multiAI Summary Pending
Skill Audit ๐
ๆซๆ OpenClaw skills ไธญ็ๅฎๅ จ้ฃ้ฉ๏ผ้ฒๆญขไพๅบ้พๆปๅปใ
3,556 stars
byopenclaw
Installation
Claude Code / Cursor / Codex
$curl -o ~/.claude/skills/raini-skill-audit/SKILL.md --create-dirs "https://raw.githubusercontent.com/openclaw/skills/main/skills/0xraini/raini-skill-audit/SKILL.md"
Manual Installation
- Download SKILL.md from GitHub
- Place it in
.claude/skills/raini-skill-audit/SKILL.mdinside your project - Restart your AI agent โ it will auto-discover the skill
How Skill Audit ๐ Compares
| Feature / Agent | Skill Audit ๐ | Standard Approach |
|---|---|---|
| Platform Support | multi | Limited / Varies |
| Context Awareness | High | Baseline |
| Installation Complexity | Unknown | N/A |
Frequently Asked Questions
What does this skill do?
ๆซๆ OpenClaw skills ไธญ็ๅฎๅ จ้ฃ้ฉ๏ผ้ฒๆญขไพๅบ้พๆปๅปใ
Which AI agents support this skill?
This skill is compatible with multi.
Where can I find the source code?
You can find the source code on GitHub using the link provided at the top of the page.
SKILL.md Source
# Skill Audit ๐
ๆซๆ OpenClaw skills ไธญ็ๅฎๅ
จ้ฃ้ฉ๏ผ้ฒๆญขไพๅบ้พๆปๅปใ
---
## ๆไปค
### `/skill-audit scan [skill-name]`
ๆซๆๅทฒๅฎ่ฃ
็ skill๏ผๆฃๆตๅฏ็ไปฃ็ ๆจกๅผใ
```bash
# ๆซๆๆๆๅทฒๅฎ่ฃ
skill
skill-audit scan
# ๆซๆๆๅฎ skill
skill-audit scan moltdash
# ๆซๆๆฌๅฐ็ฎๅฝ
skill-audit scan ./my-skill
```
### `/skill-audit check <clawhub-slug>`
ๅฎ่ฃ
ๅๆฃๆฅ ClawHub ไธ็ skillใ
```bash
skill-audit check some-skill
```
---
## ๆฃๆต่งๅ
### ๐ด ้ซ้ฃ้ฉ (Critical)
- ่ฏปๅๅญ่ฏๆไปถ: `~/.ssh/`, `~/.env`, `credentials.json`
- ๅคๅๆฐๆฎ: `fetch()`, `curl`, `webhook`, `POST` ๅฐๆช็ฅ URL
- ไปฃ็ ๆง่ก: `eval()`, `exec()`, `child_process`
- ่ฏปๅ็ฏๅขๅ้ไธญ็ๅฏ้ฅ: `process.env.API_KEY`
### ๐ ไธญ้ฃ้ฉ (Warning)
- ็ฝ็ป่ฏทๆฑๅฐ้็ฅๅๅๅ
- ๆไปถ็ณป็ป้ๅ: `fs.readdir()`, `glob`
- ๅจๆ require/import
- Base64 ็ผ็ ็ๅญ็ฌฆไธฒ (ๅฏ่ฝๆฏๆททๆท)
### ๐ก ไฝ้ฃ้ฉ (Info)
- ไฝฟ็จ shell ๅฝไปค
- ่ฏปๅ็จๆท็ฎๅฝๅค็ๆไปถ
- ๅคง้ไพ่ตๅ
---
## ่พๅบ็คบไพ
```
๐ Skill Audit Report: suspicious-weather
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Risk Score: 85/100 ๐ด HIGH RISK
โโโโโโโโโโโโโโโฌโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ File โ Severity โ Finding โ
โโโโโโโโโโโโโโโผโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ index.ts โ CRITICAL โ Reads ~/.openclaw/credentials/ โ
โ index.ts โ CRITICAL โ POST to webhook.site โ
โ utils.ts โ WARNING โ Uses eval() โ
โโโโโโโโโโโโโโโดโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ๏ธ DO NOT INSTALL - This skill may steal your credentials!
```
---
## ่ฟ่กๆนๅผ
่ฏฅ skill ้ๅธฆไธไธช CLI ่ๆฌ๏ผagent ๅฏ็ดๆฅ่ฐ็จ๏ผ
```bash
node {baseDir}/src/audit.js scan ~/.openclaw/workspace/skills/moltdash
node {baseDir}/src/audit.js scan --all
```
---
## ๅ่
- [OWASP LLM Top 10](https://owasp.org/www-project-top-10-for-large-language-model-applications/)
- [Moltbook Security Discussion](https://www.moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a73bcd5)