项目结构\r\n- 数据库连接信息、API 密钥、环境变量\r\n- 依赖包清单的具体内容（分析在本地完成）\r\n- 任何形式的安全凭据\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n输出 `ORDER_NO`、`AMOUNT`、`QUESTION`、`INDICATOR`。AMOUNT 单位为人民币分。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入 `order_no` 和 `indicator`。\r\n\r\n### 第三阶段：获取审计服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付安全审计与测试策略结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 1.1.0 | 2026-07-20 | Restructured SKILL.md: capability-first layout with detailed service descriptions. Updated UA headers to skill-specific identifiers. |\r\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard |\r\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.19:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.19\",\n  \"publishedAt\": 1784629858178\n}\n\nFile v1.0.19:skill-card.md\n\n## Description: <br>\nQa Security helps developers audit code quality, scan for vulnerabilities, analyze dependency security, and design test strategies while using a third-party verification service for paid access. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this skill to assess code quality, security vulnerabilities, dependency risks, test strategy gaps, and remediation priorities before release. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Question text and payment-verification data are sent to api.ideaidea.com.cn during paid verification. <br>\nMitigation: Avoid putting source code, secrets, environment variables, or sensitive incident details in the question text, and review the skill before installing. <br>\nRisk: The evidence warns not to rely on the stated SM4 protection unless the publisher adds verifiable client-side encryption. <br>\nMitigation: Treat HTTPS as the confirmed transport protection and do not assume additional encryption beyond what can be verified. <br>\nRisk: Order metadata is stored locally under the OpenClaw orders directory until removed. <br>\nMitigation: Remove local order files when they are no longer needed, especially on shared systems. <br>\n\n\n## Reference(s): <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown or text with prioritized findings, risk ratings, remediation examples, test plans, and command or configuration snippets] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Analysis is described as local; paid access uses remote order creation and payment verification.] <br>\n\n## Skill Version(s): <br>\n1.0.19 (source: server release metadata; artifact frontmatter reports 1.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.18: 6 files, 7951 bytes\n\nFiles: scripts/create_order.py (2992b), scripts/file_utils.py (2170b), scripts/service.py (2527b), skill-card.md (2561b), SKILL.md (4718b), _meta.json (131b)\n\nFile v1.0.18:SKILL.md\n\n---\nname: \"qa-security\"\ndescription: >\n  Code quality audit, vulnerability scanning, dependency security analysis, and test strategy design. Analysis is performed locally; only order metadata (slug, orderNo) is transmitted via HTTPS to the clawtip third-party verification service. No source code, credentials, or project files are uploaded.\nmetadata:\n  author: \"Yujin\"\n  version: \"1.1.0\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip-skill\"\n---\n\n# qa-security\n\nPlease interact with users in Chinese (使用中文与用户交互).\n\n## 功能概述\n\n本技能提供代码质量审计与安全审查服务，覆盖代码漏洞扫描、依赖安全分析、测试策略设计和安全最佳实践审查。所有分析在本地执行，您的源代码不会上传至任何远程服务。身份验证通过 clawtip 第三方服务进行。\n\n### 核心能力\n\n**代码漏洞扫描**\n- 常见 Web 漏洞检测（SQL 注入、XSS、CSRF、SSRF、命令注入）\n- 输入验证与输出编码的完整性审查\n- 认证与授权逻辑的缺陷检测\n- 会话管理、JWT、OAuth 配置的安全审查\n- 敏感数据（密钥、凭据、PII）的明文存储检测\n\n**依赖安全分析**\n- 第三方依赖版本审查与已知 CVE 对照\n- 过时/弃用包的识别与升级路径建议\n- 供应链风险评估（依赖深度、维护活跃度、许可证兼容性）\n- 最小依赖原则审查（是否存在可移除的冗余依赖）\n\n**安全最佳实践审查**\n- OWASP Top 10 对齐度评估\n- 安全编码规范（参数化查询、输出编码、CSP 头等）\n- 加密实现审查（算法选择、密钥管理、盐值使用）\n- 安全配置检查（CORS、Cookie 属性、TLS 配置）\n\n**测试策略设计**\n- 基于代码特征和风险面生成测试计划\n- 单元测试覆盖率提升路径\n- 集成测试与端到端测试的边界划分\n- 安全测试用例设计（模糊测试、渗透测试场景）\n- CI/CD 流水线中的质量门禁配置建议\n\n**风险分级与修复优先级**\n- 按 CVSS 思路对发现的问题进行严重性分级\n- 输出风险矩阵（可能性 × 影响程度）\n- 生成按优先级排序的修复路线图\n- 每个问题附带可执行的修复代码示例\n\n### 使用场景示例\n\n- \"帮我审查这个用户登录模块的安全性\"\n- \"检查项目里的依赖有没有已知漏洞\"\n- \"我们的 API 接口有认证漏洞吗\"\n- \"给这个支付模块设计一套安全测试用例\"\n- \"上线前的安全审查清单帮我看一下\"\n\n### 分析流程\n\n1. **问题诊断**：AI 根据您的描述和代码片段进行风险面分析\n2. **本地审计**：所有代码审查、依赖分析、策略设计在本地完成\n3. **分级输出**：问题按严重性排序，附带修复方案和优先级\n\n---\n\n## 数据处理与隐私说明\n\n### 本地处理（数据始终不离开本机）\n- 代码审查、漏洞分析、依赖检查由 AI 在本地完成\n- 测试策略和安全建议在本地生成\n- 所有文件读取和分析均在本地执行\n\n### 远程传输（仅身份验证阶段）\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\n- **传输协议**：HTTPS + SM4 国密加密\n- **传输时机**：仅在订单创建和履约验证时发生\n\n### 绝不收集或传输\n- 源代码文件内容和项目结构\n- 数据库连接信息、API 密钥、环境变量\n- 依赖包清单的具体内容（分析在本地完成）\n- 任何形式的安全凭据\n\n---\n\n## 如何开始使用\n\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程。