activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
Crawler Summary
本地安全审计 Skill - 在安装第三方 Skills 前进行静态安全扫描,检测恶意代码模式、混淆payload、可疑命令组合等威胁。 --- name: security-auditor description: 本地安全审计 Skill - 在安装第三方 Skills 前进行静态安全扫描,检测恶意代码模式、混淆payload、可疑命令组合等威胁。 user-invocable: true metadata: { "openclaw": { "emoji": "🔒", }, } --- Security Auditor Skill 在安装/更新第三方 Skills 之前进行静态安全扫描,防止恶意代码进入你的系统。 使用场景 当用户: - 安装新的 skill (clawhub install xxx) - 从 GitHub 手动拉取 skill - 更新现有 skill - 想检查某个 skill 目录是否安全 触发词 - "扫描这个 skill" - "安全检查" - "审核 skill" - "检查安全性" - "scan skill" - "secur Capability contract not published. No trust telemetry is available yet. Last updated 2/24/2026.
Freshness
Last checked 2/24/2026
Best For
security-auditor is best for skill workflows where OpenClaw compatibility matters.
Not Ideal For
Contract metadata is missing or unavailable for deterministic execution.
Evidence Sources Checked
editorial-content, GITHUB OPENCLEW, runtime-metrics, public facts pack
本地安全审计 Skill - 在安装第三方 Skills 前进行静态安全扫描,检测恶意代码模式、混淆payload、可疑命令组合等威胁。 --- name: security-auditor description: 本地安全审计 Skill - 在安装第三方 Skills 前进行静态安全扫描,检测恶意代码模式、混淆payload、可疑命令组合等威胁。 user-invocable: true metadata: { "openclaw": { "emoji": "🔒", }, } --- Security Auditor Skill 在安装/更新第三方 Skills 之前进行静态安全扫描,防止恶意代码进入你的系统。 使用场景 当用户: - 安装新的 skill (clawhub install xxx) - 从 GitHub 手动拉取 skill - 更新现有 skill - 想检查某个 skill 目录是否安全 触发词 - "扫描这个 skill" - "安全检查" - "审核 skill" - "检查安全性" - "scan skill" - "secur
Public facts
4
Change events
1
Artifacts
0
Freshness
Feb 24, 2026
Capability contract not published. No trust telemetry is available yet. Last updated 2/24/2026.
Trust score
Unknown
Compatibility
OpenClaw
Freshness
Feb 24, 2026
Vendor
Cumuifreer
Artifacts
0
Benchmarks
0
Last release
Unpublished
Key links, install path, and a quick operational read before the deeper crawl record.
Summary
Capability contract not published. No trust telemetry is available yet. Last updated 2/24/2026.
Setup snapshot
git clone https://github.com/Cumuifreer/security-auditor-skill.gitSetup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.
Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Everything public we have scraped or crawled about this agent, grouped by evidence type with provenance.
Vendor
Cumuifreer
Protocol compatibility
OpenClaw
Handshake status
UNKNOWN
Crawlable docs
6 indexed pages on the official domain
Merged public release, docs, artifact, benchmark, pricing, and trust refresh events.
Extracted files, examples, snippets, parameters, dependencies, permissions, and artifact metadata.
Extracted files
0
Examples
6
Snippets
0
Languages
typescript
Parameters
bash
# 扫描当前目录的 skill security-audit # 扫描指定路径 security-audit /path/to/skill # 扫描 ClawHub 安装的 skill security-audit ~/.openclaw/skills/xxx
bash
# 快速扫描 (仅关键危险) security-audit --fast # 完整扫描 (包括中低风险) security-audit --full # 输出 JSON 格式 security-audit --json
text
🔒 Security Audit Report ======================== Path: ~/.openclaw/skills/suspicious-skill Date: 2026-02-22 19:30:00 CRITICAL: 2 [!] curl | bash detected (install.sh:23) [!] base64 encoded payload >2KB (lib/utils.js:45) HIGH: 1 [!] Hardcoded API key (config.json:8) MEDIUM: 3 [!] HTTP URL found (api.js:12) [!] Unknown binary (bin/malware) WHITELISTED: 5 ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ ⚠️ RECOMMENDATION: DO NOT INSTALL Found 2 CRITICAL threats. This skill appears malicious.
javascript
const CRITICAL_PATTERNS = [ /curl\s*\|\s*bash/i, /wget\s*\|\s*bash/i, /base64\s+-d\s*\|\s*(bash|sh|zsh)/i, /eval\s*\$\(/i, /xattr\s+-r.*com\.apple\.quarantine/i, ];
javascript
const MAGIC_NUMBERS = {
'exe': '4d5a',
'mach-o': 'feedface',
'elf': '7f454c46',
'zip': '504b',
};json
{
"whitelist": [
"skill-name:hash",
"another-skill:hash"
]
}Full documentation captured from public sources, including the complete README when available.
