Token导航 LogoToken导航TokenDH.com
运维需要联网clawhub未标认证来源可访问clear审计通过

afrexai-ai-safety-auditAfrexai AI 安全审计

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

15,150

周安装

625

GitHub Stars

公开资料未说明

下载量

4,950
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:afrexai-ai-safety-audit(Afrexai AI 安全审计)
来源仓库:https://github.com/1kalin/afrexai-ai-safety-audit
安装命令:
openclaw skills install afrexai-ai-safety-audit
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install afrexai-ai-safety-audit

简介

Afrexai AI Safety Audit 执行覆盖六大领域的 30 项安全控制措施评估。

  • 将系统映射至欧盟人工智能法案风险分类,生成可操作的 90 天整改计划。
  • 重点检查认证流程、密钥管理与漏洞暴露面,降低恶意利用可能性。
  • 审计结论需经人工复核,尤其涉及生产系统时应先隔离测试环境验证。
  • 敏感凭据不得明文输出,所有发现项必须关联最小权限原则进行修复。

SKILL.md

AI Safety Audit

Comprehensive AI safety and alignment audit framework for businesses deploying AI agents. Built around the UK AI Security Institute Alignment Project standards (2026), EU AI Act requirements, and NIST AI RMF.

What This Skill Does

When activated, the agent performs a structured safety audit of your AI deployment:

  1. AI System Inventory — Catalogs all AI models, agents, and automated decision systems in use
  2. Risk Classification — Maps each system to EU AI Act risk tiers (Unacceptable/High/Limited/Minimal)
  3. Safety Controls Assessment — Evaluates 30 controls across 6 domains
  4. Gap Analysis — Identifies missing safeguards with severity and remediation cost
  5. Compliance Roadmap — Generates a prioritized 90-day action plan

6 Audit Domains (30 Controls)

1. Model Governance (5 controls)

  • Model registry with version tracking
  • Access control and deployment permissions
  • Update and rollback procedures
  • Vendor risk assessment for third-party models
  • Model retirement and data deletion policy

2. Data Protection (5 controls)

  • Data residency and sovereignty mapping
  • PII detection and handling in AI pipelines
  • Training data provenance documentation
  • Data retention aligned with AI lifecycle
  • Cross-border data transfer compliance

3. Output Safety (5 controls)

  • Hallucination detection and mitigation
  • Bias testing across protected characteristics
  • Content filtering for harmful outputs
  • Confidence scoring and uncertainty flagging
  • Human-in-the-loop for high-stakes decisions

4. Security (5 controls)

  • Prompt injection defense
  • Model extraction prevention
  • API rate limiting and abuse detection
  • Adversarial input testing
  • Supply chain security for AI dependencies

5. Monitoring & Observability (5 controls)

  • Real-time output quality tracking
  • Drift detection (data and model)
  • Incident logging and alerting
  • Performance degradation monitoring
  • Cost tracking per AI workflow

6. Organizational Readiness (5 controls)

  • Named AI safety officer
  • Staff training program with completion tracking
  • Board-level AI risk reporting
  • Incident response playbook
  • Third-party audit schedule

Scoring

Each control scores 0-3:

  • 0 — Not implemented
  • 1 — Partially implemented, no documentation
  • 2 — Implemented with documentation
  • 3 — Implemented, documented, tested, and audited

Total: 90 points max

  • 0-30: Critical risk — stop deploying until gaps are addressed
  • 31-55: High risk — remediate within 30 days
  • 56-75: Moderate risk — address within 90 days
  • 76-90: Strong posture — maintain and iterate

Regulatory Mapping

FrameworkStatusKey Requirements
EU AI ActEnforcing 2026Risk classification, conformity assessment, transparency
UK AI Safety InstituteActive 2026Alignment testing, frontier model evaluation
NIST AI RMFPublishedGovern, Map, Measure, Manage lifecycle
ISO 42001PublishedAI management system certification
SOC 2 + AIEmergingAgent-specific controls (CC6/CC7/CC8)

Cost Benchmarks

Company SizeFull Audit CostAnnual ComplianceNon-Compliance Risk
15-50 employees$8K – $20K$18K – $45K$200K+
50-200 employees$20K – $55K$45K – $120K$500K – $2M
200-1000 employees$55K – $150K$120K – $400K$2M – $10M

Output Format

The agent delivers:

  1. Executive Summary — Overall score, top 3 risks, recommended actions
  2. Detailed Scorecard — All 30 controls with scores and evidence
  3. Gap Analysis — Missing controls ranked by risk severity
  4. 90-Day Roadmap — Phased remediation plan with cost estimates
  5. Board Report Template — One-page summary for leadership

Industry Adjustments

The audit adjusts control weighting based on industry:

  • Healthcare: Output safety and data protection weighted 2x
  • Financial Services: Model governance and monitoring weighted 2x
  • Legal: Output safety (hallucination) weighted 3x
  • Manufacturing: Security and monitoring weighted 2x
  • Government/Defense: All domains weighted equally at maximum

Go Deeper

Bundles

  • AI Playbook — $27
  • Pick 3 Industries — $97
  • All 10 Industries — $197
  • Everything Bundle — $247

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

86.22%
按下载量换算4,268

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

未展示

权限和风险

需要联网

该 Skill 可能需要联网访问来源站点、仓库或外部 API;具体网络访问范围需要结合源码和 README 复核。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills