风险评分

59/100 (Medium)

OpenClaw: suspicious
VirusTotal: benign
StaticScan: unknown

GitHub Token

作者: Danny Shmueli
Slug:github-token
版本:1.0.0
更新时间:2026-03-15 02:01:50
风险信息

OpenClaw: suspicious

查看 OpenClaw 分析摘要(前 200 字预览)
The skill mostly does what it says (uses PATs to talk to GitHub) but there are security- and coherence-related issues (metadata omissions, unsafe token handling/storage, and CLI usage that can leak to...

[内容已截断]

VirusTotal: benign VT 报告

静态扫描: unknown

README

README 未提供

文件列表

无文件信息

下载
下载官方 ZIP
原始 JSON 数据
{
    "latestVersion": {
        "_creationTime": 1769540675159,
        "_id": "k9703n0htrk4ss4fn8kf1d4ysd801dhw",
        "changelog": "Secure GitHub via PAT",
        "changelogSource": "user",
        "createdAt": 1769540675159,
        "version": "1.0.0"
    },
    "owner": {
        "_creationTime": 0,
        "_id": "publishers:missing",
        "displayName": "Danny Shmueli",
        "handle": "dannyshmueli",
        "image": "https:\/\/avatars.githubusercontent.com\/u\/4062328?v=4",
        "kind": "user",
        "linkedUserId": "kn7caxjvqk9fengp67p290smnn800sv9"
    },
    "ownerHandle": "dannyshmueli",
    "skill": {
        "_creationTime": 1769540675159,
        "_id": "kd79f5y91msbvdzyqa6cwh6yvn801x0a",
        "badges": [],
        "canonicalSkillId": "kd77bmvp7zb554pvzdk35m7twx8003vr",
        "createdAt": 1769540675159,
        "displayName": "GitHub Token",
        "forkOf": {
            "at": 1773511310831,
            "kind": "duplicate",
            "skillId": "kd79f5y91msbvdzyqa6cwh6yvn801x0a",
            "version": "1.0.0"
        },
        "latestVersionId": "k9703n0htrk4ss4fn8kf1d4ysd801dhw",
        "ownerUserId": "kn7caxjvqk9fengp67p290smnn800sv9",
        "slug": "github-token",
        "stats": {
            "comments": 0,
            "downloads": 1504,
            "installsAllTime": 2,
            "installsCurrent": 2,
            "stars": 1,
            "versions": 1
        },
        "summary": "Interact with GitHub using Personal Access Tokens. Secure, user-controlled access - no OAuth, no full account access. Clone, push, branch, PR, issues. Use when user wants to work with GitHub repos.",
        "tags": {
            "latest": "k9703n0htrk4ss4fn8kf1d4ysd801dhw"
        },
        "updatedAt": 1773511310831
    }
}