Docs source
GITHUB OPENCLEW
Editorial quality
ready
本地安全审计 Skill - 在安装第三方 Skills 前进行静态安全扫描,检测恶意代码模式、混淆payload、可疑命令组合等威胁。 --- name: security-auditor description: 本地安全审计 Skill - 在安装第三方 Skills 前进行静态安全扫描,检测恶意代码模式、混淆payload、可疑命令组合等威胁。 user-invocable: true metadata: { "openclaw": { "emoji": "🔒", }, } --- Security Auditor Skill 在安装/更新第三方 Skills 之前进行静态安全扫描,防止恶意代码进入你的系统。 使用场景 当用户: - 安装新的 skill (clawhub install xxx) - 从 GitHub 手动拉取 skill - 更新现有 skill - 想检查某个 skill 目录是否安全 触发词 - "扫描这个 skill" - "安全检查" - "审核 skill" - "检查安全性" - "scan skill" - "secur
在安装/更新第三方 Skills 之前进行静态安全扫描,防止恶意代码进入你的系统。
当用户:
clawhub install xxx)# 扫描当前目录的 skill
security-audit
# 扫描指定路径
security-audit /path/to/skill
# 扫描 ClawHub 安装的 skill
security-audit ~/.openclaw/skills/xxx
# 快速扫描 (仅关键危险)
security-audit --fast
# 完整扫描 (包括中低风险)
security-audit --full
# 输出 JSON 格式
security-audit --json
| 模式 | 描述 |
|------|------|
| curl \| bash | 下载并直接执行远程脚本 |
| curl > .bashrc | 写入 shell 配置 |
| curl > ~/.ssh | 写入 SSH 密钥 |
| wget \| bash | 同 curl|bash |
| base64 -d \| bash | 混淆后执行 |
| chmod +x + 网络下载 | 下载并赋予执行权限 |
| Gatekeeper bypass | xattr -rd com.apple.quarantine |
| 模式 | 描述 |
|------|------|
| eval $(curl | 远程代码注入 |
| openssl ... | bash | 下载并执行 OpenSSL |
| 加密货币钱包替换 | 替换钱包地址 |
| sudo ... 无确认 | 静默提权 |
| 导出凭据到远程 | export CREDENTIALS |
| 模式 | 描述 | |------|------| | Base64 编码块 >1KB | 可能的混淆 payload | | 外部 API 密钥硬编码 | 可能的凭据泄露 | | HTTP (非 HTTPS) | 不安全传输 | | 未知二进制文件 | 可能的恶意程序 |
| 模式 | 描述 | |------|------| | 无 package.json 的 Node skill | 依赖不明 | | 未知来源的二进制 | 需确认 | | 敏感路径写入 | 需确认意图 |
🔒 Security Audit Report
========================
Path: ~/.openclaw/skills/suspicious-skill
Date: 2026-02-22 19:30:00
CRITICAL: 2
[!] curl | bash detected (install.sh:23)
[!] base64 encoded payload >2KB (lib/utils.js:45)
HIGH: 1
[!] Hardcoded API key (config.json:8)
MEDIUM: 3
[!] HTTP URL found (api.js:12)
[!] Unknown binary (bin/malware)
WHITELISTED: 5
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
⚠️ RECOMMENDATION: DO NOT INSTALL
Found 2 CRITICAL threats. This skill appears malicious.
扫描以下文件类型:
*.sh (Shell 脚本)*.js, *.ts (JavaScript/TypeScript)*.py (Python)*.json (配置文件)使用正则表达式检测已知恶意模式:
const CRITICAL_PATTERNS = [
/curl\s*\|\s*bash/i,
/wget\s*\|\s*bash/i,
/base64\s+-d\s*\|\s*(bash|sh|zsh)/i,
/eval\s*\$\(/i,
/xattr\s+-r.*com\.apple\.quarantine/i,
];
检测伪装成文本的二进制文件:
const MAGIC_NUMBERS = {
'exe': '4d5a',
'mach-o': 'feedface',
'elf': '7f454c46',
'zip': '504b',
};
检测危险命令组合:
curl + | + bashwget + chmod +xbase64 + eval记录已知安全的 skill 特征哈希,减少误报:
{
"whitelist": [
"skill-name:hash",
"another-skill:hash"
]
}
无需额外依赖,使用系统原生工具:
grep / egrep - 模式匹配file - 文件类型检测xxd / hexdump - 十六进制查看"Trust but Verify"
Machine endpoints, protocol fit, contract coverage, invocation examples, and guardrails for agent-to-agent use.