\n\n### 前置条件\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\n\n### 第一阶段：创建验证订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n输出 `ORDER_NO`、`AMOUNT`、`QUESTION`、`INDICATOR`。AMOUNT 单位为人民币分。\n\n### 第二阶段：身份验证\n\n使用技能 `clawtip` 完成支付验证，传入 `order_no` 和 `indicator`。\n\n### 第三阶段：获取审计服务\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付安全审计与测试策略结果。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:---|:---|:---|\n| 1.1.0 | 2026-07-20 | Restructured SKILL.md: capability-first layout with detailed service descriptions. Updated UA headers to skill-specific identifiers. |\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard |\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.18:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.18\",\n  \"publishedAt\": 1784562767106\n}\n\nFile v1.0.18:skill-card.md\n\n## Description: <br>\nQa Security supports local code quality audits, vulnerability scanning, dependency security analysis, security best-practice review, and test strategy design with a paid third-party verification flow. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineering teams use this skill to request code security review guidance, dependency risk analysis, remediation priorities, and security-focused test plans for software projects. The skill is intended to produce local audit guidance after the user completes third-party order verification. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The order creation flow sends the user's question to a remote verification service even though the skill summary says only order metadata is transmitted. <br>\nMitigation: Keep order questions generic and exclude source code, credentials, vulnerability details, incident context, and other sensitive project information. <br>\nRisk: The skill requests outbound network, credential-read, filesystem-read, and filesystem-write permissions while handling a paid verification workflow. <br>\nMitigation: Run the skill in a controlled workspace, inspect local order records before reuse, and verify the third-party service behavior before using it on confidential projects. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/qa-security) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [Third-party verification service](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Guidance] <br>\n**Output Format:** [Markdown guidance with command snippets, risk findings, remediation examples, and test strategy recommendations] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The helper scripts print order and payment-verification status values; audit guidance is generated locally by the agent.] <br>\n\n## Skill Version(s): <br>\n1.0.18 (source: server release metadata; artifact frontmatter reports 1.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.17: 6 files, 7516 bytes\n\nFiles: scripts/create_order.py (3038b), scripts/file_utils.py (2170b), scripts/service.py (2573b), skill-card.md (1862b), SKILL.md (5239b), _meta.json (131b)\n\nFile v1.0.17:SKILL.md\n\n---\r\nname: \"qa-security\"\r\ndescription: >\r\n  QA and security audit: code vulnerability scanning, dependency analysis, security best practice review. 此为付费技能，使用 clawtip 三阶段支付流程（创建订单 → 支付验证 → 服务交付）。用户提问会通过 HTTPS 发送至服务端用于订单创建，订单元数据保存至本地 ~/.openclaw/skills/orders/ 目录。\r\n  QA and security audit: code vulnerability scanning, dependency analysis, security best practice review\r\nmetadata:\r\n  author: \"Yujin\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n---\r\n\r\n# qa-security\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## Skill Overview\r\n\r\nQuality assurance and security audit service including code vulnerability scanning, dependency analysis, and security best practice review.\r\n\r\n本技能为**付费服务**，采用 clawtip 三阶段支付流程：\r\n\r\n1. **Phase 1 — 创建订单**：将提问通过 HTTPS 发送至服务端，返回订单号并将订单元数据（含提问摘要）保存至本地 `~/.openclaw/skills/orders/` 目录\r\n2. **Phase 2 — 支付处理**：通过 `clawtip` 完成支付验证，支付凭证自动写入本地订单文件\r\n3. **Phase 3 — 服务执行**：验证支付后返回QA与安全审计结果\r\n\r\n用户提问仅用于本次服务的订单生成与履约验证，不会持久化存储或用于其他目的。\r\n\r\n**Direct execution:** If the user has already provided an <<order_no>> (and the order file already contains payCredential), skip directly to the third stage and skip the first two stages.\r\n\r\n---\r\n\r\n## First Stage: Create Order\r\n\r\nIf this is the first interaction and the user has not yet paid, you must first create an order before initiating payment.\r\n\r\n### 1. Required Parameters\r\n* `<question>`: the user's specific question or content.\r\n\r\n### 2. Execution Command\r\n\r\nExecute the order creation script using the following command. Replace `<...>` placeholders with actual values.