风险评分

94/100 (Very Low)

OpenClaw: benign
VirusTotal: benign
StaticScan: unknown

SchemaPin

作者: Jascha
Slug:schemapin
版本:1.0.0
更新时间:2026-02-26 06:55:35
风险信息

OpenClaw: benign

查看 OpenClaw 分析摘要
The skill's instructions, scope, and requirements match its stated purpose (schema signing/verification); nothing requested is disproportionate or unrelated.

VirusTotal: benign VT 报告

静态扫描: unknown

README

README 未提供

文件列表

无文件信息

下载
下载官方 ZIP
原始 JSON 数据
{
    "latestVersion": {
        "_creationTime": 1771137797912,
        "_id": "k97dqmmhzrcc31wwv5c68mpdnn817s0h",
        "changelog": "SchemaPin 1.0.0 initial release\n\n- Introduces cross-language libraries (Python, JavaScript, Go, Rust) for cryptographically signing and verifying tool schemas.\n- Prevents schema tampering and \"MCP Rug Pull\" attacks using ECDSA P-256 + SHA-256 signatures and Trust-On-First-Use (TOFU) key pinning.\n- Implements deterministic schema canonicalization and RFC 8615 `.well-known` endpoints for public key discovery.\n- Provides code samples and integration guides for each supported language.\n- Features include revocation documents, trust bundles for offline use, pluggable discovery resolvers, and file-based skill folder signing with manifest support.",
        "changelogSource": "user",
        "createdAt": 1771137797912,
        "version": "1.0.0"
    },
    "owner": {
        "_creationTime": 0,
        "_id": "publishers:missing",
        "displayName": "Jascha",
        "handle": "jaschadub",
        "image": "https:\/\/avatars.githubusercontent.com\/u\/768841?v=4",
        "kind": "user",
        "linkedUserId": "kn7cn5bc5z4c6bkhm154y7pe29815a7t"
    },
    "ownerHandle": "jaschadub",
    "skill": {
        "_creationTime": 1771137797912,
        "_id": "kd72kpfnpjc6wxwsp4vqbm4re5816gr3",
        "badges": [],
        "createdAt": 1771137797912,
        "displayName": "SchemaPin",
        "latestVersionId": "k97dqmmhzrcc31wwv5c68mpdnn817s0h",
        "ownerUserId": "kn7cn5bc5z4c6bkhm154y7pe29815a7t",
        "slug": "schemapin",
        "stats": {
            "comments": 0,
            "downloads": 474,
            "installsAllTime": 0,
            "installsCurrent": 0,
            "stars": 0,
            "versions": 1
        },
        "summary": "SchemaPin enables cryptographic signing and verification of tool schemas to prevent tampering using ECDSA P-256, SHA-256, TOFU pinning, and .well-known key d...",
        "tags": {
            "latest": "k97dqmmhzrcc31wwv5c68mpdnn817s0h"
        },
        "updatedAt": 1772060135906
    }
}