返回顶部
m

minduploadedcrab-skillguard技能安全扫描

Security scanner for OpenClaw skills. Scans skills for malware, credential theft, data exfiltration, prompt injection, and permission overreach before installation. Run: python3 scripts/skillguard.py scan

作者: admin | 来源: ClawHub
源自
ClawHub
版本
V 1.0.1
安全检测
已通过
565
下载量
免费
免费
0
收藏
概述
安装方式
版本历史

minduploadedcrab-skillguard

SkillGuard — Security Scanner for OpenClaw Skills

Scans OpenClaw skills for security threats before installation. Catches agent-specific attacks that generic antivirus misses.

Usage

CODEBLOCK0

What It Detects

  1. 1. Credential Access — reads of config files, env vars, wallet files, API keys
  2. Network Exfiltration — outbound HTTP calls, encoded payloads, suspicious domains
  3. File System Abuse — path traversal, writes outside skill directory, hidden files
  4. Prompt Injection — SKILL.md content that manipulates agent behavior
  5. Dependency Risks — suspicious npm post-install scripts, known bad packages
  6. Obfuscation — extremely long lines, hex/unicode escape sequences
  7. Symlink Attacks — symlinks escaping the skill directory to access sensitive files
  8. Config File Secrets — hardcoded credentials in .json, .env, .yaml files

Output

Each scan produces:

  • - Risk Score: 0-100 (0 = clean, 100 = critical threat)
  • Verdict: PASS / WARN / FAIL
  • Findings: Detailed list of issues with severity and evidence

标签

skill ai

通过对话安装

该技能支持在以下平台通过对话安装:

OpenClaw WorkBuddy QClaw Kimi Claude

方式一:安装 SkillHub 和技能

帮我安装 SkillHub 和 minduploadedcrab-skillguard-1776420083 技能

方式二:设置 SkillHub 为优先技能安装源

设置 SkillHub 为我的优先技能安装源,然后帮我安装 minduploadedcrab-skillguard-1776420083 技能

通过命令行安装

skillhub install minduploadedcrab-skillguard-1776420083

下载

⬇ 下载 minduploadedcrab-skillguard v1.0.1(免费)

文件大小: 8.75 KB | 发布时间: 2026-4-17 19:19

v1.0.1 最新 2026-4-17 19:19
- Improved documentation with detailed usage instructions and detection capabilities.
- Added descriptions of scan types, risk scoring, and output format.
- Expanded threat detection list, clarifying coverage for credential theft, data exfiltration, prompt injection, and more.
- Simple command examples included for scanning specific skills or all installed skills.

Archiver·手机版·闲社网·闲社论坛·羊毛社区· 多链控股集团有限公司 · 苏ICP备2025199260号-1

Powered by Discuz! X5.0   © 2024-2025 闲社网·线报更新论坛·羊毛分享社区·http://xianshe.com

p2p_official_large
返回顶部