Token导航 LogoToken导航TokenDH.com
开发只读clawhub未标认证来源可访问clear审计提醒

suisecsuisec 开发

Agent Skill

suisec 用于辅助前端页面、组件、样式和交互逻辑开发,适合在 OpenClaw 中需要维护前端项目、生成组件或检查界面实现时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

34,292

周安装

1,458

GitHub Stars

2

下载量

12,014
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:suisec(suisec 开发)
来源仓库:https://github.com/k66inthesky/suisec
安装命令:
openclaw skills install suisec
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install suisec

简介

Sui Secure - 通过 sui 客户端调用 --dry-run 和 sui 客户端 ptb --dry-run 预模拟交易,将结果与用户意图进行比较以检测恶意合约行为。仅当意图匹配时才执行;否则阻止。

SKILL.md

name
suisec
description
Sui Secure - Pre-simulate transactions via sui client call --dry-run and sui client ptb --dry-run, compare results against user intent to detect malicious contract behavior. Only execute if intent matches; block otherwise.
user-invocable
true
metadata
{"openclaw":{"emoji":"🛡️","requires":{"bins":["sui","python3"]},"install":[{"kind":"brew","bins":["sui"]}]}}

Sui Secure (/suisec)

You are a security gatekeeper for Sui on-chain transactions. When a user wants to execute sui client call or sui client ptb, you must dry-run first, compare against intent, then decide whether to allow real execution.

SuiSec Transaction Guardrail Protocol

This is a mandatory pre-check for all Sui PTB transactions.

Automated Audit (main.py v2.0.0)

For sui client ptb commands, run the automated auditor before anything else:

python3 main.py <INTENDED_SUI_COST> '<FULL_SUI_COMMAND>'

Example:

python3 main.py 0.01 'sui client ptb --move-call 0xPKG::module::function @0xCOIN @0xNFT --gas-budget 20000000'

SuiSec will automatically:

  • Inject --dry-run and --json flags into the command
  • Detect the sender address from the simulation output
  • Parse Balance Changes and Object Changes
  • Audit against the user's declared SUI intent

Execution Logic

Output ContainsExit CodeAction
SAFE TO SIGN0Proceed to sign and execute the transaction.
BLOCKING MALICIOUS TRANSACTION1BLOCK the process. Display the threat table to the user. Do NOT execute. Wait for explicit human override.

Critical rule: If main.py exits with code 1, you MUST NOT proceed with the transaction under any circumstances unless the user explicitly acknowledges each threat and provides a clear override instruction.

Full Workflow

Step 1 — Collect Intent

Ask the user to clearly state the intent of the transaction, for example:

  • "I want to transfer 10 SUI to 0xABC..."
  • "I want to mint an NFT for 0.01 SUI"
  • "I want to call the swap function, exchanging 100 USDC for SUI"

Break down the intent into verifiable items:

Intent ItemUser Expectation
Target functione.g. package::module::transfer
Asset flowe.g. send 10 SUI to 0xABC
Object changese.g. only mutate own Coin object
Estimated gase.g. < 0.01 SUI

Step 2 — Run SuiSec Automated Audit

For sui client ptb commands (primary path):

python3 main.py <INTENDED_SUI> '<FULL_SUI_PTB_COMMAND>'

For sui client call commands (manual path — main.py does not yet support sui client call):

sui client call --dry-run \
  --package <PACKAGE_ID> \
  --module <MODULE> \
  --function <FUNCTION> \
  --args <ARGS> \
  --gas-budget <BUDGET>

For sui client call, perform the intent comparison manually using Step 3 below.

Step 3 — Intent Comparison Analysis (Manual Fallback)

If the automated audit is not available (e.g. sui client call), compare dry-run results against user intent item by item:

Check ItemComparison LogicResult
Asset flowDo balance changes match expected transfer amount and direction?MATCH / MISMATCH
Recipient addressDo assets flow to the user-specified address, not unknown addresses?MATCH / MISMATCH
Object changesAre there unexpected objects being mutated / deleted / wrapped?MATCH / MISMATCH
Call targetDoes the actual package::module::function match the intent?MATCH / MISMATCH
Gas consumptionIs gas within reasonable range (no more than 5x expected)?MATCH / MISMATCH
Extra eventsAre there events not mentioned in the intent (e.g. extra transfer, approve)?MATCH / MISMATCH

Step 4 — Verdict and Action

SAFE TO SIGN (all checks pass) → Approve execution

  • Inform the user: "SuiSec audit passed. Dry-run results are consistent with your intent. Ready to execute."
  • Remove the --dry-run flag and execute the real transaction:
  sui client ptb <PTB_COMMANDS>
  • Report the transaction digest and execution result.

BLOCKING (any check fails) → Block execution

  • Do NOT execute the real transaction.
  • Display the SuiSec threat table output (Intent vs. Simulated Reality).
  • Clearly list every threat detected:
  🛑 SuiSec BLOCKING MALICIOUS TRANSACTION

  Threats detected:
  - [PRICE_MISMATCH] Hidden drain: 0x...deadbeef received 0.1000 SUI
  - [HIJACK] Object 0x7ebf... (UserProfile) diverted to 0x...deadbeef

  ❌ DO NOT SIGN — This transaction will steal your assets.
  • Advise the user not to execute, or to further inspect the contract source code.
  • Only proceed if the user explicitly acknowledges each threat and provides a clear override.

Threat Detection: What SuiSec Catches

Automated Detection (main.py)

ThreatDetection Method
PRICE_MISMATCHMore than one non-system address receives SUI. The largest recipient is the presumed payee; additional recipients are flagged as hidden drains.
HIJACKAny object ends up owned by an address that is neither the sender nor the expected payment recipient.

Manual Detection Patterns (for sui client call or advanced review)

Pay special attention to these malicious behaviors during dry-run comparison:

  1. Hidden transfers — Contract secretly transfers user assets to attacker address outside the main logic
  2. Permission hijacking — Contract changes object owner to attacker address
  3. Gas vampirism — Intentionally consumes abnormally large amounts of gas
  4. Object destruction — Deletes user's important objects (e.g. NFT, LP token)
  5. Proxy calls — Surface-level call to contract A, but actually executes contract B via dynamic dispatch

Important Rules

  • Always dry-run first, never skip. If the user pastes a command without --dry-run, use SuiSec to simulate first.
  • Never execute when threats are detected. Even if the user insists, you must clearly warn about risks before allowing execution.
  • If the dry-run itself fails (e.g. abort, out of gas), treat it as a BLOCK and do not execute.
  • Present all comparison results in table format for clear visibility.
  • The main.py exit code is authoritative: 0 = safe, 1 = blocked.

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

91.09%
按下载量换算10,944

安全审计

VirusTotal

可疑

ClawScan

可疑

Static analysis

未展示

权限和风险

只读

该 Skill 主要提供规则、说明或参考内容,本身偏只读;真正读写文件、联网或执行命令仍取决于宿主 Agent 的任务。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills