Token导航 LogoToken导航TokenDH.com
开发敏感数据clawhub未标认证来源可访问clear审计通过

moltblockmoltblock 开发

Agent Skill

moltblock 用于补充开发相关能力,适合在 OpenClaw 中需要让 Agent 承接开发相关任务时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

46,688

周安装

1,965

GitHub Stars

3

下载量

16,349
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:moltblock(moltblock 开发)
来源仓库:https://github.com/meshailabs/moltblock
安装命令:
openclaw skills install moltblock
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install moltblock

简介

moltblock 作为 AI 生成工件的验证门控,实施策略检查以防止危险模式执行。

  • 适用于 OpenClaw 中的安全部署流程。
  • 通过 openclaw skills install moltblock 命令安装使用。
  • 需自定义策略规则以适应具体业务场景。
  • moltblock 属于开发类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

name
moltblock - Trust Layer for AI Agents
description
Verification gating for AI-generated artifacts. Policy checks to catch dangerous patterns before execution.
version
0.11.8
homepage
https://github.com/moltblock/moltblock
repository
https://github.com/moltblock/moltblock
metadata
openclaw
requires
anyBins
optionalConfig
primaryEnv
OPENAI_API_KEY
optionalEnv
homepage
https://github.com/moltblock/moltblock
install
package
moltblock@0.11.8
bins
[moltblock]

moltblock — Trust Layer for AI Agents

Description

Moltblock provides verification gating for AI-generated artifacts. It runs policy checks to catch dangerous patterns before they reach production.

What moltblock does:

  • Generates artifacts via LLM API calls, then runs policy checks against the output
  • Returns a structured verification result (pass/fail with evidence)
  • Optionally reads config files (moltblock.json, ~/.moltblock/moltblock.json) if present — no config is required
  • API keys are read from environment variables at runtime and sent only to the configured LLM provider endpoint
  • No code execution occurs — moltblock only performs policy checks on generated artifacts

When to Use

Use moltblock when the task involves:

  • High risk (always verify): Destructive operations (rm -rf, DROP TABLE), privilege escalation (sudo, chmod 777), credential/key access (.ssh/, id_rsa, .env), system modification, raw disk writes
  • Medium risk (verify when uncertain): Network requests (curl, wget, fetch), file writes, database modifications, subprocess spawning, dynamic code evaluation
  • Low risk (skip verification): Simple text responses, math, reading public information, code that doesn't touch the filesystem or network

Tool: moltblock

Verify a task before execution.

Usage

npx moltblock@0.11.8 "<task description>" --provider <provider> --json

Parameters

ParameterRequiredDescription
taskYesThe task description to verify
--providerNoLLM provider: openai, google, zai, local (auto-detected from env)
--modelNoModel override
--jsonNoOutput structured JSON result

Environment Variables

Moltblock auto-detects the LLM provider from whichever API key is set. If no key is set, it falls back to a local LLM at localhost:1234. Set one of these for a cloud provider:

  • OPENAI_API_KEY — OpenAI (primary)
  • ANTHROPIC_API_KEY — Anthropic/Claude (optional)
  • GOOGLE_API_KEY — Google/Gemini (optional)
  • ZAI_API_KEY — ZAI (optional)

Example

# Verify a task
npx moltblock@0.11.8 "implement a function that validates email addresses" --json

Output (JSON mode)

{
  "verification_passed": true,
  "verification_evidence": "All policy rules passed.",
  "authoritative_artifact": "...",
  "draft": "...",
  "critique": "...",
  "final_candidate": "..."
}

Installation

Use directly with npx (recommended, no install needed):

npx moltblock@0.11.8 "your task" --json

Or install globally:

npm install -g moltblock@0.11.8

Configuration

No configuration file is required. Moltblock auto-detects your LLM provider from environment variables and falls back to sensible defaults.

Optionally, place moltblock.json in your project root or ~/.moltblock/moltblock.json to customize model bindings:

{
  "agent": {
    "bindings": {
      "generator": { "backend": "google", "model": "gemini-2.0-flash" },
      "critic": { "backend": "google", "model": "gemini-2.0-flash" },
      "judge": { "backend": "google", "model": "gemini-2.0-flash" }
    }
  }
}

See the full configuration docs for policy rules and advanced options.

Source

Security

When used as a skill, moltblock performs policy checks only — no code is generated, written to disk, or executed. The tool analyzes task descriptions against configurable policy rules and returns a pass/fail verification result.

API key scope: Consider using a limited-scope API key dedicated to verification rather than a key with broader permissions.

Disclaimer

Moltblock reduces risk but does not eliminate it. Verification is best-effort — policy rules and LLM-based checks can miss dangerous patterns. Always review generated artifacts before executing them. The authors and contributors are not responsible for any damage, data loss, or security incidents resulting from the use of this tool. Use at your own risk.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

70.86%
按下载量换算11,585

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills