风险评分

90/100 (Very Low)

OpenClaw: benign
VirusTotal: benign
StaticScan: suspicious

Audit Skills Security

作者: yhy
Slug:audit-skills-security
版本:0.1.0
更新时间:2026-03-20 20:12:02
风险信息

OpenClaw: benign

查看 OpenClaw 分析摘要(前 200 字预览)
The skill's requested operations match its stated purpose (audit local skill files); the prompt-injection patterns found in SKILL.md are intentional detection rules, and nothing else in the instructio...

[内容已截断]

VirusTotal: benign VT 报告

静态扫描: suspicious

Detected: suspicious.prompt_injection_instructions
README

README 未提供

文件列表

无文件信息

下载
下载官方 ZIP
原始 JSON 数据
{
    "latestVersion": {
        "_creationTime": 1774006615632,
        "_id": "k97f6sfmwqefb41z4p1acg2s2h838drj",
        "changelog": "audit-skills-security 0.1.0 – Initial skill release for automated skill security auditing\n\n- Provides a structured skill security audit workflow triggered by new skill files or user requests.\n- Scans and analyzes skills for prompt injection, data exfiltration, privilege escalation, obfuscation, and persistence attacks.\n- Combines deterministic Grep scanning for known dangerous patterns with LLM-based semantic analysis across six dimensions.\n- Outputs a detailed and standardized audit report including rating, evidence lists, and actionable recommendations.\n- Includes strict protocol to prevent audit manipulation via prompt injection.\n- Adds a built-in disclaimer outlining tool limitations and advising human review for high-risk scenarios.",
        "changelogSource": "auto",
        "createdAt": 1774006615632,
        "version": "0.1.0"
    },
    "owner": {
        "_creationTime": 0,
        "_id": "publishers:missing",
        "displayName": "yhy",
        "handle": "yhy0",
        "image": "https:\/\/avatars.githubusercontent.com\/u\/31311038?v=4",
        "kind": "user",
        "linkedUserId": "kn79sjykbqsqznyrp68rnjy8jh82w52k"
    },
    "ownerHandle": "yhy0",
    "skill": {
        "_creationTime": 1774006615632,
        "_id": "kd73t6zhp6fczk6712fc7y784s839npa",
        "badges": [],
        "createdAt": 1774006615632,
        "displayName": "Audit Skills Security",
        "latestVersionId": "k97f6sfmwqefb41z4p1acg2s2h838drj",
        "ownerUserId": "kn79sjykbqsqznyrp68rnjy8jh82w52k",
        "slug": "audit-skills-security",
        "stats": {
            "comments": 0,
            "downloads": 33,
            "installsAllTime": 0,
            "installsCurrent": 0,
            "stars": 0,
            "versions": 1
        },
        "summary": "Use when installing new skills, reviewing third-party skills, or verifying skill safety before use. Triggers on any new .md skill file appearing in skill dir...",
        "tags": {
            "latest": "k97f6sfmwqefb41z4p1acg2s2h838drj"
        },
        "updatedAt": 1774008722124
    }
}