风险评分

100/100 (Very Low)

OpenClaw: benign
VirusTotal: benign
StaticScan: clean

Go Vuln Crypto Tls

作者: yhy
Slug:go-vuln-crypto-tls
版本:0.1.0
更新时间:2026-03-14 16:31:47
风险信息

OpenClaw: benign

查看 OpenClaw 分析摘要
An instruction-only auditing helper whose grep- and checklist-based guidance aligns with its stated purpose and requests no extra permissions or installs.

VirusTotal: benign VT 报告

静态扫描: clean

No suspicious patterns detected.
README

README 未提供

文件列表

无文件信息

下载
下载官方 ZIP
原始 JSON 数据
{
    "latestVersion": {
        "_creationTime": 1773476177307,
        "_id": "k9720j3v29hcheexm1gba6441h82wy35",
        "changelog": "Initial skill release for auditing Go crypto\/TLS code vulnerabilities:\n\n- Detects insecure TLS configurations (e.g., InsecureSkipVerify, weak mTLS, CA misconfig).\n- Covers JWT\/SAML signature verification misuse, including algorithm confusion and XML signature wrapping.\n- Provides grep-based detection paths and a step-by-step audit checklist for CWE-295, CWE-347, CWE-345.\n- Covers correct\/incorrect HMAC comparison practices for webhook signature validation.\n- Includes extensive exclusion guidance to reduce false positives.\n- References real-world vulnerabilities for context.",
        "changelogSource": "auto",
        "createdAt": 1773476177307,
        "version": "0.1.0"
    },
    "owner": {
        "_creationTime": 0,
        "_id": "publishers:missing",
        "displayName": "yhy",
        "handle": "yhy0",
        "image": "https:\/\/avatars.githubusercontent.com\/u\/31311038?v=4",
        "kind": "user",
        "linkedUserId": "kn79sjykbqsqznyrp68rnjy8jh82w52k"
    },
    "ownerHandle": "yhy0",
    "skill": {
        "_creationTime": 1773476177307,
        "_id": "kd7e5mc6spszzhd351fa78y9nd82xhxw",
        "badges": [],
        "createdAt": 1773476177307,
        "displayName": "Go Vuln Crypto Tls",
        "latestVersionId": "k9720j3v29hcheexm1gba6441h82wy35",
        "ownerUserId": "kn79sjykbqsqznyrp68rnjy8jh82w52k",
        "slug": "go-vuln-crypto-tls",
        "stats": {
            "comments": 0,
            "downloads": 118,
            "installsAllTime": 0,
            "installsCurrent": 0,
            "stars": 0,
            "versions": 1
        },
        "summary": "Use when auditing Go code involving TLS configuration, certificate validation, JWT token parsing, SAML assertion verification, webhook signature checking, or...",
        "tags": {
            "latest": "k9720j3v29hcheexm1gba6441h82wy35"
        },
        "updatedAt": 1773477107598
    }
}