← 返回
未分类 中文

Klemenska Security Auditor

Scan and audit installed skills for security risks, suspicious patterns, and permission overreach. Use when: (1) before installing a new skill; (2) periodica...
对已安装技能进行安全扫描与审计,检测风险、可疑行为及权限过度。使用场景:①安装新技能前;②定期检查。
klemenska
未分类 clawhub v1.0.0 1 版本 100000 Key: 无需
★ 0
Stars
📥 324
下载
💾 0
安装
1
版本
#latest

概述

Security Auditor

Audit skills for security risks before installing or using them.

Purpose

Skills can request permissions and access that may be:

  • Overreaching (accessing data they shouldn't need)
  • Suspicious (behaving oddly, phoning home, etc.)
  • Outdated (known vulnerabilities in dependencies)

This skill helps you audit them.

When to Run

TriggerAction
-----------------
Before installing a new skillFull audit
Periodic reviewQuick scan of installed skills
Suspicious behaviorDeep analysis
Permission reviewCheck requested permissions

Audit Workflow

Step 1: Quick Scan

python3 scripts/audit.py --scan

Checks:

  • File access patterns
  • Network access requests
  • Suspicious API usage
  • Permission requests

Step 2: Detailed Audit

python3 scripts/audit.py --audit <skill-path>

Performs deep analysis:

  • Code pattern analysis
  • Dependency checking
  • Permission mapping
  • Risk scoring

Step 3: Generate Report

python3 scripts/audit.py --report <skill-path> --output report.md

Creates detailed security report.

Step 4: Compare Skills

python3 scripts/audit.py --compare <skill1-path> <skill2-path>

Compare security posture of two skills.

Risk Levels

LevelMeaningAction
------------------------
🟢 LOWMinimal risk, standard permissionsSafe to install
🟡 MEDIUMSome overreach, review recommendedRead code before install
🔴 HIGHSignificant risks, careful review requiredDo not install without review
⛔ CRITICALDangerous patterns detectedDo not install

Red Flags to Watch For

File Access

  • Accessing ~/.ssh/ or ~/.aws/
  • Reading password, secret, key files
  • Writing to system directories
  • Accessing other users' directories

Network

  • Exfiltrating data to unknown servers
  • DNS rebinding patterns
  • Encrypted payloads to unfamiliar domains

Permissions

  • Requesting exec with no scope limitation
  • Reading memory or process info
  • Keylogging or screenshot capabilities
  • Accessing other installed skills' data

Code Patterns

  • Obfuscated code
  • Dynamic code generation
  • Shell commands without sanitization
  • Credential harvesting patterns

Files

  • scripts/audit.py — Main audit script
  • scripts/scan_skill.py — Skill-specific scanner
  • references/rules.md — Security rules and patterns
  • references/permissions.md — Permission reference guide

版本历史

共 1 个版本

  • v1.0.0 当前
    2026-05-07 10:49 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

data-analysis

Twitter/X API

klemenska
通过API管理X/Twitter消息,包括读取、发布推文、回复、发送私信、搜索和查看分析数据。用于用户与X/Twitter互动场景。
★ 0 📥 1,825

Context Window Optimizer

klemenska
优化上下文窗口使用,通过总结旧对话片段,提取关键事实和决定存入永久记忆,并保持当前上下文精简
★ 0 📥 436

Memory Defragmenter

klemenska
对代理记忆文件进行碎片整理和优化,清理重复项、合并相似条目、归档陈旧内容并确保层级划分合理。适用场景:(...
★ 0 📥 430