Token导航 LogoToken导航TokenDH.com
开发敏感数据clawhub未标认证来源可访问clear审计通过

skill-security-auditor-jack技能安全审核员杰克

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

3,917

周安装

160

GitHub Stars

公开资料未说明

下载量

1,254
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:skill-security-auditor-jack(技能安全审核员杰克)
来源仓库:https://github.com/sunbinnju-star/skill-security-auditor-jack
安装命令:
openclaw skills install skill-security-auditor-jack
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install skill-security-auditor-jack

简介

用于辅助安全审计、权限检查和常见漏洞排查,梳理敏感配置与鉴权逻辑。

  • 适合分析依赖风险、生成安全复核清单或审核第三方技能。
  • 通过 clawhub 安装,使用 openclaw skills install skill-security-auditor-jack 命令。
  • 不能将工具输出直接当最终结论,需确认最小权限与操作边界。
  • 涉及密钥、令牌或生产系统时应先脱敏并评估影响。

SKILL.md

name
skill-security-auditor
description
Audit third-party or custom skills for permission risk, unsafe commands, and integration safety. Use before: installing a new skill, enabling external scripts or repos, granting broad permissions, recurring security review. Triggered when any skill is about to be adopted into the OpenClaw system.

Skill Security Auditor

Audit skills for supply-chain, privilege, and automation risk before adoption.

Input

Required:

  • skill_manifest — the skill's SKILL.md or metadata
  • source_location — where the skill comes from (clawhub, git, local, unknown)
  • required_permissions — what permissions the skill requests
  • shell_commands — any shell/CLI commands referenced by the skill
  • env_usage — environment variables the skill reads or writes
  • install_steps — how the skill is installed / what it runs on install

Output Schema

risk_level: "low" | "medium" | "high" | "critical"

suspicious_actions: {
  action: string
  location: string
  severity: "warning" | "critical"
  description: string
  recommendation: string
}[]

over_privileged_points: {
  permission: string
  why_needed: string | null
  why_excessive: string
  recommendation: string
}[]

install_recommendation: "approve" | "approve_with_sandbox" | "reject" | "manual_review"

sandbox_recommendation: {
  recommended: boolean
  isolation_level: "none" | "process" | "network" | "full"
  reasons: string[]
} | null

audit_summary: string    # one paragraph honest summary

Risk Levels

LevelCriteria
lowMinimal permissions, no shell, no env secrets, known source
mediumSome filesystem access or env usage, known source
highShell commands, broad permissions, or unknown source
criticalOpaque install scripts, secret access, eval/exec patterns

Suspicious Actions to Flag

  • eval, exec, Function() — code execution
  • curl / wget with pipe to shell — remote code download
  • chmod +x / sudo — privilege escalation
  • Reading ~/.ssh, /etc/passwd, environment secrets
  • Network calls to unknown hosts
  • Base64-encoded or obfuscated commands
  • Install scripts that fetch from unknown URLs

Over-Privileged Points to Flag

  • Filesystem access beyond the skill's stated scope
  • Broad read permissions on entire directories
  • write access to system paths
  • Environment variables containing tokens/keys
  • Network access not strictly needed for stated function

Source Trust Levels

SourceTrust
ClawHub verifiedmedium (review anyway)
Known git repomedium
Local skillhigh
Unknown URLlow
Copy-pasted codevery low

Rules

  1. Never default-approve high-privilege skills. Burden of proof is on the skill, not the auditor.
  2. Flag remote install scripts and opaque shell chains. If you can't see what runs, flag it.
  3. Flag access to secrets, env vars, filesystem, or network where not strictly needed.
  4. Recommend isolation for untrusted skills. Better safe than sorry.

Failure Handling

If source trust cannot be established:

  • Default to risk_level = "high" minimum
  • Recommend reject or manual_review
  • Do not fabricate a clean audit
  • Explicitly state what could not be verified

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

82.41%
按下载量换算1,033

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills