← 返回 Skills 市场
engsathiago

Seguranca Auditoria

作者 engsathiago · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ✓ 安全检测通过
155
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install seguranca-auditoria
功能描述
Auditoria de segurança para skills do OpenClaw. Verifica código malicioso, prompt injection, APIs perigosas e práticas inseguras. Protege contra ClawHavoc e...
安全使用建议
This skill appears coherent and low-risk as an instruction-only audit checklist. Before installing, verify the authoritative source (clawhub registry entry or the GitHub repo referenced in clawhub.json) and the publisher identity. Understand that the skill's instructions describe audits an agent would perform on other skill code — an agent will need permission to read the target skill files to run these checks, so only run it against code you permit the agent to inspect. If you expect a packaged executable, confirm the registry provides one (this bundle contains only documentation).
功能分析
Type: OpenClaw Skill Name: seguranca-auditoria Version: 1.0.0 The skill bundle contains metadata and documentation for a security auditing tool designed to identify vulnerabilities and malicious patterns in other OpenClaw skills. The files (SKILL.md, clawhub.json, and _meta.json) do not contain any executable code, suspicious network requests, or prompt injection attempts. The content is entirely consistent with its stated purpose of providing security analysis and protecting users from threats like 'ClawHavoc'.
能力评估
Purpose & Capability
The name/description (security audit for OpenClaw skills) matches the instructions (what to look for: exec/eval, suspicious domains, credential leakage, etc.). The skill does not request unrelated credentials or binaries. Minor metadata inconsistency: registry metadata at the top shows no homepage/source, while clawhub.json includes a GitHub homepage — worth verifying the authoritative source before installing.
Instruction Scope
SKILL.md consists of audit guidance (patterns to flag, report format, sample CLI usage). The instructions focus on examining target skill code/config for risky constructs and do not direct the agent to exfiltrate user data or access unrelated system secrets. Note: SKILL.md shows CLI usage (seguranca-auditoria auditar ...) despite there being no packaged binary or install spec in this bundle; that is typical for an instruction-only skill but means the instructions describe behavior rather than an included executable.
Install Mechanism
There is no install spec and no code files — lowest-risk form. The README suggests using 'clawhub install' to install the skill from the registry; that is consistent with instruction-only skills being provided by the platform rather than by this package.
Credentials
The skill does not request environment variables, credentials, or config paths. The audit guidance specifically flags access to sensitive paths (e.g., ~/.ssh, .env) in target skills rather than requesting them for itself.
Persistence & Privilege
always is false and the skill is user-invocable. Model invocation is allowed (platform default); nothing in the package demands permanent or elevated presence.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install seguranca-auditoria
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /seguranca-auditoria 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
- Lançamento inicial da skill seguranca-auditoria. - Audita skills do OpenClaw para identificar código malicioso, prompt injections, uso de APIs perigosas e práticas inseguras. - Classifica riscos em alto, médio e baixo, gerando relatórios detalhados em markdown ou HTML. - Recomendações de segurança incluídas para usuários. - Totalmente em português, voltada para a comunidade brasileira.
元数据
Slug seguranca-auditoria
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Seguranca Auditoria 是什么?

Auditoria de segurança para skills do OpenClaw. Verifica código malicioso, prompt injection, APIs perigosas e práticas inseguras. Protege contra ClawHavoc e... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 155 次。

如何安装 Seguranca Auditoria?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install seguranca-auditoria」即可一键安装,无需额外配置。

Seguranca Auditoria 是免费的吗?

是的,Seguranca Auditoria 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Seguranca Auditoria 支持哪些平台?

Seguranca Auditoria 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Seguranca Auditoria?

由 engsathiago(@engsathiago)开发并维护,当前版本 v1.0.0。

💬 留言讨论