Contract coverage
Status
missing
Auth
None
Streaming
No
Data region
Unspecified
Protocol support
Requires: none
Forbidden: none
Guardrails
Operational confidence: low
curl -s "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/contract"
curl -s "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/trust"
Trust and runtime signals, benchmark suites, failure patterns, and practical risk constraints.
Trust signals
Handshake
UNKNOWN
Confidence
unknown
Attempts 30d
unknown
Fallback rate
unknown
Runtime metrics
Observed P50
unknown
Observed P95
unknown
Rate limit
unknown
Estimated cost
unknown
Do not use if
Every public screenshot, visual asset, demo link, and owner-provided destination tied to this agent.
Neighboring agents from the same protocol and source ecosystem for comparison and shortlist building.
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
The Frontend for Agents & Generative UI. React + Angular
Contract JSON
{
"contractStatus": "missing",
"authModes": [],
"requires": [],
"forbidden": [],
"supportsMcp": false,
"supportsA2a": false,
"supportsStreaming": false,
"inputSchemaRef": null,
"outputSchemaRef": null,
"dataRegion": null,
"contractUpdatedAt": null,
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Invocation Guide
{
"preferredApi": {
"snapshotUrl": "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/snapshot",
"contractUrl": "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/contract",
"trustUrl": "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/trust"
},
"curlExamples": [
"curl -s \"https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/snapshot\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/contract\"",
"curl -s \"https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/trust\""
],
"jsonRequestTemplate": {
"query": "summarize this repo",
"constraints": {
"maxLatencyMs": 2000,
"protocolPreference": [
"OPENCLEW"
]
}
},
"jsonResponseTemplate": {
"ok": true,
"result": {
"summary": "...",
"confidence": 0.9
},
"meta": {
"source": "GITHUB_OPENCLEW",
"generatedAt": "2026-10-09T04:42:24.658Z"
}
},
"retryPolicy": {
"maxAttempts": 3,
"backoffMs": [
500,
1500,
3500
],
"retryableConditions": [
"HTTP_429",
"HTTP_503",
"NETWORK_TIMEOUT"
]
}
}Trust JSON
{
"status": "unavailable",
"handshakeStatus": "UNKNOWN",
"verificationFreshnessHours": null,
"reputationScore": null,
"p95LatencyMs": null,
"successRate30d": null,
"fallbackRate": null,
"attempts30d": null,
"trustUpdatedAt": null,
"trustConfidence": "unknown",
"sourceUpdatedAt": null,
"freshnessSeconds": null
}Capability Matrix
{
"rows": [
{
"key": "OPENCLEW",
"type": "protocol",
"support": "unknown",
"confidenceSource": "profile",
"notes": "Listed on profile"
},
{
"key": "skill",
"type": "capability",
"support": "supported",
"confidenceSource": "profile",
"notes": "Declared in agent profile metadata"
}
],
"flattenedTokens": "protocol:OPENCLEW|unknown|profile capability:skill|supported|profile"
}Facts JSON
[
{
"factKey": "docs_crawl",
"category": "integration",
"label": "Crawlable docs",
"value": "6 indexed pages on the official domain",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
},
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Cumuifreer",
"href": "https://github.com/Cumuifreer/security-auditor-skill",
"sourceUrl": "https://github.com/Cumuifreer/security-auditor-skill",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-02-24T19:43:55.858Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-02-24T19:43:55.858Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/cumuifreer-security-auditor-skill/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
]Change Events JSON
[
{
"eventType": "docs_update",
"title": "Docs refreshed: Sign in to GitHub · GitHub",
"description": "Fresh crawlable documentation was indexed for the official domain.",
"href": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceUrl": "https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fopenclaw%2Fskills%2Ftree%2Fmain%2Fskills%2Fasleep123%2Fcaldav-calendar",
"sourceType": "search_document",
"confidence": "medium",
"observedAt": "2026-04-15T05:03:46.393Z",
"isPublic": true
}
]Sponsored
Ads related to security-auditor and adjacent AI workflows.