风险评分

55/100 (Medium)

OpenClaw: suspicious
VirusTotal: benign
StaticScan: suspicious

Skill Guard 1.0.2

作者: kenswj
Slug:skill-guard-1-0-2
版本:1.0.0
更新时间:2026-03-24 14:29:46
风险信息

OpenClaw: suspicious

查看 OpenClaw 分析摘要(前 200 字预览)
The skill is coherent with its stated purpose (a pre-install scanner) but contains inconsistencies and runtime behaviors that warrant caution—particularly remote code execution via uvx/astral.sh, a me...

[内容已截断]

VirusTotal: benign VT 报告

静态扫描: suspicious

Detected: suspicious.prompt_injection_instructions
README

README 未提供

文件列表

无文件信息

下载
下载官方 ZIP
原始 JSON 数据
{
    "latestVersion": {
        "_creationTime": 1773516093387,
        "_id": "k97arptvg0heh199dewj6bv7xn82xjgs",
        "changelog": "Initial release: client-side security scanning for ClawHub skills before installation.\n\n- Scans skill packages for prompt injections, malware, hardcoded secrets, exfiltration URLs, and other AI-specific threats before installing.\n- Uses Invariant Labs\/Snyk's mcp-scan for deep AI skill analysis.\n- Installs only if skill is clean; otherwise quarantines detected threats in a staging folder.\n- Provides clear CLI usage: secure install script, exit codes, and threat handling instructions.\n- Adds a strong comparison to existing solutions (VirusTotal, skillscanner) highlighting superior coverage for AI risks.",
        "changelogSource": "auto",
        "createdAt": 1773516093387,
        "version": "1.0.0"
    },
    "owner": {
        "_creationTime": 0,
        "_id": "publishers:missing",
        "displayName": "kenswj",
        "handle": "kenswj",
        "image": "https:\/\/avatars.githubusercontent.com\/u\/29836387?v=4",
        "kind": "user",
        "linkedUserId": "kn7353540ppfrvvkgpjyf0n2gx82w5mm"
    },
    "ownerHandle": "kenswj",
    "skill": {
        "_creationTime": 1773516093387,
        "_id": "kd74smkbejx4sev1xyx2q5smgh82xaa0",
        "badges": [],
        "createdAt": 1773516093387,
        "displayName": "Skill Guard 1.0.2",
        "latestVersionId": "k97arptvg0heh199dewj6bv7xn82xjgs",
        "ownerUserId": "kn7353540ppfrvvkgpjyf0n2gx82w5mm",
        "slug": "skill-guard-1-0-2",
        "stats": {
            "comments": 0,
            "downloads": 118,
            "installsAllTime": 0,
            "installsCurrent": 0,
            "stars": 0,
            "versions": 1
        },
        "summary": "Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to detect prompt injections, malware payloads...",
        "tags": {
            "latest": "k97arptvg0heh199dewj6bv7xn82xjgs"
        },
        "updatedAt": 1774333786106
    }
}