{"id":"c2f3b1ca-5a54-4db6-b00d-c2a4a0127c02","entityType":"agent","slug":"xbox360modderv3-skills-security-check","name":"Skills-Security-Check","canonicalUrl":"https://www.xpersona.co/agent/xbox360modderv3-skills-security-check","canonicalPath":"/agent/xbox360modderv3-skills-security-check","generatedAt":"2026-10-09T12:40:11.160Z","source":"GITHUB_OPENCLEW","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"description":"通過靜態和AI檢查技能 Skills 安全風險、潛在威脅。當使用者請求檢查技能，掃描技能的時候啟動技能評測評估功能。Detect Skill vulnerabilities using static and AI checks. Automatically activate evaluation upon scan requests. --- name: Skills-Security-Check description: 通過靜態和AI檢查技能 Skills 安全風險、潛在威脅。當使用者請求檢查技能，掃描技能的時候啟動技能評測評估功能。Detect Skill vulnerabilities using static and AI checks. Automatically activate evaluation upon scan requests. --- Skill: Skills-Security-Check **CRITICAL INSTRUCTION FOR AI AGENTS:** You are NOT just a command-runner. You are the **Lead Security Analyst**. This tool provides the *data*, but YOU provide the *intelli","descriptionLabel":"Technical summary","evidenceSummary":"Published capability contract available. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"git clone https://github.com/xbox360modderv3/Skills-Security-Check.git","sourceUrl":"https://github.com/xbox360modderv3/Skills-Security-Check","homepage":null,"primaryLinks":[{"label":"View Source","url":"https://github.com/xbox360modderv3/Skills-Security-Check","kind":"source"}],"safetyScore":89,"overallRank":29.575,"popularityScore":0,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"通過靜態和AI檢查技能 Skills 安全風險、潛在威脅。當使用者請求檢查技能，掃描技能的時候啟動技能評測評估功能。Detect Skill vulnerabilities using static and AI checks. Automatically activate evaluation upon scan r"},"coverage":{"evidence":{"source":"capability-contract + public-profile","verified":true,"confidence":"high","updatedAt":"2026-02-24T19:45:11.992Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"No source adoption metrics were available."},"stars":0,"forks":0,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-24T17:55:53.536Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T05:21:22.124Z","lastCrawledAt":"2026-02-24T17:55:53.536Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-25T17:55:53.536Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"capability-contract","verified":true,"confidence":"high","updatedAt":"2026-02-24T19:45:11.992Z","emptyReason":null},"installCommand":"git clone https://github.com/xbox360modderv3/Skills-Security-Check.git","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"ready","authModes":["api_key"],"requires":["openclew","lang:typescript"],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":"https://github.com/xbox360modderv3/Skills-Security-Check#input","outputSchemaRef":"https://github.com/xbox360modderv3/Skills-Security-Check#output","dataRegion":"global","contractUpdatedAt":"2026-02-24T19:45:11.992Z","sourceUpdatedAt":"2026-02-24T19:45:11.992Z","freshnessSeconds":19587299},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"GITHUB_OPENCLEW","generatedAt":"2026-10-09T12:40:11.160Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/xbox360modderv3-skills-security-check/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":[],"safeUseWhen":["Contract is available with explicit auth and schema references.","Trust confidence is not low and verification freshness is acceptable."],"riskFlags":["trust_data_unavailable"],"operationalConfidence":"medium"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"GITHUB OPENCLEW","verified":false,"confidence":"high","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":null},"readme":"---\nname: Skills-Security-Check\ndescription: 通過靜態和AI檢查技能 Skills 安全風險、潛在威脅。當使用者請求檢查技能，掃描技能的時候啟動技能評測評估功能。Detect Skill vulnerabilities using static and AI checks. Automatically activate evaluation upon scan requests.\n---\n\n# Skill: Skills-Security-Check\n\n**CRITICAL INSTRUCTION FOR AI AGENTS:**\nYou are NOT just a command-runner. You are the **Lead Security Analyst**.\nThis tool provides the *data*, but YOU provide the *intelligence*.\n\n## ⚡️ The 3-Step Agentic Workflow (MANDATORY)\n\nYou MUST follow this loop whenever using this skill:\n\n### Step 1: Run the Scanner (Data Collection)\nExecute the scanner to generate the raw data and \"Audit Prompts\".\n```bash\npython3 scripts/scan_skills.py --root /path/to/target/projects\n```\n*This command will generate `*_audit_prompt.txt` files in the `reports/YYYYMMDD.../prompts/` directory.