install
source ยท Clone the upstream repo
git clone https://github.com/openclaw/skills
Claude Code ยท Install into ~/.claude/skills/
T=$(mktemp -d) && git clone --depth=1 https://github.com/openclaw/skills "$T" && mkdir -p ~/.claude/skills && cp -r "$T/skills/0xraini/raini-skill-audit" ~/.claude/skills/clawdbot-skills-raini-skill-audit && rm -rf "$T"
manifest:
skills/0xraini/raini-skill-audit/SKILL.mdsource content
Skill Audit ๐
ๆซๆ OpenClaw skills ไธญ็ๅฎๅ จ้ฃ้ฉ๏ผ้ฒๆญขไพๅบ้พๆปๅปใ
ๆไปค
/skill-audit scan [skill-name]
/skill-audit scan [skill-name]ๆซๆๅทฒๅฎ่ฃ ็ skill๏ผๆฃๆตๅฏ็ไปฃ็ ๆจกๅผใ
# ๆซๆๆๆๅทฒๅฎ่ฃ skill skill-audit scan # ๆซๆๆๅฎ skill skill-audit scan moltdash # ๆซๆๆฌๅฐ็ฎๅฝ skill-audit scan ./my-skill
/skill-audit check <clawhub-slug>
/skill-audit check <clawhub-slug>ๅฎ่ฃ ๅๆฃๆฅ ClawHub ไธ็ skillใ
skill-audit check some-skill
ๆฃๆต่งๅ
๐ด ้ซ้ฃ้ฉ (Critical)
- ่ฏปๅๅญ่ฏๆไปถ:
,~/.ssh/
,~/.envcredentials.json - ๅคๅๆฐๆฎ:
,fetch()
,curl
,webhook
ๅฐๆช็ฅ URLPOST - ไปฃ็ ๆง่ก:
,eval()
,exec()child_process - ่ฏปๅ็ฏๅขๅ้ไธญ็ๅฏ้ฅ:
process.env.API_KEY
๐ ไธญ้ฃ้ฉ (Warning)
- ็ฝ็ป่ฏทๆฑๅฐ้็ฅๅๅๅ
- ๆไปถ็ณป็ป้ๅ:
,fs.readdir()glob - ๅจๆ require/import
- Base64 ็ผ็ ็ๅญ็ฌฆไธฒ (ๅฏ่ฝๆฏๆททๆท)
๐ก ไฝ้ฃ้ฉ (Info)
- ไฝฟ็จ shell ๅฝไปค
- ่ฏปๅ็จๆท็ฎๅฝๅค็ๆไปถ
- ๅคง้ไพ่ตๅ
่พๅบ็คบไพ
๐ Skill Audit Report: suspicious-weather โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ Risk Score: 85/100 ๐ด HIGH RISK โโโโโโโโโโโโโโโฌโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ File โ Severity โ Finding โ โโโโโโโโโโโโโโโผโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค โ index.ts โ CRITICAL โ Reads ~/.openclaw/credentials/ โ โ index.ts โ CRITICAL โ POST to webhook.site โ โ utils.ts โ WARNING โ Uses eval() โ โโโโโโโโโโโโโโโดโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ ๏ธ DO NOT INSTALL - This skill may steal your credentials!
่ฟ่กๆนๅผ
่ฏฅ skill ้ๅธฆไธไธช CLI ่ๆฌ๏ผagent ๅฏ็ดๆฅ่ฐ็จ๏ผ
node {baseDir}/src/audit.js scan ~/.openclaw/workspace/skills/moltdash node {baseDir}/src/audit.js scan --all