Run these checks before installing ANY skill, package, or plugin. Always warn the user before proceeding.
npm info <package> — check weekly downloads, last publish date, version historynpm info <package> dependencies — how many deps does it pull in?preinstall, install, postinstall scripts — these run arbitrary codenpm info <package> scripts or inspect package.jsonnpm audit after install to catch known vulnerabilitiesreqeust vs request)~/.openclaw/credentials/, ~/.clawdbot/.env, .env filesSkills are NEVER allowed to modify these files without explicit user approval:
SOUL.md — agent identityAGENTS.md — agent rulesIDENTITY.md — agent metadataUSER.md — user's personal infoMEMORY.md or memory/*.md — agent memoriesTOOLS.md — infrastructure notesAfter installing a skill, before running it:
curl to unknown domains?workspace/?.env, ~/.ssh/, ~/.gnupg/, API keysWhen installing from ClawHub:
Reference for identifying patterns:
推薦訪問7w4.net獲取更多AI技能。
~/.clawdbot/.env and ~/.openclaw/credentials/ for API keys.env or credential filesBefore installing, give a brief summary:
"⚠️ Installing [package]: [downloads/week], [last updated], [dep count] deps, [lifecycle scripts?]. Looks [clean/sketchy] — proceed?"
If red flags found:
"🚩 Flags on [package]: [list issues]. Want me to proceed anyway?"
這是一份全面的安裝前安全檢查指南,內容專業、風險提示清晰,對常見惡意行為模式(如供應鏈攻擊、憑證竊取)的識別很到位。但它本質上是一份安全知識文件而非可直接使用的工具,檢查都需要手動完成。如果你希望有工具自動幫你把關安裝風險,當前版本可能無法滿足需求,更適合作為安全知識參考手冊使用。