← 返回 Skills 市场
andyxinweiminicloud

Publisher Identity Verifier

作者 andyxinweiminicloud · GitHub ↗ · v1.0.0
cross-platform ✓ 安全检测通过
493
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install publisher-identity-verifier
功能描述
Helps verify publisher identity integrity in AI agent ecosystems. Detects impersonation, key rotation anomalies, and identity gaps in the trust chain between...
安全使用建议
This SKILL.md is an instruction-only guidance tool and appears internally consistent, but before installing: 1) Note the skill has no homepage and the publisher cannot be verified — you are trusting an unverifiable verifier. 2) Because the instructions are open-ended, ensure the agent enforces network/rate limits and legal/ToS policies to avoid aggressive scraping or unintended data collection. 3) Prefer running this skill in a restricted/sandboxed agent (limited outbound network access) until you confirm its behavior. 4) Ask the publisher for an implementation or audited code (or a documented list of endpoints the skill will query) if you need stronger assurance. 5) Treat its outputs as advisory signals — manually verify high-impact findings (e.g., alleged key rotations or impersonation) before acting.
功能分析
Type: OpenClaw Skill Name: publisher-identity-verifier Version: 1.0.0 The skill's documentation (`SKILL.md`) describes a legitimate security tool for verifying publisher identity. It declares a requirement for `curl` and `python3` binaries, which are powerful but plausibly necessary for a tool that performs cross-platform identity correlation and analysis. There is no evidence of prompt injection attempts, malicious instructions, data exfiltration, or other harmful behaviors within the provided files. The content is transparent and aligned with its stated purpose.
能力评估
Purpose & Capability
The name/description align with the requested primitives: web queries and simple analysis (curl + python3) are reasonable for cross-platform identity checks. However, the skill package has no homepage and an unknown source/owner ID; a tool that audits identity while having no verifiable provenance is a modest concern because you cannot independently vet who produced the verifier.
Instruction Scope
SKILL.md contains a clear, high-level checklist (publication history, key rotation, homoglyph detection, cross-platform correlation). It does not include any instructions to access local files or secrets. It is open-ended about what platforms to query and how aggressively to crawl — this grants broad discretion to the agent and could lead to extensive data collection, scraping, or contacting many third-party endpoints unless the runtime agent enforces limits and policies.
Install Mechanism
No install spec or code is provided (instruction-only). That minimizes installation risk because nothing is written to disk by the skill itself. Required binaries (curl, python3) are common and proportional to the described tasks.
Credentials
The skill requests no environment variables, no credentials, and no config paths. That is appropriate for a tool that examines public identity signals; there is no unexplained secret or elevated access request.
Persistence & Privilege
Defaults are used (no always:true). The skill is user-invocable and can be invoked autonomously per platform defaults; that is expected for a utility skill. There is no request to modify other skills or persist credentials.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install publisher-identity-verifier
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /publisher-identity-verifier 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release — publisher-identity-verifier v1.0.0: - Provides tools to assess publisher identity integrity in AI agent ecosystems. - Detects impersonation attempts, key rotation anomalies, and identity/expertise gaps in the trust chain. - Outputs detailed reports with identity consistency scores, risk assessments, event timelines, and recommended actions for adopters. - Supports auditing via publisher ID, skill identifier, or marketplace search. - Integrates with related tools for code and documentation trust analysis.
元数据
Slug publisher-identity-verifier
版本 1.0.0
许可证
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Publisher Identity Verifier 是什么?

Helps verify publisher identity integrity in AI agent ecosystems. Detects impersonation, key rotation anomalies, and identity gaps in the trust chain between... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 493 次。

如何安装 Publisher Identity Verifier?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install publisher-identity-verifier」即可一键安装,无需额外配置。

Publisher Identity Verifier 是免费的吗?

是的,Publisher Identity Verifier 完全免费(开源免费),可自由下载、安装和使用。

Publisher Identity Verifier 支持哪些平台?

Publisher Identity Verifier 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Publisher Identity Verifier?

由 andyxinweiminicloud(@andyxinweiminicloud)开发并维护,当前版本 v1.0.0。

💬 留言讨论