风险评分

65/100 (Medium)

OpenClaw: suspicious
VirusTotal: benign
StaticScan: clean

Xiaopi Skill Vetter

作者: Adin
Slug:xiaopi-skill-vetter
版本:1.0.0
更新时间:2026-03-30 03:41:52
风险信息

OpenClaw: suspicious

查看 OpenClaw 分析摘要(前 200 字预览)
The skill's instructions match a reasonable vetting checklist, but metadata inconsistencies (ownerId mismatch), lack of provenance, and a couple of vague instructions merit caution before trusting it ...

[内容已截断]

VirusTotal: benign VT 报告

静态扫描: clean

No suspicious patterns detected.
README

README 未提供

文件列表

无文件信息

下载
下载官方 ZIP
原始 JSON 数据
{
    "latestVersion": {
        "_creationTime": 1774811211205,
        "_id": "k97945xb9fmdp3b38yjbwv7s3583tvht",
        "changelog": "Initial release of skill-vetter — a security-first vetting protocol for AI agent skills.\n\n- Provides a step-by-step checklist to review skill sources, code, permission scopes, and risk levels before installation.\n- Lists critical red flags for immediate rejection and offers a clear risk classification framework.\n- Includes a standardized vetting report template for documenting evaluations.\n- Offers quick commands for assessing GitHub-hosted skills.\n- Establishes a trust hierarchy and best practices to minimize security risks when installing new skills.",
        "changelogSource": "auto",
        "createdAt": 1774811211205,
        "version": "1.0.0"
    },
    "owner": {
        "_creationTime": 0,
        "_id": "s17c7djh1gag2b7k7dst2mkr6983sy0v",
        "displayName": "Adin",
        "handle": "a-din",
        "image": "https:\/\/avatars.githubusercontent.com\/u\/22701008?v=4",
        "kind": "user",
        "linkedUserId": "kn7256rtp1jzayyfabbd4m60qd834q8a"
    },
    "ownerHandle": "a-din",
    "skill": {
        "_creationTime": 1774811211205,
        "_id": "kd723sv77kndcks3x116350n2d83v6kr",
        "badges": [],
        "canonicalSkillId": "kd702w03jd74bhgbpwwtfxfaq582w0de",
        "createdAt": 1774811211205,
        "displayName": "Xiaopi Skill Vetter",
        "forkOf": {
            "at": 1774811211205,
            "kind": "duplicate",
            "skillId": "kd702w03jd74bhgbpwwtfxfaq582w0de"
        },
        "latestVersionId": "k97945xb9fmdp3b38yjbwv7s3583tvht",
        "ownerPublisherId": "s17c7djh1gag2b7k7dst2mkr6983sy0v",
        "ownerUserId": "kn7256rtp1jzayyfabbd4m60qd834q8a",
        "slug": "xiaopi-skill-vetter",
        "stats": {
            "comments": 0,
            "downloads": 15,
            "installsAllTime": 0,
            "installsCurrent": 0,
            "stars": 0,
            "versions": 1
        },
        "summary": "Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...",
        "tags": {
            "latest": "k97945xb9fmdp3b38yjbwv7s3583tvht"
        },
        "updatedAt": 1774813312888
    }
}