Skill Audit by Raini

# Skill Audit ๐Ÿ”

Safety Notice

This item is sourced from the public archived skills repository. Treat as untrusted until reviewed.

Skill Audit ๐Ÿ”

ๆ‰ซๆ OpenClaw skills ไธญ็š„ๅฎ‰ๅ…จ้ฃŽ้™ฉ๏ผŒ้˜ฒๆญขไพ›ๅบ”้“พๆ”ปๅ‡ปใ€‚


ๆŒ‡ไปค

/skill-audit scan [skill-name]

ๆ‰ซๆๅทฒๅฎ‰่ฃ…็š„ skill๏ผŒๆฃ€ๆต‹ๅฏ็–‘ไปฃ็ ๆจกๅผใ€‚

# ๆ‰ซๆๆ‰€ๆœ‰ๅทฒๅฎ‰่ฃ… skill
skill-audit scan

# ๆ‰ซๆๆŒ‡ๅฎš skill
skill-audit scan moltdash

# ๆ‰ซๆๆœฌๅœฐ็›ฎๅฝ•
skill-audit scan ./my-skill

/skill-audit check <clawhub-slug>

ๅฎ‰่ฃ…ๅ‰ๆฃ€ๆŸฅ ClawHub ไธŠ็š„ skillใ€‚

skill-audit check some-skill

ๆฃ€ๆต‹่ง„ๅˆ™

๐Ÿ”ด ้ซ˜้ฃŽ้™ฉ (Critical)

  • ่ฏปๅ–ๅ‡ญ่ฏๆ–‡ไปถ: ~/.ssh/, ~/.env, credentials.json
  • ๅค–ๅ‘ๆ•ฐๆฎ: fetch(), curl, webhook, POST ๅˆฐๆœช็Ÿฅ URL
  • ไปฃ็ ๆ‰ง่กŒ: eval(), exec(), child_process
  • ่ฏปๅ–็Žฏๅขƒๅ˜้‡ไธญ็š„ๅฏ†้’ฅ: process.env.API_KEY

๐ŸŸ  ไธญ้ฃŽ้™ฉ (Warning)

  • ็ฝ‘็ปœ่ฏทๆฑ‚ๅˆฐ้ž็ŸฅๅๅŸŸๅ
  • ๆ–‡ไปถ็ณป็ปŸ้ๅކ: fs.readdir(), glob
  • ๅŠจๆ€ require/import
  • Base64 ็ผ–็ ็š„ๅญ—็ฌฆไธฒ (ๅฏ่ƒฝๆ˜ฏๆททๆท†)

๐ŸŸก ไฝŽ้ฃŽ้™ฉ (Info)

  • ไฝฟ็”จ shell ๅ‘ฝไปค
  • ่ฏปๅ†™็”จๆˆท็›ฎๅฝ•ๅค–็š„ๆ–‡ไปถ
  • ๅคง้‡ไพ่ต–ๅŒ…

่พ“ๅ‡บ็คบไพ‹

๐Ÿ” Skill Audit Report: suspicious-weather
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Risk Score: 85/100 ๐Ÿ”ด HIGH RISK

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ File        โ”‚ Severity โ”‚ Finding                         โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ index.ts    โ”‚ CRITICAL โ”‚ Reads ~/.openclaw/credentials/  โ”‚
โ”‚ index.ts    โ”‚ CRITICAL โ”‚ POST to webhook.site            โ”‚
โ”‚ utils.ts    โ”‚ WARNING  โ”‚ Uses eval()                     โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โš ๏ธ  DO NOT INSTALL - This skill may steal your credentials!

่ฟ่กŒๆ–นๅผ

่ฏฅ skill ้™„ๅธฆไธ€ไธช CLI ่„šๆœฌ๏ผŒagent ๅฏ็›ดๆŽฅ่ฐƒ็”จ๏ผš

node {baseDir}/src/audit.js scan ~/.openclaw/workspace/skills/moltdash
node {baseDir}/src/audit.js scan --all

ๅ‚่€ƒ

Source Transparency

This detail page is rendered from real SKILL.md content. Trust labels are metadata-based hints, not a safety guarantee.

Related Skills

Related by shared tags or category signals.

Security

skill-guard

Scan ClawHub skills for prompt injection and malicious content using Lakera Guard before installing them. Run automatically when the user asks to install a skill, or on-demand to audit any skill by slug or search query.

Archived SourceRecently Updated
Security--
0xmerkle
Security

pentest-api-attacker

Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks.

Archived SourceRecently Updated
Security--
0x-professor
Security

google-workspace-automation

Design Gmail, Drive, Sheets, and Calendar automations with scope-aware plans. Use for repeatable daily task automation with explicit OAuth scopes and audit-ready outputs.

Archived SourceRecently Updated
Security--
0x-professor