Requirements
- Target platform
- OpenClaw
- Install method
- Manual import
- Extraction
- Extract archive
- Prerequisites
- OpenClaw
- Primary doc
- SKILL.md
Scans installed or remote OpenClaw skills for security risks like credential leaks and suspicious code to prevent supply chain attacks.
Scans installed or remote OpenClaw skills for security risks like credential leaks and suspicious code to prevent supply chain attacks.
Hand the extracted package to your coding agent with a concrete install brief instead of figuring it out manually.
I downloaded a skill package from Yavira. Read SKILL.md from the extracted folder and install it by following the included instructions. Tell me what you changed and call out any manual steps you could not complete.
I downloaded an updated skill package from Yavira. Read SKILL.md from the extracted folder, compare it with my current installation, and upgrade it while preserving any custom configuration unless the package docs explicitly say otherwise. Summarize what changed and any follow-up checks I should run.
ๆซๆ OpenClaw skills ไธญ็ๅฎๅ จ้ฃ้ฉ๏ผ้ฒๆญขไพๅบ้พๆปๅปใ
ๆซๆๅทฒๅฎ่ฃ ็ skill๏ผๆฃๆตๅฏ็ไปฃ็ ๆจกๅผใ # ๆซๆๆๆๅทฒๅฎ่ฃ skill skill-audit scan # ๆซๆๆๅฎ skill skill-audit scan moltdash # ๆซๆๆฌๅฐ็ฎๅฝ skill-audit scan ./my-skill
ๅฎ่ฃ ๅๆฃๆฅ ClawHub ไธ็ skillใ skill-audit check some-skill
่ฏปๅๅญ่ฏๆไปถ: ~/.ssh/, ~/.env, credentials.json ๅคๅๆฐๆฎ: fetch(), curl, webhook, POST ๅฐๆช็ฅ URL ไปฃ็ ๆง่ก: eval(), exec(), child_process ่ฏปๅ็ฏๅขๅ้ไธญ็ๅฏ้ฅ: process.env.API_KEY
็ฝ็ป่ฏทๆฑๅฐ้็ฅๅๅๅ ๆไปถ็ณป็ป้ๅ: fs.readdir(), glob ๅจๆ require/import Base64 ็ผ็ ็ๅญ็ฌฆไธฒ (ๅฏ่ฝๆฏๆททๆท)
ไฝฟ็จ shell ๅฝไปค ่ฏปๅ็จๆท็ฎๅฝๅค็ๆไปถ ๅคง้ไพ่ตๅ
๐ Skill Audit Report: suspicious-weather โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ Risk Score: 85/100 ๐ด HIGH RISK โโโโโโโโโโโโโโโฌโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ File โ Severity โ Finding โ โโโโโโโโโโโโโโโผโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค โ index.ts โ CRITICAL โ Reads ~/.openclaw/credentials/ โ โ index.ts โ CRITICAL โ POST to webhook.site โ โ utils.ts โ WARNING โ Uses eval() โ โโโโโโโโโโโโโโโดโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ ๏ธ DO NOT INSTALL - This skill may steal your credentials!
่ฏฅ skill ้ๅธฆไธไธช CLI ่ๆฌ๏ผagent ๅฏ็ดๆฅ่ฐ็จ๏ผ node {baseDir}/src/audit.js scan ~/.openclaw/workspace/skills/moltdash node {baseDir}/src/audit.js scan --all
OWASP LLM Top 10 Moltbook Security Discussion
Identity, auth, scanning, governance, audit, and operational guardrails.
Largest current source with strong distribution and engagement signals.