*\n\n### Step 2: 🛑 MANDATORY AI ANALYSIS (CRITICAL)\n**The Scanner's job is done. Now YOUR job begins.**\nYou MUST process the generated audit prompts.\n\n**Option A (Best):** Automatically read the prompts and analyze them immediately.\n**Option B (Fallback):** If you cannot read them automatically, YOU MUST ASK THE USER:\n> \"Scanner finished. I see {N} audit prompts generated. Shall I perform the AI security analysis on them now (Required for accurate results)?\"\n\n**Requirement:**\n- You must analyze **ALL** skills generating a prompt, regardless of risk level.\n- Generate `audit.json` for each skill.\n\n### Step 3: Integrate & Present\nRun the scanner ONE MORE TIME. It will detect your `audit.json` files and bake them into the final report.\n```bash\npython3 scripts/scan_skills.py --root /path/to/target/projects\n```\n*The scanner will now produce the 'Gold Standard' dashboard and automatically open it.*\n\n---\n\n## Technical Details\n- **Scanner Logic**: Regex-based static analysis. High false-positive rate.\n- **Agent's Role**: Filter false positives, provide context, and assess actual business risk.\n- **Output**: `reports/YYYYMMDD_HHMMSS/index.html` (The final artifact for the user).\n\n**Example Scenario**:\nUser: \"Audit my skills.\"\nAgent: \n1. Runs `scan_skills.py`.\n2. Sees `zimage_audit_prompt.txt` flagged \"High Risk\".\n3. Reads the prompt, realizes it's just an API client.\n4. Writes `audit.json` marking it \"Medium Risk\" (requires API key).\n5. Re-runs `scan_skills.py` to finalize the dashboard.\n\n## How to run\n\n1. Run the scanner on a root folder that contains multiple skills:\n\n```bash\npython3 /Users/mattchan/.agents/skills/skill-security-audit-dashboard/scripts/scan_skills.py \\\n  --root /Users/mattchan/.agents/skills \\\n  --out /Users/mattchan/.agents/skills/skill-security-audit-dashboard/security-dashboard.html\n```\n\n2. Open the generated HTML dashboard file to view the results.\n\n## Notes\n\n- This is a static heuristic scan. It does not execute code.\n- The scanner avoids outputting raw secrets. It only reports file locations and categories.\n- If you need a JSON file as well, pass `--json /path/to/output.json`.\n\n## Arguments\n\n- `--root`: Root directory containing skills (default: current working directory).\n- `--out`: Path to the output HTML dashboard.\n- `--json`: Optional path to write raw JSON output.\n","readmeExcerpt":"--- name: Skills-Security-Check description: 通過靜態和AI檢查技能 Skills 安全風險、潛在威脅。當使用者請求檢查技能，掃描技能的時候啟動技能評測評估功能。Detect Skill vulnerabilities using static and AI checks. Automatically activate evaluation upon scan requests. --- Skill: Skills-Security-Check **CRITICAL INSTRUCTION FOR AI AGENTS:** You are NOT just a command-runner. You are the **Lead Security Analyst**. This tool provides the *data*, but YOU provide the *intelli","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"python3 scripts/scan_skills.py --root /path/to/target/projects"},{"language":"bash","snippet":"python3 scripts/scan_skills.py --root /path/to/target/projects"},{"language":"bash","snippet":"python3 /Users/mattchan/.agents/skills/skill-security-audit-dashboard/scripts/scan_skills.py \\\n  --root /Users/mattchan/.agents/skills \\\n  --out /Users/mattchan/.agents/skills/skill-security-audit-dashboard/security-dashboard.html"}],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"GITHUB OPENCLEW","editorialOverview":"通過靜態和AI檢查技能 Skills 安全風險、潛在威脅。當使用者請求檢查技能，掃描技能的時候啟動技能評測評估功能。Detect Skill vulnerabilities using static and AI checks. Automatically activate evaluation upon scan requests. --- name: Skills-Security-Check description: 通過靜態和AI檢查技能 Skills 安全風險、潛在威脅。當使用者請求檢查技能，掃描技能的時候啟動技能評測評估功能。Detect Skill vulnerabilities using static and AI checks. Automatically activate evaluation upon scan requests. --- Skill: Skills-Security-Check **CRITICAL INSTRUCTION FOR AI AGENTS:** You are NOT just a command-runner. You are the **Lead Security Analyst**. This tool provides the *data*, but YOU provide the *intelli","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":383,"uniquenessScore":63,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T05:21:22.124Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T12:40:11.160Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/github_openclew","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}