Token导航 LogoToken导航TokenDH.com
研究检索操作浏览器clawhub未标认证来源可访问clear审计通过

osv-ui操作系统用户界面

Agent Skill

用于辅助界面设计、视觉规范、排版、配色、布局和交互体验优化。它适合让 Agent 根据产品场景整理页面结构、生成 UI 方案、检查视觉一致性或改进组件层级。使用时需要结合现有品牌、设计系统和用户任务,不应只堆装饰元素;涉及真实页面改动时,应通过截图或浏览器预览检查文本溢出、对齐和响应式表现。

总安装

4,633

周安装

195

GitHub Stars

公开资料未说明

下载量

1,622
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:osv-ui(操作系统用户界面)
来源仓库:https://github.com/toan203/osv-ui
安装命令:
openclaw skills install osv-ui
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install osv-ui

简介

用于辅助界面设计、视觉规范和交互体验优化,适合整理页面结构或生成 UI 方案。

  • 适用于产品场景中的布局规划、组件层级梳理和视觉一致性检查。
  • 需结合品牌规范与用户任务使用,避免堆砌装饰元素;涉及页面改动时应通过预览验证表现。
  • 安装前请确认权限范围,建议通过截图或浏览器检查文本溢出与响应式效果。
  • 注意:不直接修改生产环境代码,仅提供设计支持与参考方案。

SKILL.md

name
osv-ui
description
Security auditing skill for scanning CVE vulnerabilities across npm, Python, Go, and Rust projects using osv-ui. Opens a visual browser dashboard for human review, then applies fixes with explicit confirmation.
version
1.0.0
author
toan203
homepage
https://github.com/toan203/osv-ui
tags
[security, cve, vulnerability, npm, python, go, rust, audit, dependabot]
tools
[bash, computer]

osv-ui — CVE Audit Skill

Use this skill whenever the user asks to:

  • Audit, scan, or check dependencies for vulnerabilities or CVEs
  • Find security issues in their npm, Python, Go, or Rust project
  • Get a visual security report or dashboard
  • Fix or upgrade vulnerable packages
  • Replace or complement npm audit, pip-audit, Snyk, or Dependabot

When to activate

Activate when the user mentions any of:

  • "audit", "scan", "CVE", "vulnerability", "security", "dependabot", "snyk"
  • "check my packages", "upgrade guide", "fix vulnerabilities"
  • "npm audit", "pip-audit", "cargo audit", "govulncheck"
  • "is my project secure?", "any known issues in my deps?"

Workflow

1 — Scan

# Single service
npx osv-ui --no-open --json ./osv-report.json

# Multiple services
npx osv-ui ./frontend ./api ./worker --no-open --json ./osv-report.json

# Auto-discover
npx osv-ui --discover --no-open --json ./osv-report.json

2 — Present summary

Parse osv-report.json and show:

📊 [project]: [N] packages · 🔴 Critical: N · 🟠 High: N · 🟡 Moderate: N · 🔵 Low: N · Risk: N/100
Top CVEs: [list top 5 by severity with fix version]

3 — Always offer the visual dashboard

"Want to review in a visual dashboard before I apply any fixes?"
npx osv-ui [same paths]
# Opens http://localhost:2003

4 — Show fix commands, get confirmation

Show what will change. NEVER apply without explicit user "yes".

npm install axios@0.30.3      # fixes 4 CVEs
npm install lodash@4.17.23    # fixes 3 CVEs

5 — Apply and verify

# Apply fixes
npm install [package@version]

# Re-scan to confirm
npx osv-ui --no-open --json ./osv-report-after.json

Notes

  • Never apply fixes silently — always confirm first
  • Prefer dashboard for 10+ CVEs
  • Alpha/beta/canary versions are never suggested as fix targets
  • Add --offline if OSV.dev is unreachable

Quick reference

npx osv-ui                          # scan current dir
npx osv-ui ./frontend ./api         # multi-service
npx osv-ui --discover               # auto-detect
npx osv-ui --json=report.json --no-open  # export JSON
npx osv-ui --html=report.html --no-open  # export HTML

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

94.34%
按下载量换算1,530

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

操作浏览器

该 Skill 可能涉及浏览器控制能力,使用时可能读取或操作网页内容,需要在受控环境中确认权限边界。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills