← 返回 Skills 市场
romainsantoli-web

Firm Platform Audit Pack

作者 romainsantoli-web · GitHub ↗ · v1.0.0
cross-platform ✓ 安全检测通过
306
总下载
0
收藏
1
当前安装
1
版本数
在 OpenClaw 中安装
/install firm-platform-audit-pack
功能描述
Platform alignment audit pack for OpenClaw 2026.2. Secrets v2, agent routing, voice security, trust model, autoupdate, plugin SDK, content boundaries, and sq...
使用说明 (SKILL.md)

firm-platform-audit-pack

⚠️ Contenu généré par IA — validation humaine requise avant utilisation.

Purpose

Validates alignment with OpenClaw platform version 2026.2. Audits Secrets v2 migration, agent routing policies, voice channel security, trust model configuration, autoupdate settings, plugin SDK compliance, content boundary enforcement, and sqlite-vec setup.

Tools (8)

Tool Description Severity
openclaw_secrets_v2_audit Secrets v2 migration readiness CRITICAL
openclaw_agent_routing_check Agent routing policy validation HIGH
openclaw_voice_security_check Voice channel security audit HIGH
openclaw_trust_model_check Trust model configuration HIGH
openclaw_autoupdate_check Autoupdate settings validation MEDIUM
openclaw_plugin_sdk_check Plugin SDK compliance MEDIUM
openclaw_content_boundary_check Content boundary enforcement MEDIUM
openclaw_sqlite_vec_check sqlite-vec extension configuration MEDIUM

Usage

skills:
  - firm-platform-audit-pack

# Run platform alignment audit:
openclaw_secrets_v2_audit config_path=/path/to/config.json
openclaw_trust_model_check config_path=/path/to/config.json
openclaw_agent_routing_check config_path=/path/to/config.json

Requirements

  • mcp-openclaw-extensions >= 3.0.0
  • OpenClaw >= 2026.2
安全使用建议
This instruction-only audit pack appears coherent with its stated purpose, but the source/homepage is missing. Before using: (1) confirm mcp-openclaw-extensions >=3.0.0 comes from a trusted repository and matches the expected vendor, (2) run the checks on a copy or non-production config if those files contain secrets, (3) review the actual implementation of the extension/tools if possible (the SKILL contains no code itself), and (4) treat AI-generated content as guidance only — validate results and outputs before making platform changes.
功能分析
Type: OpenClaw Skill Name: firm-platform-audit-pack Version: 1.0.0 The skill bundle 'firm-platform-audit-pack' appears benign. Its stated purpose is to perform platform alignment audits using specific `openclaw_` audit tools. The `SKILL.md` provides clear instructions and examples consistent with this purpose, without any evidence of data exfiltration, malicious execution, persistence mechanisms, or prompt injection attempts against the AI agent. The dependency declaration (`mcp-openclaw-extensions`) is standard and does not indicate malice within this skill itself.
能力评估
Purpose & Capability
The name/description align with an audit pack for OpenClaw 2026.2. The SKILL.md lists audit tools (secrets, routing, voice, trust, autoupdate, plugin SDK, content boundaries, sqlite-vec) and declares mcp-openclaw-extensions >= 3.0.0 as a requirement; these tools are plausibly provided by that extension. There are no unrelated credentials or binaries requested.
Instruction Scope
Instructions are minimal and simply show invoking audit commands with a config_path argument. That is coherent for an audit pack, but running these checks will require access to platform config files (which may contain secrets or sensitive settings). The SKILL warns that content was AI-generated and needs human validation — follow that guidance.
Install Mechanism
There is no install spec and no code files (instruction-only). This minimizes on-disk installation risk. The declared dependency on mcp-openclaw-extensions is reasonable for this purpose but you should obtain that extension from a trusted source.
Credentials
The skill does not request environment variables or credentials (none declared). However, it operates by taking a config_path — the config you point it at could contain secrets. That is expected for an audit tool, but you should be deliberate about which config files you provide.
Persistence & Privilege
Defaults are normal (always: false, agent invocation allowed). The skill does not request elevated/persistent platform presence or modify other skills. No persistence concerns are evident from the SKILL.md.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install firm-platform-audit-pack
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /firm-platform-audit-pack 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release — 8 tools: secrets v2, routing, voice, trust, autoupdate, plugin SDK
元数据
Slug firm-platform-audit-pack
版本 1.0.0
许可证
累计安装 1
当前安装数 1
历史版本数 1
常见问题

Firm Platform Audit Pack 是什么?

Platform alignment audit pack for OpenClaw 2026.2. Secrets v2, agent routing, voice security, trust model, autoupdate, plugin SDK, content boundaries, and sq... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 306 次。

如何安装 Firm Platform Audit Pack?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install firm-platform-audit-pack」即可一键安装,无需额外配置。

Firm Platform Audit Pack 是免费的吗?

是的,Firm Platform Audit Pack 完全免费(开源免费),可自由下载、安装和使用。

Firm Platform Audit Pack 支持哪些平台?

Firm Platform Audit Pack 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Firm Platform Audit Pack?

由 romainsantoli-web(@romainsantoli-web)开发并维护,当前版本 v1.0.0。

💬 留言讨论