\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n### 3. Output Processing\r\n\r\n**On success**, the script prints the following key-value pairs to stdout:\r\n\r\n    ORDER_NO=<value>\r\n    AMOUNT=<value>\r\n    QUESTION=<value>\r\n    INDICATOR=<value>\r\n\r\nExtract ORDER_NO and INDICATOR and proceed to the second stage.\r\n\r\n> [!NOTE]\r\n> AMOUNT is in RMB fen. When displaying to the user, divide by 100 and present in yuan.\r\n\r\n**On failure**, the script exits with code 1 and prints:\r\n\r\n    订单创建失败: <error detail>\r\n\r\n> [!CAUTION]\r\n> If the script exits with non-zero code, **immediately terminate the entire workflow** and inform the user of the failure.\r\n\r\n---\r\n\r\n## Second Stage: Payment Processing\r\n\r\nAfter obtaining ORDER_NO and INDICATOR from the first stage, initiate the payment request.\r\n\r\n**Operation:** Use skill `clawtip` to process payment and obtain payment credentials. If this skill does not exist, install it first.\r\n\r\n**Parameters required by `clawtip`:**\r\n\r\n    {\r\n      \"order_no\": \"<ORDER_NO from first stage>\",\r\n      \"indicator\": \"<INDICATOR from first stage>\"\r\n    }\r\n\r\n> [!NOTE]\r\n> All order details (skill-id, order_no, amount, question, description, slug, resource_url etc.) have already been written to a local JSON file by the first stage script. `clawtip` automatically locates and reads the file based on order_no and indicator.\r\n\r\n**Goal:** Wait for payment success and obtain payCredential, which will be automatically written to the order file.\r\n\r\n---\r\n\r\n## Third Stage: Service Execution\r\n\r\nAfter successful payment and obtaining payCredential, resume interaction and execute the service script.\r\n\r\n### 1. Required Parameters\r\n* `<order_no>`: the order number generated in the first stage.\r\n\r\n> [!NOTE]\r\n> payCredential and question do not need to be passed via command line. The script reads them automatically from the order JSON file.\r\n\r\n### 2. Execution Command\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n### 3. Output Processing\r\n\r\n**After execution:**\r\n\r\n1. Extract the PAY_STATUS value (format: `PAY_STATUS: <value>`).\r\n2. If PAY_STATUS is ERROR, extract ERROR_INFO and inform the user.\r\n\r\n| Field | Enum | Output Format |\r\n|-------|------|---------------|\r\n| PAY_STATUS | SUCCESS, PROCESSING, FAIL, ERROR | `PAY_STATUS: SUCCESS` |\r\n| ERROR_INFO | N/A | `ERROR_INFO: <reason>` |\r\n\r\n---\r\n\r\n## Data Handling\r\n\r\n- **Transmitted**: skill slug, order number, user question, encrypted payment data via HTTPS to `https://api.ideaidea.com.cn`\r\n- **Stored locally**: order metadata (order_no, amount, question, payCredential) to `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- **Not collected**: database credentials, API keys, personal files, project content. Note: user question text is transmitted and stored as described above; if it contains code snippets, those are part of the transmitted question\r\n\r\n\r\n---\r\n\r\n## Version History\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard: add question parameter, standardize output |\r\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v1.0.17:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.17\",\n  \"publishedAt\": 1784541391742\n}\n\nFile v1.0.17:skill-card.md\n\n## Description: <br>\nQA/security audit service for code vulnerability scanning, dependency analysis, and security best-practice review. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and security reviewers use this paid ClawHub skill to request QA and security audit assistance for code vulnerability checks, dependency review, and security best-practice feedback. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: User questions, including embedded code snippets, may be transmitted to the provider and saved in local order files. <br>\nMitigation: Avoid including secrets, credentials, or sensitive proprietary code unless that handling is acceptable. <br>\nRisk: Local order files may retain questions and payment metadata after the service interaction. <br>\nMitigation: Periodically remove old order files when they are no longer needed. <br>\n\n\n## Reference(s): <br>\n- [Qa Security ClawHub listing](https://clawhub.ai/jinyu12166/skills/qa-security) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Markdown with shell command outputs] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Returns payment status and, after successful payment verification, QA/security audit guidance from the service.] <br>\n\n## Skill Version(s): <br>\n1.0.17 (source: release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: qa-security Owner: jinyu12166 Summary: Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification. Tags: