TopRank Skills

Home / Claw Skills / 其他 / skill-auditor
Official OpenClaw rules 15%

skill-auditor

Security audit and quarantine system for third-party OpenClaw skills. Use when evaluating, reviewing, or installing any skill from ClawHub or external sources. Automatically triggered before any skill installation.

Stars

0

Installs

0

Status

ACTIVE

Visibility

PUBLIC

安装方式

直接复制以下提示词,发送给你的 AI 助手即可完成安装。

请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 skill-auditor 技能。 若已安装,则直接安装 skill-auditor 技能。

Overview

Skill Key
aiwithabidi/agxntsix-skill-auditor
Author
aiwithabidi
Source Repo
openclaw/skills
Version
-
Source Path
skills/aiwithabidi/agxntsix-skill-auditor
Latest Commit SHA
5b6e55c3a99183da9bbc5a29109f0a4355a6151f

Extracted Content

SKILL.md excerpt

# Skill Auditor

Security gatekeeper for third-party skill installation. **No skill gets installed without passing audit.**

## When to Use

- Before installing ANY skill from ClawHub or external sources
- When asked to review/evaluate a skill's safety
- When `clawhub install` or similar installation is requested

## Audit Workflow

### 1. Quarantine First
Never copy a skill directly to the production skills directory. Always quarantine first:

```bash
bash skills/skill-auditor/scripts/quarantine.sh /path/to/skill-source
```

This copies the skill to a temp directory, runs the full audit, and only allows installation if the risk score is CLEAN or LOW.

### 2. Manual Audit (Python Script Directly)
For inspection without the quarantine wrapper:

```bash
python3 skills/skill-auditor/scripts/audit_skill.py /path/to/skill-dir
```

Outputs JSON report to stdout. Add `--human` for formatted text output.

### 3. Interpreting Results

| Rating | Action |
|--------|--------|
| CLEAN | Safe to install |
| LOW | Safe, minor notes — review findings briefly |
| MEDIUM | **Do NOT install** without manual review of each finding |
| HIGH | **Block installation** — likely malicious patterns detected |
| CRITICAL | **Block immediately** — active threat indicators (exfil, prompt injection, obfuscated payloads) |

### 4. Exit Codes
- `0` = CLEAN or LOW (safe)
- `1` = MEDIUM (needs review)
- `2` = HIGH or CRITICAL (blocked)

## What Gets Scanned

- All files: inventory, sizes, suspicious file types
- Code: shell commands, network calls, env access, filesystem escape, obfuscation, dynamic imports
- SKILL.md: prompt injection patterns, permission scope requests
- Dependencies: requirements.txt / package.json flagged packages
- Encoding: base64 payloads, hex/unicode escapes, string manipulation tricks

## References

- `references/known-patterns.md` — catalog of real attack patterns from ClawHub
- `references/prompt-injection-patterns.md` — prompt injection signatures to detect

## Importan...

Related Claw Skills