OpenClaw: suspicious
VirusTotal: suspicious
StaticScan: unknown
OpenClaw: suspicious
The package is documentation-only and its workflows reasonably require shell, network, and credentials, but the registry metadata omits those runtime requirements — an incoherence you should understan... [内容已截断]
VirusTotal: suspicious VT 报告
静态扫描: unknown
README 未提供
无文件信息
{
"latestVersion": {
"_creationTime": 1771254085149,
"_id": "k977fy63eqkdhpwxk9g0mfw8dx818ry0",
"changelog": "v5.11.3 – Security Declaration Alignment\n\nThis release fixes security-scan findings caused by inconsistent runtime declarations in v5.11.2.\n\nWhat changed\n\n• Updated runtime declarations to match actual workflow behavior:\n• requires_binaries: true\n• requires_credentials: true\n• requires_network: true\n• Clarified package behavior:\n• The package itself remains documentation-only (no install-time executable payload).\n• Agent workflows may execute shell\/network actions at runtime when invoked by the user.\n• Added explicit runtime transparency:\n• Required\/optional runtime binaries\n• Optional credentials\/environment expectations (e.g. GH_TOKEN, Claude auth, MCP configuration)\n• Refined security semantics to distinguish:\n• install-time safety\n• runtime agent capabilities\n\nWhy this release\n\nv5.11.2 could create a misleading security impression by claiming no network\/credentials\/code-execution requirements while documenting workflows that use shell, GitHub, Playwright, and web tools.\nv5.11.3 resolves that mismatch for clearer trust and more accurate scanner interpretation.\n\nCompatibility\n\n• No breaking workflow changes\n• Backward-compatible behavior\n• Metadata\/security declaration update only",
"changelogSource": "user",
"createdAt": 1771254085149,
"parsed": {
"clawdis": {
"emoji": "🚀"
}
},
"version": "5.11.3"
},
"owner": {
"_creationTime": 0,
"_id": "publishers:missing",
"displayName": "TonyNoScope",
"handle": "cubetribe",
"image": "https:\/\/avatars.githubusercontent.com\/u\/176912438?v=4",
"kind": "user",
"linkedUserId": "kn71pcr5rek24ey8ccr2kzrg4h80g4tk"
},
"ownerHandle": "cubetribe",
"skill": {
"_creationTime": 1770210020925,
"_id": "kd73c1n7bsgh7vrhw42kbakywx80g80j",
"badges": [],
"createdAt": 1770210020925,
"displayName": "Openclaw Godmode Skill Repo",
"latestVersionId": "k977fy63eqkdhpwxk9g0mfw8dx818ry0",
"ownerUserId": "kn71pcr5rek24ey8ccr2kzrg4h80g4tk",
"slug": "cc-godmode",
"stats": {
"comments": 0,
"downloads": 4029,
"installsAllTime": 19,
"installsCurrent": 19,
"stars": 12,
"versions": 3
},
"summary": "Self-orchestrating multi-agent development workflows. You say WHAT, the AI decides HOW.",
"tags": {
"latest": "k977fy63eqkdhpwxk9g0mfw8dx818ry0"
},
"updatedAt": 1774322564299
}
}