latest:1.0.27 Version history: v1.0.27 | 2026-07-28T12:48:07.412Z | user Version 1.1.0 - Switched to official clawtip wallet for payment processing. - Removed all references and data transmission to api.i","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"openclaw skills install clawtip"},{"language":"bash","snippet":"python3 scripts/create_order.py \"<question>\""},{"language":"bash","snippet":"npx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12"},{"language":"bash","snippet":"python3 scripts/service.py \"<order_no>\""},{"language":"bash","snippet":"openclaw skills install clawtip"},{"language":"bash","snippet":"python3 scripts/create_order.py \"<question>\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: \"qa-security\"\nversion: \"1.1.0\"\ndescription: >\n  Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# qa-security\n\n请使用中文与用户交互。\n\n## 技能概述\n\n代码质量审计与安全审查服务，覆盖漏洞识别模式、依赖风险评估、安全最佳实践和测试策略设计。付费服务，通过 clawtip 完成支付验证后由 AI 交付审核结果。\n\n**直接执行：** 如用户已提供带支付凭证的订单号，直接跳到第三阶段。\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥（十六进制，32 字符） |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n\n**失败：** `订单创建失败: <详情>` → 终止工作流。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n> [!CAUTION]\n> 技能名称必须严格等于 `clawtip`，不允许替代。\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n| 字段 | 值 | 说明 |\n|------|-----|------|\n| PAY_STATUS | SUCCESS / ERROR | 支付验证状态 |\n| ERROR_INFO | 错误描述 | 失败时的错误原因 |\n\n---\n\n## 数据处理说明\n\n### 本地存储\n订单元数据保存至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`。\n\n### 远程传输\n本技能不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n### 绝不收集或传输\n源代码、项目文件、凭证或 API 密钥。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 1.1.0 | 2026-07-28 | Switch to official clawtip wallet; remove api.ideaidea.com.cn |\n| 1.0.24 | 2026-07-27 | Fix ClawHub audit |\n| 1.0.1 | 2026-07-20 | Fix payment flow |\n| 1.0.0 | 2026-07-19 | Initial release |"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"qa-security\",\n  \"version\": \"1.0.27\",\n  \"publishedAt\": 1785242887412\n}"},{"path":"skill-card.md","content":"## Description:\n\nCode quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment with AI-delivered service access via clawtip verification.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jinyu12166](https://clawhub.ai/user/jinyu12166)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use qa-security to request code quality audits, security review guidance, vulnerability pattern analysis, dependency risk assessment, and testing strategy suggestions after completing the clawtip payment workflow.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill uses a paid clawtip workflow with credential access, network permission, persistent local order files, and external payment tooling.\n\nMitigation: Install only when that payment and permission posture is acceptable for the environment, and review the payment flow before use.\n\nRisk: The local payment verification is weak according to the security guidance.\n\nMitigation: Treat payment authorization as low-assurance until the publisher strengthens credential validation and dependency integrity.\n\nRisk: The initial question may contain sensitive project details, source code, or secrets.\n\nMitigation: Avoid including secrets, source code, credentials, or sensitive project information in the initial consultation question.\n\n## Reference(s):\n\n- [qa-security ClawHub skill page](https://clawhub.ai/jinyu12166/skills/qa-security)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, markdown, shell commands, configuration]\n\n**Output Format:** [Markdown guidance with shell commands and payment status text]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Paid clawtip workflow; order metadata is written locally before service authorization.]\n\n## Skill Version(s):\n\n1.0.27 (source: server release metadata; artifact frontmatter lists 1.1.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification. Skill: qa-security Owner: jinyu12166 Summary: Code quality audit guidance, security review, vulnerability identification patterns, and dependency risk assessment. AI-delivered service via clawtip verification. Tags: latest:1.0.27 Version history: v1.0.27 | 2026-07-28T12:48:07.412Z | user Version 1.1.0 - Switched to official clawtip wallet for payment processing. - Removed all references and data transmission to api.i","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1161,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T22:00:51.837Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T22:00:51.837Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T03:52:35.828Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}