← 返回 Skills 市场
7639
总下载
6
收藏
0
当前安装
3
版本数
在 OpenClaw 中安装
/install clawdex
功能描述
Security check for ClawHub skills powered by Koi. Query the Clawdex API before installing any skill to verify it's safe.
安全使用建议
Before installing, be comfortable with sending candidate or installed skill names to Koi’s Clawdex API for verdicts. Treat the verdicts as advisory and keep user approval in the loop for unknown or risky skills.
功能分析
Type: OpenClaw Skill
Name: clawdex
Version: 1.0.2
The OpenClaw AgentSkills skill bundle 'clawdex' is designed to perform security checks on other ClawHub skills. Its primary function involves making `curl` requests to `https://clawdex.koi.security/api/skill/SKILL_NAME` to retrieve a security verdict, which is consistent with its stated purpose. It also uses `ls` to list installed skills in `~/.openclaw/skills/` or `~/.clawdbot/skills/` for auditing. While the `SKILL.md` contains instructions for the AI agent (e.g., to inform the user or seek approval for 'unknown' skills), these are security-positive directives that align with the skill's function and do not constitute malicious prompt injection. There is no evidence of data exfiltration, malicious execution, persistence, or other harmful behaviors.
能力评估
Purpose & Capability
The artifact’s stated purpose is to check ClawHub skills for safety, and its capabilities are limited to querying a Clawdex/Koi verdict API and optionally listing installed skill names for audit.
Instruction Scope
Runtime instructions are security-focused: check a skill before installation, avoid installing malicious results, and ask the user before installing unknown results. No hidden role override, unrelated agent control, or deceptive instruction was found.
Install Mechanism
The reviewed package contains only SKILL.md and metadata; no executable install hooks, scripts, dependencies, or mutation mechanisms were present.
Credentials
The skill may list local installed-skill directories and send skill names to an external API. That data flow is disclosed and proportionate for a security-audit skill, but users should understand it.
Persistence & Privilege
No evidence of persistence, privilege escalation, credential access, destructive actions, background workers, or automatic modification of installed skills was found.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install clawdex - 安装完成后,直接呼叫该 Skill 的名称或使用
/clawdex触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.2
- Updated skill name and description to reference "Koi" instead of "Koi Security."
- Changed "About Koi Security" section title to "About Koi" and updated the description, mentioning that Clawdex verdicts are powered by Wings, the agentic AI risk engine.
- Minor rewording throughout documentation for consistency and clarity.
v1.0.1
- No changes detected in this version.
- Version number updated to 1.0.1.
v1.0.0
Initial release of the Clawdex skill.
- Provides a security check for ClawHub skills using the Clawdex API.
- Returns a verdict ("benign", "malicious", or "unknown") to help users decide if a skill is safe to install.
- Guides users on interpreting verdicts and next steps for each case.
- Includes instructions for auditing already-installed skills for potential threats.
- Developed by Koi Security.
元数据
常见问题
Clawdex by Koi 是什么?
Security check for ClawHub skills powered by Koi. Query the Clawdex API before installing any skill to verify it's safe. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 7639 次。
如何安装 Clawdex by Koi?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install clawdex」即可一键安装,无需额外配置。
Clawdex by Koi 是免费的吗?
是的,Clawdex by Koi 完全免费(开源免费),可自由下载、安装和使用。
Clawdex by Koi 支持哪些平台?
Clawdex by Koi 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Clawdex by Koi?
由 wearekoi(@wearekoi)开发并维护,当前版本 v1.0.2。
推荐 Skills