/install cmic-skill-scanner
Skill Scan Wrapper
当你要在安装一个本地 skill、归档或 release bundle 前做一次快速安全检查时,使用这个 skill。
⚠️ Security Notice
This tool operates locally and requires user trust in the binary you run. Always verify the checksum after downloading. For maximum security, build from source (recommended).
Reference Package (No Binary)
This package contains only documentation. Pre-built binaries are hosted on Gitee Releases (open source, verifiable).
Download from Gitee Releases: https://gitee.com/random_player/cmic-skill-scanner/releases
Verify checksums before running: See https://gitee.com/random_player/cmic-skill-scanner/raw/main/releases/v0.8.0/SHA256SUMS
Build from source (recommended for maximum security):
git clone https://gitee.com/random_player/cmic-skill-scanner.git
cd cmic-skill-scanner && cargo build --release
前置条件
- 默认不需要任何外部依赖
--upload-url和--engine external功能默认禁用,仅在用户显式配置时启用
信任模型
This is an open-source (MIT-0) package. The binary (bundled or downloaded) is a convenience only — it does not grant any additional trust.
Your options:
| Approach | Trust Requirement | Verification |
|---|---|---|
| Build from source | None (you control everything) | Manual code review |
| Bundled/downloaded binary | You trust the release host | SHA-256 checksum |
What the tool does NOT do by default:
- Does NOT upload data anywhere
- Does NOT connect to the network
- Does NOT access credentials, SSH configs, or environment variables
- Does NOT execute external tools unless you explicitly configure
--engine external
工作流程
- 调用 skillscan:
skillscan review /path/to/target --format markdown
skillscan review /path/to/skills --output-dir /tmp/skillscan-out
- 阅读输出中的:输入类型、完整度、engine 执行状态、findings
网络上传功能 (默认禁用)
⚠️ This feature is completely optional and disabled by default. It requires explicit user configuration via --upload-url.
What gets sent (only when you configure --upload-url):
- A structured JSON report containing detection findings
- An instance identifier you supply via
--instance-id - No skill source code, credentials, or system configuration is ever transmitted
外部引擎集成 (默认禁用)
⚠️ This feature is completely optional and disabled by default. It requires explicit user configuration via --engine external.
Delegates pattern-matching to a user-configured local tool. This runs locally — no remote calls are made.
Permissions Required
| Scope | Reason |
|---|---|
| Read files in target path | To analyze skill source code for patterns |
Write to --output-dir |
To save scan reports locally |
| Execute binary | To run the scanner engine |
| Network (optional) | Only if --upload-url is explicitly configured |
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install cmic-skill-scanner - 安装完成后,直接呼叫该 Skill 的名称或使用
/cmic-skill-scanner触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
CMIC Skill Scanner 是什么?
使用内置 Rust 引擎审计待安装的 skill 包或归档,并可选桥接外部 scanner。 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 153 次。
如何安装 CMIC Skill Scanner?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install cmic-skill-scanner」即可一键安装,无需额外配置。
CMIC Skill Scanner 是免费的吗?
是的,CMIC Skill Scanner 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
CMIC Skill Scanner 支持哪些平台?
CMIC Skill Scanner 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 CMIC Skill Scanner?
由 cyzlmh(@cyzlmh)开发并维护,当前版本 v0.8.0。