OpenClaw: benign
VirusTotal: benign
StaticScan: suspicious
OpenClaw: benign
The skill's requested operations match its stated purpose (audit local skill files); the prompt-injection patterns found in SKILL.md are intentional detection rules, and nothing else in the instructio... [内容已截断]
VirusTotal: benign VT 报告
静态扫描: suspicious
Detected: suspicious.prompt_injection_instructions
README 未提供
无文件信息
{
"latestVersion": {
"_creationTime": 1774006615632,
"_id": "k97f6sfmwqefb41z4p1acg2s2h838drj",
"changelog": "audit-skills-security 0.1.0 – Initial skill release for automated skill security auditing\n\n- Provides a structured skill security audit workflow triggered by new skill files or user requests.\n- Scans and analyzes skills for prompt injection, data exfiltration, privilege escalation, obfuscation, and persistence attacks.\n- Combines deterministic Grep scanning for known dangerous patterns with LLM-based semantic analysis across six dimensions.\n- Outputs a detailed and standardized audit report including rating, evidence lists, and actionable recommendations.\n- Includes strict protocol to prevent audit manipulation via prompt injection.\n- Adds a built-in disclaimer outlining tool limitations and advising human review for high-risk scenarios.",
"changelogSource": "auto",
"createdAt": 1774006615632,
"version": "0.1.0"
},
"owner": {
"_creationTime": 0,
"_id": "publishers:missing",
"displayName": "yhy",
"handle": "yhy0",
"image": "https:\/\/avatars.githubusercontent.com\/u\/31311038?v=4",
"kind": "user",
"linkedUserId": "kn79sjykbqsqznyrp68rnjy8jh82w52k"
},
"ownerHandle": "yhy0",
"skill": {
"_creationTime": 1774006615632,
"_id": "kd73t6zhp6fczk6712fc7y784s839npa",
"badges": [],
"createdAt": 1774006615632,
"displayName": "Audit Skills Security",
"latestVersionId": "k97f6sfmwqefb41z4p1acg2s2h838drj",
"ownerUserId": "kn79sjykbqsqznyrp68rnjy8jh82w52k",
"slug": "audit-skills-security",
"stats": {
"comments": 0,
"downloads": 33,
"installsAllTime": 0,
"installsCurrent": 0,
"stars": 0,
"versions": 1
},
"summary": "Use when installing new skills, reviewing third-party skills, or verifying skill safety before use. Triggers on any new .md skill file appearing in skill dir...",
"tags": {
"latest": "k97f6sfmwqefb41z4p1acg2s2h838drj"
},
"updatedAt": 1774008722124
}
}