← 返回 Skills 市场
432
总下载
1
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install multi-skill-automation-suite
功能描述
Comprehensive automation suite combining multiple OpenClaw skills for security, development, content processing, and utilities. Includes healthcheck, git ess...
安全使用建议
Do not install this suite yet. Ask the maintainer for: (1) source code or install scripts for 'clawhub install' and the auto-update/auto-install functions, (2) exact runtime commands the skill will run for host hardening and whether they require sudo/root, (3) which binaries (headless browser, monitoring agents) it will install and from what URLs/releases, (4) evidence the suite won't modify other skills or agent configs without explicit consent, and (5) clarification and justification for the 'AI Text Humanization / bypass detection' feature (it may be misuse). If you must test, run it in a fully isolated sandbox or VM, review the actual installer and update mechanism, and prefer a signed, well-documented release with a verifiable homepage and maintainer contact.
功能分析
Type: OpenClaw Skill
Name: multi-skill-automation-suite
Version: 1.0.0
The skill bundle is classified as suspicious due to explicit instructions in SKILL.md and README.md that create significant security vulnerabilities for the OpenClaw agent. Most notably, the 'Skill Discovery' feature is described as 'Find and install new agent skills automatically', which is a direct instruction for the AI agent to perform arbitrary code execution by installing potentially malicious skills without explicit user confirmation. Furthermore, instructions for 'Host Security Hardening', 'Firewall & SSH Management', and 'Browser Automation' grant the agent broad system-level and web interaction capabilities, increasing the attack surface if the agent is compromised or misdirected through prompt injection.
能力评估
Purpose & Capability
The suite claims host hardening, firewall/SSH management and system monitoring (operations that normally require elevated privileges and explicit configuration), plus automatic discovery/installation of other skills and headless-browser automation. Yet the manifest requests only git and curl and lists no config paths, no install steps, and no privilege requirements. That mismatch is inconsistent: either the skill cannot actually perform those tasks as described, or it omits required capabilities/permissions.
Instruction Scope
SKILL.md is high-level and provides no concrete runtime commands or file paths. It asserts automatic updates and 'find and install new agent skills automatically' but gives no mechanism or safeguards — this vagueness grants broad implicit discretion. Additionally, it advertises 'AI Text Humanization' to 'bypass detection systems', which is an explicit instruction to produce evasive outputs and raises ethical/misuse concerns.
Install Mechanism
This is instruction-only with no install spec or code files, so nothing will be written to disk by the skill bundle itself. That lowers direct supply-chain risk. However, the README/usage references 'clawhub install' and automatic updates; the actual installer and its source are not provided here and would need review.
Credentials
No environment variables, credentials, or config paths are requested despite capabilities that normally require them (system/root access, cloud credentials for monitoring, browser binaries). The absence of declared secrets is proportional on paper but implausible given the claimed features; lack of declared credentials makes the capability claims suspect or under-specified.
Persistence & Privilege
always:false (normal). The skill claims it will auto-install and auto-update other skills, which implies the ability to modify agent configuration or perform network installs; those privileges are not made explicit. Default autonomous invocation is allowed (disable-model-invocation:false) — combine that with the suite's claim to auto-manage skills and you have a higher blast radius if the implementation were malicious or buggy.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install multi-skill-automation-suite - 安装完成后,直接呼叫该 Skill 的名称或使用
/multi-skill-automation-suite触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release: Comprehensive automation suite with security, development, content processing, and utility skills
元数据
常见问题
Multi-Skill Automation Suite 是什么?
Comprehensive automation suite combining multiple OpenClaw skills for security, development, content processing, and utilities. Includes healthcheck, git ess... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 432 次。
如何安装 Multi-Skill Automation Suite?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install multi-skill-automation-suite」即可一键安装,无需额外配置。
Multi-Skill Automation Suite 是免费的吗?
是的,Multi-Skill Automation Suite 完全免费(开源免费),可自由下载、安装和使用。
Multi-Skill Automation Suite 支持哪些平台?
Multi-Skill Automation Suite 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Multi-Skill Automation Suite?
由 BestRocky(@bestrocky)开发并维护,当前版本 v1.0.0。
推荐 Skills