风险评分

47/100 (Medium)

OpenClaw: suspicious
VirusTotal: suspicious
StaticScan: clean

zcloak-ai-agent

作者: whgreate
Slug:zcloak-ai-agent
版本:1.0.18
更新时间:2026-03-24 13:10:53
风险信息

OpenClaw: suspicious

查看 OpenClaw 分析摘要(前 200 字预览)
The skill's claimed purpose (zCloak agent operations) matches the CLI workflows in SKILL.md, but the runtime instructions require the agent to silently overwrite its SKILL.md and to install/run arbitr...

[内容已截断]

VirusTotal: suspicious VT 报告

静态扫描: clean

No suspicious patterns detected.
README

README 未提供

文件列表

无文件信息

下载
下载官方 ZIP
原始 JSON 数据
{
    "latestVersion": {
        "_creationTime": 1773293634429,
        "_id": "k9732cjyrxf4xvrhc213szvvjx82shty",
        "changelog": "Version 1.0.18 of the zcloak-ai-agent skill introduces significant policy and workflow changes for clarity, security, and better user experience:\n\n- Added unified terminology and precise definitions for Principal IDs, Owner AI IDs (`.ai`), Agent AI IDs (`.agent`), and readable IDs.\n- Introduced strict rules for user-facing interactions: the agent now runs all CLI steps internally and only asks the user for actions when human participation is required (e.g., browser or passkey steps).\n- Enforced automatic agent identity management: always use (and, if missing, auto-create) a dedicated PEM at `~\/.config\/zcloak\/ai-id.pem` without prompting the user.\n- Standardized global readable ID resolution to Principal ID for all workflows using registry canister lookups, avoiding unknown IDs or incorrect fallback behaviors.\n- Automated SKILL.md and `@zcloak\/ai-agent` CLI refreshes on session start, with improved version reporting and error handling to prevent stale skill usage.\n- Clarified onboarding and owner binding flows: proactively guides users to bind an owner and explains",
        "changelogSource": "user",
        "createdAt": 1773293634429,
        "version": "1.0.18"
    },
    "owner": {
        "_creationTime": 0,
        "_id": "publishers:missing",
        "displayName": "whgreate",
        "handle": "whgreate",
        "image": "https:\/\/avatars.githubusercontent.com\/u\/811644?v=4",
        "kind": "user",
        "linkedUserId": "kn7ehqvvzsa0b0dpea1zyy2ych824pyx"
    },
    "ownerHandle": "whgreate",
    "skill": {
        "_creationTime": 1772614046731,
        "_id": "kd7f2ym54r3p6h3xd3hehdg6398299np",
        "badges": [],
        "createdAt": 1772614046731,
        "displayName": "zcloak-ai-agent",
        "latestVersionId": "k9732cjyrxf4xvrhc213szvvjx82shty",
        "ownerUserId": "kn7ehqvvzsa0b0dpea1zyy2ych824pyx",
        "slug": "zcloak-ai-agent",
        "stats": {
            "comments": 0,
            "downloads": 314,
            "installsAllTime": 0,
            "installsCurrent": 0,
            "stars": 0,
            "versions": 9
        },
        "summary": "zCloak.ai Agent skill — sign, verify, register and interact with canisters",
        "tags": {
            "latest": "k9732cjyrxf4xvrhc213szvvjx82shty"
        },
        "updatedAt": 1774329053065
    }
}