← 返回 Skills 市场
Ai Workflow Red Team Lite
作者
vx:17605205782
· GitHub ↗
· v1.0.1
· MIT-0
240
总下载
0
收藏
0
当前安装
2
版本数
在 OpenClaw 中安装
/install ai-workflow-red-team-lite
功能描述
对 AI 自动化流程做轻量红队演练,聚焦误用路径、边界失败和数据泄露风险。;use for red-team, ai, workflow workflows;do not use for 输出可直接滥用的攻击脚本, 帮助破坏系统.
使用说明 (SKILL.md)
AI 工作流轻量红队师
你是什么
你是“AI 工作流轻量红队师”这个独立 Skill,负责:对 AI 自动化流程做轻量红队演练,聚焦误用路径、边界失败和数据泄露风险。
Routing
适合使用的情况
- 帮我轻量 red-team 一下这个 AI 工作流
- 聚焦误用路径和边界失败
- 输入通常包含:流程说明、输入输出、权限边界
- 优先产出:攻击面摘要、误用路径、演练清单
不适合使用的情况
- 不要输出可直接滥用的攻击脚本
- 不要帮助破坏系统
- 如果用户想直接执行外部系统写入、发送、删除、发布、变更配置,先明确边界,再只给审阅版内容或 dry-run 方案。
工作规则
- 先把用户提供的信息重组成任务书,再输出结构化结果。
- 缺信息时,优先显式列出“待确认项”,而不是直接编造。
- 默认先给“可审阅草案”,再给“可执行清单”。
- 遇到高风险、隐私、权限或合规问题,必须加上边界说明。
- 如运行环境允许 shell / exec,可使用:
python3 "{baseDir}/scripts/run.py" --input \x3C输入文件> --output \x3C输出文件>
- 如当前环境不能执行脚本,仍要基于
{baseDir}/resources/template.md与{baseDir}/resources/spec.json的结构直接产出文本。
标准输出结构
请尽量按以下结构组织结果:
- 攻击面摘要
- 误用路径
- 边界失败
- 数据风险
- 缓解建议
- 演练清单
本地资源
- 规范文件:
{baseDir}/resources/spec.json - 输出模板:
{baseDir}/resources/template.md - 示例输入输出:
{baseDir}/examples/ - 冒烟测试:
{baseDir}/tests/smoke-test.md
安全边界
- 只做防御性分析,不提供破坏性步骤。
- 默认只读、可审计、可回滚。
- 不执行高风险命令,不隐藏依赖,不伪造事实或结果。
安全使用建议
This skill appears coherent and implements a local, resources-driven audit/report workflow using the bundled Python script. Before running: (1) avoid pointing the script or the agent at system-wide or sensitive directories (e.g., /, /etc, user home) unless you intend to scan them, because the script will read file contents you supply as input; (2) prefer running the script in an isolated workspace or container and use --dry-run when experimenting; (3) inspect outputs locally before sharing externally — while the script masks long secret-like tokens in reports, it still reads files that could contain secrets; (4) no credentials or network installs are required, but if you modify the skill to add network behavior, re-evaluate carefully. If you want stricter guarantees, review scripts/run.py directly or run it in a sandbox.
功能分析
Type: OpenClaw Skill
Name: ai-workflow-red-team-lite
Version: 1.0.1
The skill bundle is a legitimate security auditing tool designed to perform light red-teaming and risk assessment on AI workflows. The primary logic in `scripts/run.py` performs static analysis, such as regex-based pattern matching for secrets and dangerous shell commands, and generates structured reports based on user-provided input or directories. The instructions in `SKILL.md` and `README.md` are strictly defensive, explicitly prohibiting the generation of harmful scripts or system destruction, and the code contains no network activity, obfuscation, or unauthorized data exfiltration mechanisms.
能力评估
Purpose & Capability
Name/description (lightweight red-team of AI workflows) matches the included assets: a resources-driven template/spec and a Python script (scripts/run.py) that produces structured reports, directory/csv/pattern audits, and skill audits. Required binaries (python3) are proportional to the task.
Instruction Scope
SKILL.md instructs the agent to run the bundled script when shell/exec is available, and to otherwise emit text using the provided templates. The script reads files and directories supplied as input and will scan file contents for patterns (secrets, dangerous commands, private URLs). This behavior is appropriate for an audit tool but means the agent could read arbitrary local files if given paths (so avoid pointing it at system roots or sensitive directories).
Install Mechanism
No install spec; the skill is instruction-only with bundled code. There are no remote downloads or package installs—only a local Python script that relies on the standard library.
Credentials
The skill declares no environment variables or credentials. The script scans file contents but does not attempt to access external secrets stores or network endpoints. No disproportionate credential requests were found.
Persistence & Privilege
always:false and no special privileges requested. The skill does not modify other skills or global agent settings. It can write an output file if run with --output, which is expected behavior for a local report generator.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install ai-workflow-red-team-lite - 安装完成后,直接呼叫该 Skill 的名称或使用
/ai-workflow-red-team-lite触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.1
No changes detected in this version.
v1.0.0
Initial release of ai-workflow-red-team-lite.
- Provides lightweight red teaming for AI automation workflows, focusing on misuse paths, boundary failures, and data leakage risks.
- Prioritizes defensive analysis and structured output: attack surface summary, misuse paths, boundary failures, data risks, mitigation advice, and exercise checklist.
- Enforces strict boundaries: no direct attack scripts, no destructive actions, and explicit boundary clarification for high-risk operations.
- Supports both shell/script-based and text-based workflows depending on environment capabilities.
- Designed for easy review and audit, with clear documentation and local resource usage.
元数据
常见问题
Ai Workflow Red Team Lite 是什么?
对 AI 自动化流程做轻量红队演练,聚焦误用路径、边界失败和数据泄露风险。;use for red-team, ai, workflow workflows;do not use for 输出可直接滥用的攻击脚本, 帮助破坏系统. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 240 次。
如何安装 Ai Workflow Red Team Lite?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install ai-workflow-red-team-lite」即可一键安装,无需额外配置。
Ai Workflow Red Team Lite 是免费的吗?
是的,Ai Workflow Red Team Lite 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Ai Workflow Red Team Lite 支持哪些平台?
Ai Workflow Red Team Lite 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(darwin, linux, win32)。
谁开发了 Ai Workflow Red Team Lite?
由 vx:17605205782(@52yuanchangxing)开发并维护,当前版本 v1.0.1。
推荐 Skills