TopRank Skills

Home / Claw Skills / API Integration / Raini Skill Audit
Official OpenClaw rules 36%

Raini Skill Audit

Skill Audit ๐Ÿ”

Stars

0

Installs

0

Status

ACTIVE

Visibility

PUBLIC

ๅฎ‰่ฃ…ๆ–นๅผ

็›ดๆŽฅๅคๅˆถไปฅไธ‹ๆ็คบ่ฏ๏ผŒๅ‘้€็ป™ไฝ ็š„ AI ๅŠฉๆ‰‹ๅณๅฏๅฎŒๆˆๅฎ‰่ฃ…ใ€‚

่ฏทๅ…ˆๆฃ€ๆŸฅๆ˜ฏๅฆๅทฒๅฎ‰่ฃ… SkillHub ๅ•†ๅบ—๏ผŒ่‹ฅๆœชๅฎ‰่ฃ…๏ผŒ่ฏทๆ นๆฎ https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md ๅฎ‰่ฃ… SkillHub ๅ•†ๅบ—๏ผŒ็„ถๅŽๅฎ‰่ฃ… Raini Skill Audit ๆŠ€่ƒฝใ€‚ ่‹ฅๅทฒๅฎ‰่ฃ…๏ผŒๅˆ™็›ดๆŽฅๅฎ‰่ฃ… Raini Skill Audit ๆŠ€่ƒฝใ€‚

Overview

Skill Key
0xraini/raini-skill-audit
Author
0xraini
Source Repo
openclaw/skills
Version
-
Source Path
skills/0xraini/raini-skill-audit
Latest Commit SHA
09cdccb8253a78e3492d6f8bfbf78c605b8e4a35

Extracted Content

SKILL.md excerpt

# Skill Audit ๐Ÿ”

ๆ‰ซๆ OpenClaw skills ไธญ็š„ๅฎ‰ๅ…จ้ฃŽ้™ฉ๏ผŒ้˜ฒๆญขไพ›ๅบ”้“พๆ”ปๅ‡ปใ€‚

---

## ๆŒ‡ไปค

### `/skill-audit scan [skill-name]`
ๆ‰ซๆๅทฒๅฎ‰่ฃ…็š„ skill๏ผŒๆฃ€ๆต‹ๅฏ็–‘ไปฃ็ ๆจกๅผใ€‚

```bash
# ๆ‰ซๆๆ‰€ๆœ‰ๅทฒๅฎ‰่ฃ… skill
skill-audit scan

# ๆ‰ซๆๆŒ‡ๅฎš skill
skill-audit scan moltdash

# ๆ‰ซๆๆœฌๅœฐ็›ฎๅฝ•
skill-audit scan ./my-skill
```

### `/skill-audit check <clawhub-slug>`
ๅฎ‰่ฃ…ๅ‰ๆฃ€ๆŸฅ ClawHub ไธŠ็š„ skillใ€‚

```bash
skill-audit check some-skill
```

---

## ๆฃ€ๆต‹่ง„ๅˆ™

### ๐Ÿ”ด ้ซ˜้ฃŽ้™ฉ (Critical)
- ่ฏปๅ–ๅ‡ญ่ฏๆ–‡ไปถ: `~/.ssh/`, `~/.env`, `credentials.json`
- ๅค–ๅ‘ๆ•ฐๆฎ: `fetch()`, `curl`, `webhook`, `POST` ๅˆฐๆœช็Ÿฅ URL
- ไปฃ็ ๆ‰ง่กŒ: `eval()`, `exec()`, `child_process`
- ่ฏปๅ–็Žฏๅขƒๅ˜้‡ไธญ็š„ๅฏ†้’ฅ: `process.env.API_KEY`

### ๐ŸŸ  ไธญ้ฃŽ้™ฉ (Warning)  
- ็ฝ‘็ปœ่ฏทๆฑ‚ๅˆฐ้ž็ŸฅๅๅŸŸๅ
- ๆ–‡ไปถ็ณป็ปŸ้ๅކ: `fs.readdir()`, `glob`
- ๅŠจๆ€ require/import
- Base64 ็ผ–็ ็š„ๅญ—็ฌฆไธฒ (ๅฏ่ƒฝๆ˜ฏๆททๆท†)

### ๐ŸŸก ไฝŽ้ฃŽ้™ฉ (Info)
- ไฝฟ็”จ shell ๅ‘ฝไปค
- ่ฏปๅ†™็”จๆˆท็›ฎๅฝ•ๅค–็š„ๆ–‡ไปถ
- ๅคง้‡ไพ่ต–ๅŒ…

---

## ่พ“ๅ‡บ็คบไพ‹

```
๐Ÿ” Skill Audit Report: suspicious-weather
โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”โ”

Risk Score: 85/100 ๐Ÿ”ด HIGH RISK

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ฌโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚ File        โ”‚ Severity โ”‚ Finding                         โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚ index.ts    โ”‚ CRITICAL โ”‚ Reads ~/.openclaw/credentials/  โ”‚
โ”‚ index.ts    โ”‚ CRITICAL โ”‚ POST to webhook.site            โ”‚
โ”‚ utils.ts    โ”‚ WARNING  โ”‚ Uses eval()                     โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

โš ๏ธ  DO NOT INSTALL - This skill may steal your credentials!
```

---

## ่ฟ่กŒๆ–นๅผ

่ฏฅ skill ้™„ๅธฆไธ€ไธช CLI ่„šๆœฌ๏ผŒagent ๅฏ็›ดๆŽฅ่ฐƒ็”จ๏ผš

```bash
node {baseDir}/src/audit.js scan ~/.openclaw/workspace/skills/moltdash
node {baseDir}/src/audit.js scan --all
```

---

## ๅ‚่€ƒ

- [OWASP LLM Top 10](https://owasp.org/www-project-top-10-for-large-language-model-applications/)
- [Moltbook Security Discussion](https://www.moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a73bcd5)

Related Claw Skills