Token导航 LogoToken导航TokenDH.com
研究检索执行命令clawhub未标认证来源可访问clear审计通过

openclaw-route-auditOpenClaw route 审核

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

2,709

周安装

114

GitHub Stars

公开资料未说明

下载量

948
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:openclaw-route-audit(OpenClaw route 审核)
来源仓库:https://github.com/pfrederiksen/openclaw-route-audit
安装命令:
openclaw skills install openclaw-route-audit
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install openclaw-route-audit

简介

静态检查与运行时双重验证 OpenClaw cron 作业路由配置。

  • 用于发现不匹配路径、静默失败与潜在路由异常问题。openclaw-route-audit 属于研究检索类 Skill,可作为该场景下的辅助能力补充。
  • 无需发送测试消息即可完成全面审计,节省调试时间。
  • 需具备对 cron 配置文件的读取权限方可执行扫描任务。
  • 结果仅反映当前快照状态,动态变更需重新运行审计获取最新结论。

SKILL.md

name
openclaw-route-audit
description
Use static route analysis plus runtime cron delivery audit to validate OpenClaw cron notification wiring. Use when auditing cron jobs, announce routing, silent notification failures, sessionKey/target mismatches, ambiguous channel:last usage, or when preparing a ClawHub/GitHub-publishable skill around openclaw-route-check. Repository: https://github.com/pfrederiksen/openclaw-route-check

OpenClaw Route Audit

Use this skill when you need to verify that OpenClaw cron jobs are both:

  • statically routed correctly
  • behaving correctly at runtime

This skill is for auditing and reporting. It does not send test messages.

Repository

Primary tool repo:

  • https://github.com/pfrederiksen/openclaw-route-check

Reference it explicitly when summarizing the static checker or preparing this skill for publishing.

Prerequisites

Required local files:

  • /root/.openclaw/cron/jobs.json
  • /root/.openclaw/workspace/tools/cron_delivery_audit.py

Optional but recommended static checker installation:

  • openclaw-route-check available on PATH
  • or a trusted local install you have inspected yourself

Before running:

  • verify the referenced local files exist
  • inspect local scripts if you did not author them
  • avoid elevated/root execution unless you actually need it
  • confirm the cron config being read does not contain secrets you are unwilling to inspect locally

When to use

Use this skill for requests like:

  • "audit cron notifications"
  • "why didn’t this cron notify me"
  • "check announce routing"
  • "find silent delivery bugs"
  • "review sessionKey / channel / target mismatches"
  • "prepare this for ClawHub or GitHub"

Core workflow

  1. Run the local runtime audit:

- python3 /root/.openclaw/workspace/tools/cron_delivery_audit.py

  1. Run the static route checker against the real cron config using a trusted openclaw-route-check installation.
  2. Compare both outputs.
  3. Prioritize real bugs in this order:

- jobs with summary text but not delivered - jobs whose prompts say to return user-visible text for cron delivery but use delivery.mode: none - jobs with ambiguous routing (channel:last, implicit target, mismatched sessionKey vs target)

  1. Patch the actual failing layer.

Safe patching guidance

Prefer these fixes:

  • set explicit delivery.channel and delivery.to
  • change delivery.mode from none to announce when the prompt explicitly returns user-visible text for cron delivery
  • keep mode: none for jobs that intentionally use the message tool or are explicitly silent-on-success

Do not claim a job is broken just because it is silent. Confirm whether the prompt intends silence.

Publishing hygiene

If publishing to ClawHub or GitHub:

  • keep the skill read-only by default
  • avoid embedding secrets, tokens, webhook URLs, cookies, chat ids beyond public examples already present in the user’s config
  • avoid curl-to-shell installers in the skill
  • avoid auto-download or self-update behavior
  • prefer pinned local paths and deterministic commands
  • include the upstream repository link in SKILL.md
  • list required local paths and prerequisites explicitly

VirusTotal-friendly posture

To keep this easy to review and low-risk:

  • no obfuscated code
  • no packed binaries
  • no outbound network writes in bundled scripts
  • no persistence or daemon setup
  • no privilege escalation
  • no credential scraping

Bundled script should stay plain text, short, and readable.

Bundled files

  • scripts/run_route_audit.sh: runs both audits and prints combined JSON after prerequisite checks
  • references/publish-checklist.md: lightweight publication checklist for ClawHub/GitHub
  • references/github-publish-notes.md: GitHub repo positioning notes

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

83.02%
按下载量换算787

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

执行命令

安装流程涉及命令执行,可能通过 openclaw skills install openclaw-route-audit 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills