Overview
- Skill Key
- 0xraini/raini-skill-audit
- Author
- 0xraini
- Source Repo
- openclaw/skills
- Version
- -
- Source Path
- skills/0xraini/raini-skill-audit
- Latest Commit SHA
- 09cdccb8253a78e3492d6f8bfbf78c605b8e4a35
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
็ดๆฅๅคๅถไปฅไธๆ็คบ่ฏ๏ผๅ้็ปไฝ ็ AI ๅฉๆๅณๅฏๅฎๆๅฎ่ฃ ใ
่ฏทๅ ๆฃๆฅๆฏๅฆๅทฒๅฎ่ฃ SkillHub ๅๅบ๏ผ่ฅๆชๅฎ่ฃ ๏ผ่ฏทๆ นๆฎ https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md ๅฎ่ฃ SkillHub ๅๅบ๏ผ็ถๅๅฎ่ฃ Raini Skill Audit ๆ่ฝใ ่ฅๅทฒๅฎ่ฃ ๏ผๅ็ดๆฅๅฎ่ฃ Raini Skill Audit ๆ่ฝใ
# Skill Audit ๐
ๆซๆ OpenClaw skills ไธญ็ๅฎๅ
จ้ฃ้ฉ๏ผ้ฒๆญขไพๅบ้พๆปๅปใ
---
## ๆไปค
### `/skill-audit scan [skill-name]`
ๆซๆๅทฒๅฎ่ฃ
็ skill๏ผๆฃๆตๅฏ็ไปฃ็ ๆจกๅผใ
```bash
# ๆซๆๆๆๅทฒๅฎ่ฃ
skill
skill-audit scan
# ๆซๆๆๅฎ skill
skill-audit scan moltdash
# ๆซๆๆฌๅฐ็ฎๅฝ
skill-audit scan ./my-skill
```
### `/skill-audit check <clawhub-slug>`
ๅฎ่ฃ
ๅๆฃๆฅ ClawHub ไธ็ skillใ
```bash
skill-audit check some-skill
```
---
## ๆฃๆต่งๅ
### ๐ด ้ซ้ฃ้ฉ (Critical)
- ่ฏปๅๅญ่ฏๆไปถ: `~/.ssh/`, `~/.env`, `credentials.json`
- ๅคๅๆฐๆฎ: `fetch()`, `curl`, `webhook`, `POST` ๅฐๆช็ฅ URL
- ไปฃ็ ๆง่ก: `eval()`, `exec()`, `child_process`
- ่ฏปๅ็ฏๅขๅ้ไธญ็ๅฏ้ฅ: `process.env.API_KEY`
### ๐ ไธญ้ฃ้ฉ (Warning)
- ็ฝ็ป่ฏทๆฑๅฐ้็ฅๅๅๅ
- ๆไปถ็ณป็ป้ๅ: `fs.readdir()`, `glob`
- ๅจๆ require/import
- Base64 ็ผ็ ็ๅญ็ฌฆไธฒ (ๅฏ่ฝๆฏๆททๆท)
### ๐ก ไฝ้ฃ้ฉ (Info)
- ไฝฟ็จ shell ๅฝไปค
- ่ฏปๅ็จๆท็ฎๅฝๅค็ๆไปถ
- ๅคง้ไพ่ตๅ
---
## ่พๅบ็คบไพ
```
๐ Skill Audit Report: suspicious-weather
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Risk Score: 85/100 ๐ด HIGH RISK
โโโโโโโโโโโโโโโฌโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ File โ Severity โ Finding โ
โโโโโโโโโโโโโโโผโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ index.ts โ CRITICAL โ Reads ~/.openclaw/credentials/ โ
โ index.ts โ CRITICAL โ POST to webhook.site โ
โ utils.ts โ WARNING โ Uses eval() โ
โโโโโโโโโโโโโโโดโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๏ธ DO NOT INSTALL - This skill may steal your credentials!
```
---
## ่ฟ่กๆนๅผ
่ฏฅ skill ้ๅธฆไธไธช CLI ่ๆฌ๏ผagent ๅฏ็ดๆฅ่ฐ็จ๏ผ
```bash
node {baseDir}/src/audit.js scan ~/.openclaw/workspace/skills/moltdash
node {baseDir}/src/audit.js scan --all
```
---
## ๅ่
- [OWASP LLM Top 10](https://owasp.org/www-project-top-10-for-large-language-model-applications/)
- [Moltbook Security Discussion](https://www.moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a73bcd5)
human-pages-ai
Search and hire real humans for tasks โ photography, delivery, research, and more
zseven-w
Reusable skill templates for OpenClaw AI agents. Templates for API integration, data processing, web scraping, CLI tools, and file processing.
capt-marbles
Attio CRM integration for managing companies, people, deals, notes, tasks, and custom objects. Use when working with Attio CRM data, searching contacts, managing sales pipelines, adding notes to records, creating tasks, or syncing prospect information.
capt-marbles
Web scraping and crawling with Firecrawl API. Fetch webpage content as markdown, take screenshots, extract structured data, search the web, and crawl documentation sites. Use when the user needs to scrape a URL, get current web info, capture a screenshot, extract specific data from pages, or crawl docs for a framework/library.
caqlayan
Tweet Processor Skill
carlosarturoleon
Connect to Windsor.ai MCP for natural language access to 325+ data sources including Facebook Ads, GA4, HubSpot, Shopify, and more.