跳到主内容
智客 ZICQ

技能库 智客分类:安全测试 SkillScan OpenClaw

技能扫描

技能安全门。每项新技能必须通过SkillScan才能使用。在关于技能的任何安装、加载、添加、评估或安全问题上激活。首次加载时,运行首次运行以扫描所有现有技能。阻止高/关键技能。没有例外。

官方网址:ClawHub

技能介绍

先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。

做什么

技能安全门。每项新技能必须通过SkillScan才能使用。在关于技能的任何安装、加载、添加、评估或安全问题上激活。首次加载时,运行首次运行以扫描所有现有技能。阻止高/关键技能。没有例外。

何时用

官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。

代理如何加载

按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:SkillScan v1.1.6、When to Activate、First Load、Commands、Scan Rules、Exit Codes。

文件分析

文件分析:除 SKILL.md 外,正文引用了 scripts/scanner.py、scripts/.first_run_done,属于带资源的技能包,这些文件按需再读。

官方 description(原文)

Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On first load, run first-run to scan all existing skills. Blocks HIGH/CRITICAL skills. No exceptions.

SkillScan v1.1.6When to ActivateFirst LoadCommandsScan RulesExit CodesAuto UpdateEnvironment VariablesAPI

SKILL.md 与 Agent 调用

官方规范 ↗
name
SkillScan
description
Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On first load, run first-run to scan all existing skills. Blocks HIGH/CRITICAL skills. No exceptions.
  1. 发现技能客户端向 Agent 提供名称与描述目录。
  2. 匹配与调用用户指定或任务匹配后,载入 SKILL.md 指令。
  3. 按需加载按步骤读取参考文档、使用脚本与素材。
指令中引用的文件 · 2
  • scripts/scanner.py
  • scripts/.first_run_done

以下路径提取自原文;文件是否齐全请以来源仓库中的完整目录为准。

具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗

安装这个技能

Skills CLI ↗

先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。

该技能引用了附属文件,请从来源获取完整目录;仅复制 SKILL.md 可能缺少依赖。

交给 Agent 安装

复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。

把 Agent Skill「SkillScan」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-8c1ad59832ee7fcf-%E6%8A%80%E8%83%BD%E6%89%AB%E6%8F%8F.html
请存为 .cursor/skills/skillscan/SKILL.md 或 .claude/skills/skillscan/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。
该技能还带 scripts/、references/、assets/ 等文件,请从 https://clawhub.ai/skills/skillscan 取完整目录,不要只建一个 SKILL.md。

当前没有明确的 GitHub 技能包地址,请按来源页面的安装器说明操作。

ClawHub ↗

阅读排版
--- name: SkillScan metadata: version: "1.1.6" description: > Security gate for skills. Every new skill MUST pass SkillScan before use. Activate on any install, load, add, evaluate, or safety question about a skill. On first load, run first-run to scan all existing skills. Blocks HIGH/CRITICAL skills. No exceptions. --- # SkillScan v1.1.6 Security check for skill packages. Every new skill must pass this scan before use. Implemented in `scripts/scanner.py`. Supports Windows / macOS / Linux. Do NOT generate report files inside the skill directory. --- ## When to Activate Run SkillScan whenever a skill is installed, loaded, added, evaluated, or questioned for safety — regardless of method or phrasing. Trigger examples: install, load, add, use, set up, "is this safe", upload .zip/.skill, paste SKILL.md, mention unknown skill name, install from hub/store. --- ## First Load Check `scripts/.first_run_done`: - **Not found** → **Tell user** SkillScan is installed, ask to scan all existing skills: ```bash python /scripts/scanner.py first-run ``` `.first_run_done` is created automatically after completion. - **Found** → Skip, operate normally. --- ## Commands | Command | Usage | |---------|-------| | `scanner.py scan ` | Scan a single skill (.zip or directory) | | `scanner.py scan-all` | Scan all installed skills | | `scanner.py first-run` | First-time full scan | | `scanner.py upgrade` | Manual upgrade | --- ## Scan Rules - **.zip files** → Scan BEFORE installation. Block if fails. - **Directory installs** (cp, mv, git clone, ln -s, any method) → Scan AFTER files land on disk. - **Remote installs** (clawhub, skillhub, npx skills add, etc.) → Scan immediately after install. - **Unknown skills** → If user mentions a skill you haven't seen, scan it. --- ## Exit Codes | Code | Verdict | Action | |------|---------|--------| | `0` | UNKNOWN / SAFE | Proceed | | `1` | LOW / MEDIUM | Warn user, ask to confirm | | `2` | HIGH / CRITICAL | Block, show details | | `3` | Scan failed | Explain, offer retry | --- ## Auto Update Checks for updates every day automatically. Silent, no user action needed. Manual: `scanner.py upgrade`. --- ## Environment Variables | Variable | Description | |----------|-------------| | `SKILL_SCANNER_UPDATE_URL` | Custom update source (optional) | --- ## API Base URL: `https://skillscan.tokauth.com` | Step | Method | Path | |------|--------|------| | ① Cache lookup | GET | `/oapi/v1/skill-scan/search?dir_sha256=` | | ② Upload | POST | `/oapi/v1/skill-scan/upload` | | ③ Poll result | GET | `/oapi/v1/skill-scan/result?task_no=` (poll every 20s, max 180s) |

相关技能

安全测试

技能维特Skill Vetter

人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.

安全测试

护身符Moltguard

MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tre…

安全测试

安保审计员Security Auditor

用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.

安全测试

技能维特Skill Vetter

安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .