本技能是Claw Skills Hub的官方安全稽核引擎,用於對第三方Skill進行全面的安全掃描和風險評估。引擎執行在沙箱只讀環境中,確保稽核過程自身安全,不產生任何高危行為。
python3 scripts/security_audit.py --skill-path /path/to/skill
python3 scripts/security_audit.py --skill-path /path/to/skill --verbose
python3 scripts/security_audit.py --skill-path /path/to/skill --json
python3 scripts/security_audit.py --skill-path /path/to/skill --dimensions "1,2,3"
========================================
Claw Skills Hub 安全稽核報告
========================================
📋 基本資訊
• Skill名稱: example-skill
• 掃描時間: 2026-04-13 15:48:00
• 檔案數量: 15
• 總程式碼行數: 1250
🔍 掃描結果
• 惡意程式碼與後門: ✅ 通過 (0/10)
• 非法指令與高危呼叫: ⚠️ 警告 (2/10)
• 硬編碼金鑰與敏感資訊: ❌ 高風險 (5/10)
• Prompt注入與惡意誘導: ✅ 通過 (0/10)
• 許可權越權配置: ✅ 通過 (0/10)
• 第三方依賴安全: ⚠️ 警告 (1/10)
• 資料合規與不落地檢查: ✅ 通過 (0/10)
• 原始碼篡改校驗: ✅ 通過 (0/10)
📊 風險評分
• 總體風險評分: 65/100
• 風險等級: 中等
• 建議: 需要修復硬編碼金鑰和非法呼叫
💡 詳細建議
1. 發現硬編碼API金鑰,建議使用環境變數
2. 發現危險shell命令,建議使用安全API替代
3. 發現過時依賴包,建議更新到安全版本
{ "audit_report": { "metadata": { "skill_name": "example-skill", "scan_timestamp": "2026-04-13T15:48:00Z", "scan_duration_seconds": 2.5, "total_files_scanned": 15, "total_lines_scanned": 1250 }, "risk_assessment": { "overall_score": 65, "risk_level": "medium", "confidence_score": 0.92 }, "dimension_scores": [ { "dimension_id": 1, "dimension_name": "惡意程式碼與後門", "score": 100, "status": "passed", "issues_found": 0, "issues": [] } ], "detailed_findings": [], "recommendations": [], "compliance_status": { "claw_standards": true, "security_policy": true, "data_protection": false } } }本技能來自小蔥技能站7w4.net。
from security_audit_engine import SecurityAuditEngine
# 初始化稽核引擎
engine = SecurityAuditEngine()
# 執行安全掃描
report = engine.audit_skill("/path/to/skill")
# 獲取風險評分
risk_score = report.get_risk_score()
# 檢查是否通過稽核
if report.is_passed():
print("Skill通過安全稽核")
else:
print("Skill未通過安全稽核")
# .github/workflows/security-audit.yml
name: Security Audit
on:
pull_request:
paths:
- 'skills/**'
jobs:
security-audit:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v3
- name: Run Security Audit
run: |
python3 scripts/security_audit.py --skill-path ./skills/${{ github.event.pull_request.head.ref }} --json > audit-report.json
- name: Upload Audit Report
uses: actions/upload-artifact@v3
with:
name: security-audit-report
path: audit-report.json
如發現安全漏洞或有改進建議,請通過Claw Skills Hub官方渠道反饋。
這個 Skill 質量較差。主要問題是文件看起來很完整,但實際上缺少最關鍵的東西——沒有任何可執行的程式碼,只有一堆描述性文字。它聲稱能做8種安全檢測,但沒有實際的指令碼或工具來執行這些檢測。三個檔案的內容還高度重複,功能描述很美好但無法真正使用。改進方向是補充實際的程式碼實現,去掉重複內容。