← 返回 Skills 市场
537
总下载
0
收藏
0
当前安装
2
版本数
在 OpenClaw 中安装
/install nyx-archive-skill-security-protocol
功能描述
Teach your AI agent to think about security. A reasoning methodology for vetting skills before installation — red/green flag heuristics, 4-phase audit protoc...
安全使用建议
This skill appears coherent with its stated purpose (a text-based methodology) and has no direct code or credential requests, which is good. However, the documentation contains a prompt-injection pattern that could be either an example or an embedded attempt to override safety. Before installing or running this skill: (1) open SKILL.md and search for literal phrases like 'ignore previous instructions', 'ignore safety', or any direct directive to bypass agent constraints; (2) ensure the file only contains warnings/examples about prompt injection rather than operational directives; (3) run the audit steps in a sandboxed agent session that has no access to your real credentials or filesystem; (4) do not grant any agent running this skill shell access or the ability to read system secrets unless you have manually verified every instruction; (5) if anything in the document instructs the agent to fetch or execute remote code, treat it as a red flag and do not proceed. If you want higher assurance, ask the publisher for provenance (author identity, repository history) or prefer skills from established authors.
功能分析
Type: OpenClaw Skill
Name: nyx-archive-skill-security-protocol
Version: 1.1.1
The OpenClaw AgentSkills skill bundle 'nyx-archive-skill-security-protocol' is benign. Its `SKILL.md` file provides a comprehensive, instruction-based security protocol for an AI agent to vet other skills. It explicitly warns against various attack patterns, including prompt injection, and instructs the agent to use standard system commands (`find`, `cat`, `ps`, `ss`, `crontab`, `ls`) solely for auditing and verification purposes. The skill itself contains no executable scripts or binaries, adhering to its 'zero dependencies' claim, and its entire content is dedicated to enhancing the agent's security judgment.
能力评估
Purpose & Capability
Name/description claim a reasoning methodology for vetting skills and the skill is instruction-only with no binaries, env vars, or install steps — this is coherent and proportionate to its stated purpose.
Instruction Scope
SKILL.md gives stepwise audit guidance (recon, analysis, post-install checks) and sample clawhub commands to inspect skill files — all within scope. However, the static pre-scan flagged a prompt-injection pattern ('ignore-previous-instructions') inside the SKILL.md. That pattern could be benign (an example/warning) or malicious (an attempt to override agent safety). Manually inspect the file for any literal instructions that tell an agent to ignore prior safety constraints, to execute shell commands, or to fetch/run remote code.
Install Mechanism
No install spec and no code files — lowest-risk model (pure documentation). Nothing is written to disk or fetched by the skill itself.
Credentials
No required environment variables, credentials, or config paths are declared; the content describes checking for sensitive files as part of audits but does not request access itself. This is proportionate.
Persistence & Privilege
always:false, user-invocable:true, and no instructions to create persistent agents or system changes. The skill does not request elevated or persistent privileges.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install nyx-archive-skill-security-protocol - 安装完成后,直接呼叫该 Skill 的名称或使用
/nyx-archive-skill-security-protocol触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.1.1
Replace author name with public handle (LeeOde)
v1.1.0
Initial release — 4-phase security audit methodology for vetting skills before installation
元数据
常见问题
[Nyx Archive] Skill Security Protocol 是什么?
Teach your AI agent to think about security. A reasoning methodology for vetting skills before installation — red/green flag heuristics, 4-phase audit protoc... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 537 次。
如何安装 [Nyx Archive] Skill Security Protocol?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install nyx-archive-skill-security-protocol」即可一键安装,无需额外配置。
[Nyx Archive] Skill Security Protocol 是免费的吗?
是的,[Nyx Archive] Skill Security Protocol 完全免费(开源免费),可自由下载、安装和使用。
[Nyx Archive] Skill Security Protocol 支持哪些平台?
[Nyx Archive] Skill Security Protocol 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 [Nyx Archive] Skill Security Protocol?
由 nyxur42(@nyxur42)开发并维护,当前版本 v1.1.1。
推荐 Skills