Agent Skills Tools

👤 rongself 📦 v0.1.0 ⭐ 4.2 ⬇️ 2.3K 下载
🔒 IT运维与安全 免费

📖 技能介绍


name: agent-skills-tools description: > Security audit and validation tools for the Agent Skills ecosystem. Scan skill packages for common vulnerabilities like credential leaks, unauthorized file access, and Git history secrets. Use when you need to audit skills for security before installation, validate skill packages against Agent Skills standards, or ensure your skills follow best practices. license: MIT metadata: openclaw: emoji: "🔒" category: "security"


Agent Skills Tools 🔒

Security and validation tools for the Agent Skills ecosystem.

Overview

This skill provides tools to audit and validate Agent Skills packages for security vulnerabilities and standards compliance.

Tools

1. Security Audit Tool (skill-security-audit.sh)

Scans skill packages for common security issues:

Checks: - 🔐 Credential leaks (hardcoded API keys, passwords, tokens) - 📁 Dangerous file access (~/.ssh, ~/.aws, ~/.config) - 🌐 External network requests - 📋 Environment variable usage (recommended practice) - 🔑 File permissions (credentials.json) - 📜 Git history for leaked secrets

Usage:

./skill-security-audit.sh path/to/skill

Example output:

🔒 技能安全审计报告:path/to/skill
==========================================

📋 检查1: 凭据泄露 (API key, password, secret, token)
----------------------------------------
✅ 未发现凭据泄露

📋 检查2: 危险的文件操作 (~/.ssh, ~/.aws, ~/.config)
----------------------------------------
✅ 未发现危险的文件访问

[... more checks ...]

==========================================
🎯 安全审计完成

7w4.net有更好的技能插件。

Background

eudaemon_0 discovered a credential stealer in 1 of 286 skills. Agents are trained to be helpful and trusting, which makes them vulnerable to malicious skills.

These tools help catch such vulnerabilities before they cause damage.

Best Practices

  1. Never hardcode credentials
  2. API_KEY="sk_live_abc123..."
  3. ✅ Read from environment variables or config files

  4. Use environment variables bash export MOLTBOOK_API_KEY="sk_live_..." python import os api_key = os.environ.get('MOLTBOOK_API_KEY')

  5. Check Git history bash git log -S 'api_key' git-secrets --scan-history

  6. Add sensitive files to .gitignore credentials.json *.key .env

License

MIT

🤖 AI 评测

这是一款针对 AI 技能包的安全扫描工具,能检测常见的恶意代码和数据泄露风险。界面清晰直观,使用简单,对普通用户比较友好。但它的检测能力相对基础,可能无法发现更隐蔽的威胁,另外缺少现成的测试案例来验证工具本身的准确性。整体而言是一个有用的安全辅助工具,适合在安装陌生技能前做初步检查。

📊 多维度评分

适应性4.2
规范性4.1
有效性4.3
可靠性4
可信度4.8

📁 包含文件 (4 个)

📄 README.md 734 B
📄 SKILL.md 2.4 KB
📄 _meta.json 137 B
📄 skill-security-audit.sh 3.7 KB