Skill Audit by Raini

# Skill Audit ๐Ÿ”

Safety Notice

This item is sourced from the public archived skills repository. Treat as untrusted until reviewed.

Copy this and send it to your AI assistant to learn

Install skill "Skill Audit by Raini" with this command: npx skills add 0xraini/raini-skill-audit

Skill Audit ๐Ÿ”

ๆ‰ซๆ OpenClaw skills ไธญ็š„ๅฎ‰ๅ…จ้ฃŽ้™ฉ๏ผŒ้˜ฒๆญขไพ›ๅบ”้“พๆ”ปๅ‡ปใ€‚


ๆŒ‡ไปค

/skill-audit scan [skill-name]

ๆ‰ซๆๅทฒๅฎ‰่ฃ…็š„ skill๏ผŒๆฃ€ๆต‹ๅฏ็–‘ไปฃ็ ๆจกๅผใ€‚

# ๆ‰ซๆๆ‰€ๆœ‰ๅทฒๅฎ‰่ฃ… skill
skill-audit scan

# ๆ‰ซๆๆŒ‡ๅฎš skill
skill-audit scan moltdash

# ๆ‰ซๆๆœฌๅœฐ็›ฎๅฝ•
skill-audit scan ./my-skill

/skill-audit check <clawhub-slug>

ๅฎ‰่ฃ…ๅ‰ๆฃ€ๆŸฅ ClawHub ไธŠ็š„ skillใ€‚

skill-audit check some-skill

ๆฃ€ๆต‹่ง„ๅˆ™

๐Ÿ”ด ้ซ˜้ฃŽ้™ฉ (Critical)

  • ่ฏปๅ–ๅ‡ญ่ฏๆ–‡ไปถ: ~/.ssh/, ~/.env, credentials.json
  • ๅค–ๅ‘ๆ•ฐๆฎ: fetch(), curl, webhook, POST ๅˆฐๆœช็Ÿฅ URL
  • ไปฃ็ ๆ‰ง่กŒ: eval(), exec(), child_process
  • ่ฏปๅ–็Žฏๅขƒๅ˜้‡ไธญ็š„ๅฏ†้’ฅ: process.env.API_KEY

๐ŸŸ  ไธญ้ฃŽ้™ฉ (Warning)

  • ็ฝ‘็ปœ่ฏทๆฑ‚ๅˆฐ้ž็ŸฅๅๅŸŸๅ
  • ๆ–‡ไปถ็ณป็ปŸ้ๅކ: fs.readdir(), glob
  • ๅŠจๆ€ require/import
  • Base64 ็ผ–็ ็š„ๅญ—็ฌฆไธฒ (ๅฏ่ƒฝๆ˜ฏๆททๆท†)

๐ŸŸก ไฝŽ้ฃŽ้™ฉ (Info)

  • ไฝฟ็”จ shell ๅ‘ฝไปค
  • ่ฏปๅ†™็”จๆˆท็›ฎๅฝ•ๅค–็š„ๆ–‡ไปถ
  • ๅคง้‡ไพ่ต–ๅŒ…

่พ“ๅ‡บ็คบไพ‹

๐Ÿ” Skill Audit Report: suspicious-weather
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Risk Score: 85/100 ๐Ÿ”ด HIGH RISK

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ File        โ”‚ Severity โ”‚ Finding                         โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ index.ts    โ”‚ CRITICAL โ”‚ Reads ~/.openclaw/credentials/  โ”‚
โ”‚ index.ts    โ”‚ CRITICAL โ”‚ POST to webhook.site            โ”‚
โ”‚ utils.ts    โ”‚ WARNING  โ”‚ Uses eval()                     โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โš ๏ธ  DO NOT INSTALL - This skill may steal your credentials!

่ฟ่กŒๆ–นๅผ

่ฏฅ skill ้™„ๅธฆไธ€ไธช CLI ่„šๆœฌ๏ผŒagent ๅฏ็›ดๆŽฅ่ฐƒ็”จ๏ผš

node {baseDir}/src/audit.js scan ~/.openclaw/workspace/skills/moltdash
node {baseDir}/src/audit.js scan --all

ๅ‚่€ƒ

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

agentguard

GoPlus AgentGuard โ€” AI agent security guard. Run /agentguard checkup for a full security health check, scans all installed skills, checks credentials, permissions, and network exposure, then delivers an HTML report directly to you. Also use for scanning third-party code, blocking dangerous commands, preventing data leaks, evaluating action safety, and running daily security patrols.

Archived SourceRecently Updated
Security

notion-cli-mcp

Notion via notion-cli โ€” a Rust CLI + MCP server for Notion API 2025-09-03+. Safety-first agent integration with rate limiting, response-size cap, untrusted-source output envelope, read-only MCP default, JSONL audit log, and --check-request dry-runs. Supports the new data-source model, 22 property types, 12 block types, and one-shot page+body creation.

Archived SourceRecently Updated
Security

fire-smoke-detection-analysis

Detects fire and smoke in video scenes. Supports both video stream and image analysis. Suitable for fire early warning scenarios such as security surveillance, forest fire prevention, and industrial parks. | ็ƒŸ็ซๆฃ€ๆต‹ๆŠ€่ƒฝ๏ผŒๅฏน่ง†้ข‘ๅœบๆ™ฏไธญ็ซๆƒ…ๅ’Œ็ƒŸ้›พ่ฟ›่กŒๆฃ€ๆต‹๏ผŒๆ”ฏๆŒ่ง†้ข‘ๆตๅ’Œๅ›พ็‰‡ๆฃ€ๆต‹๏ผŒ้€‚็”จไบŽๅฎ‰้˜ฒ็›‘ๆŽงใ€ๆฃฎๆž—้˜ฒ็ซใ€ๅทฅไธšๅ›ญๅŒบ็ญ‰็ซ็พ้ข„่ญฆๅœบๆ™ฏ

Archived SourceRecently Updated
Security

basic-object-detection-analysis

Detects people, vehicles, non-motorized vehicles, pets, and parcels appearing in the target area. Supports video stream and image detection, suitable for general security surveillance scenarios. | ๅŸบ็ก€็›ฎๆ ‡ๆฃ€ๆต‹ๆŠ€่ƒฝ๏ผŒๆฃ€ๆต‹ๅ‡บ็›ฎๆ ‡ๅŒบๅŸŸๅ†…ๅ‡บ็Žฐ็š„ไบบใ€่ฝฆใ€้žๆœบๅŠจ่ฝฆใ€ๅฎ ็‰ฉใ€ๅŒ…่ฃน๏ผŒๆ”ฏๆŒ่ง†้ข‘ๆตๅ’Œๅ›พ็‰‡ๆฃ€ๆต‹๏ผŒ้€‚็”จไบŽ้€š็”จๅฎ‰้˜ฒ็›‘ๆŽงๅœบๆ™ฏ

Archived SourceRecently Updated