Token导航 LogoToken导航TokenDH.com
研究检索敏感数据clawhub未标认证来源可访问clear审计提醒

skill-auditor-in-sandbox沙盒中的技能审核员

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

2,471

周安装

104

GitHub Stars

公开资料未说明

下载量

865
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:skill-auditor-in-sandbox(沙盒中的技能审核员)
来源仓库:https://github.com/freecodewu/skill-auditor-in-sandbox
安装命令:
openclaw skills install skill-auditor-in-sandbox
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install skill-auditor-in-sandbox

简介

用于辅助安全审计和权限检查,适合让 Agent 分析鉴权逻辑和生成复核清单。

  • 适用于启动 NovitaClaw 沙箱环境,测试技能安装与安全合规性。
  • 可生成安装报告和安全审核结果,支持本地测试验证。
  • 使用时不能将工具输出直接作为最终结论,需人工确认操作影响。
  • skill-auditor-in-sandbox 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

name
skill-auditor-in-sandbox
description
Launch a NovitaClaw (OpenClaw) sandbox, install a specified skill, and generate an installation & security audit report. Use when: (1) You want to test a community skill before installing it locally, (2) You need a security audit of a skill's code, hooks, and dependencies, (3) You want to verify a skill from ClawHub or GitHub in an isolated environment.
argument-hint
<skill-name>
metadata
source
https://github.com/freecodewu/skill-auditor-in-sandbox
homepage
https://github.com/freecodewu/skill-auditor-in-sandbox

Skill Auditor in Sandbox

Test and audit Claude Code skills in an isolated NovitaClaw (OpenClaw) sandbox before installing them locally. The skill launches a sandbox, installs the target skill, runs a security scan, and generates a structured risk report.

Quick Reference

SituationAction
Test a ClawHub skill/skill-auditor-in-sandbox owner/skill-name
Test a GitHub skill/skill-auditor-in-sandbox owner/repo-name
Review the reportCheck risk level, suspicious patterns, URLs, external paths
After reviewPause or stop the sandbox to save costs

Prerequisites

  • NOVITA_API_KEY must be set. If not, ask the user to register at https://novita.ai/?utm_source=OpenClaw&utm_medium=Dev_Rel&utm_campaign=Claw-30 and get an API key from https://novita.ai/settings/key-management, then:

export NOVITA_API_KEY=<key>

  • novitaclaw CLI must be installed. If not found:

curl -fsSL https://novitaclaw.novita.ai/install.sh | bash

  • novita-sandbox npm package must be available. If not:

npm install novita-sandbox

Usage

You are given a skill name (or identifier) as $ARGUMENTS. Your job is to launch a sandbox, install the skill, run a security audit, and generate a report.

Step 1: Launch Sandbox

novitaclaw launch --json

Parse the JSON output and extract sandbox_id and webui. Save these for the report.

If launch fails, check error_code and remediation fields:

  • MISSING_API_KEY → ask user for API key
  • SANDBOX_TIMEOUT → retry with --timeout 300

Step 2: Install Skill

Run the install script from the project root:

SANDBOX_ID=<sandbox_id> SKILL_NAME="$ARGUMENTS" node scripts/install-skill.mjs

The script outputs JSON: { success, method, skillDir, files, error? }.

  • If success is false, show the error and stop.
  • Note the method used (clawhub / git-github / git-clawhub) for the report.

Step 3: Security Audit

Run the audit script:

SANDBOX_ID=<sandbox_id> SKILL_NAME="$ARGUMENTS" node scripts/audit-skill.mjs

The script outputs JSON:

  • suspicious[] — lines matching risky code patterns (dynamic execution, shell spawning, encoding, etc.)
  • urls[] — all URL references found in skill files
  • externalPaths[] — references to paths outside the skill directory (system dirs, dotfiles, temp dirs)
  • dependencies — contents of requirements.txt or package.json if present
  • fileContents[] — full contents of all text files for manual review

Step 4: Assess Risk

Based on audit results, assign a risk level:

Risk LevelCriteria
LOWNo suspicious patterns, URLs are legitimate (GitHub, docs), no external paths
MEDIUMSome suspicious patterns but explainable (e.g., fetch() for legitimate API calls)
HIGHUnexplained network calls, access to sensitive paths, obfuscated code
CRITICALCredential harvesting, mining indicators, command injection patterns

Step 5: Generate Report

Output a structured report:

## Skill Installation Report

**Skill:** <skill-name>
**Sandbox ID:** <sandbox_id>
**Web UI:** <webui_url>
**Timestamp:** <current time>

### Installation Status
- **Result:** SUCCESS / FAILED
- **Method:** <clawhub / git-github / git-clawhub>
- **Files Installed:** <count> files

### Installed Files
<table of files and their purpose>

### Security Analysis
- **Risk Level:** LOW / MEDIUM / HIGH / CRITICAL

### Suspicious Patterns Found
| File | Line | Pattern | Severity |
|------|------|---------|----------|
(or "None found")

### URL References
| File | URL | Context |
|------|-----|---------|
(list all URLs and whether they look legitimate)

### External Path References
(list any, or "None found")

### Dependencies
(list any, or "No external dependencies")

### Recommendations
- <recommendation based on findings>

### Sandbox Management
- To access: <webui_url>
- To pause (save costs): `novitaclaw pause <sandbox_id>`
- To stop (permanent): `novitaclaw stop <sandbox_id>`

After generating the report, automatically pause the sandbox to save costs:

novitaclaw pause <sandbox_id> --json

Then inform the user that the sandbox has been paused and can be resumed or stopped:

  • To resume: novitaclaw resume <sandbox_id>
  • To stop (permanent): novitaclaw stop <sandbox_id>

What Gets Scanned

CategoryPatterns
Suspicious codeShell spawning, dynamic code execution, encoding functions, mining indicators
Network callsAll URL references found in skill files
External pathsSystem directories, user home dotfiles, temp directories
Dependenciesrequirements.txt, package.json
File contentsFull text of all .md, .txt, .json, .py, .js, .ts, .sh, .yaml, .yml files

Important Notes

  • Always use --json flag with novitaclaw commands.
  • The sandbox auto-terminates based on keep_alive. Suggest pause to save costs.
  • Prefer pause over stop — stop is irreversible. Confirm before stopping.

Attribution

  • Source: https://github.com/freecodewu/skill-auditor-in-sandbox
  • Powered by NovitaClaw sandbox infrastructure

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

96.15%
按下载量换算832

安全审计

VirusTotal

通过

ClawScan

可疑

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills