← 返回 Skills 市场
1231qaz2wsx

Skill Safe Install (L0 Strict)

作者 1231qaz2wsx · GitHub ↗ · v1.0.1 · MIT-0
cross-platform ✓ 安全检测通过
265
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install skill-safe-install-l0-strict
功能描述
Strict secure-install workflow for ClawHub/OpenClaw skills. Use when asked to install a skill safely, inspect skill permissions, review third-party skill ris...
安全使用建议
This skill appears to do what it says: run clawhub commands, sandbox an install, rate risk, and require explicit consent before writing trust. Before using it: (1) ensure you trust the clawhub CLI on your system (the skill invokes it), (2) be aware it will read your OpenClaw config (~/.openclaw/openclaw.json) even though the registry metadata didn't declare a config path, (3) verify the skill will not perform writes without the explicit ‘yes/install’ consent at Step 4, and (4) if you rely on automated installs, expect this skill to pause for manual confirmation by design. If you want the skill to be fully auditable, test it in a safe environment first and confirm it adheres to the Step 0–6 outputs before using it in production.
功能分析
Type: OpenClaw Skill Name: skill-safe-install-l0-strict Version: 1.0.1 The skill is a security-focused utility designed to enforce a strict, multi-step workflow for auditing and safely installing other OpenClaw skills. It mandates risk assessments, sandboxing in isolated directories, and explicit user consent gates before performing installations or modifying configuration files (SKILL.md, clawhub.yaml). No malicious intent, data exfiltration, or unauthorized execution patterns were found.
能力评估
Purpose & Capability
Name, description, and instructions all focus on a secure install workflow. The suggested CLI commands (clawhub search/inspect/install) and sandbox steps are appropriate and proportional to the stated goal.
Instruction Scope
The SKILL.md directs the agent to read the platform config path (~/.openclaw/openclaw.json) to check installed skills and trust state; that behavior is reasonable for a safe-installer skill but the skill's declared metadata lists no required config paths. This is a minor mismatch worth documenting: the instructions do access a user config file even though no config path was declared in the registry metadata.
Install Mechanism
No install spec or code is provided — instruction-only skills have the lowest install risk. There are no download URLs, archives, or external packages being installed by the skill itself.
Credentials
The skill requests no environment variables or credentials. All actions described (inspecting, sandboxing, prompting) are consistent with that. It does not request unrelated secrets or broad access.
Persistence & Privilege
always is false and the workflow explicitly forbids writing persistent config without explicit consent. The skill's guidance includes backup/confirmation steps for any optional trust persistence, which is proportionate.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install skill-safe-install-l0-strict
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /skill-safe-install-l0-strict 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.1
Skill-safe-install-l0-strict v1.0.1 - Introduces a strict and auditable workflow for secure installation of ClawHub/OpenClaw skills. - Enforces mandatory risk review, sandbox verification, and explicit user consent before any install or config modification. - Blocks all author-based trust shortcuts and implicit config changes; requires step-by-step confirmation. - Provides clear step-by-step output and refusal conditions to maximize install security and reduce risk.
元数据
Slug skill-safe-install-l0-strict
版本 1.0.1
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Skill Safe Install (L0 Strict) 是什么?

Strict secure-install workflow for ClawHub/OpenClaw skills. Use when asked to install a skill safely, inspect skill permissions, review third-party skill ris... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 265 次。

如何安装 Skill Safe Install (L0 Strict)?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install skill-safe-install-l0-strict」即可一键安装,无需额外配置。

Skill Safe Install (L0 Strict) 是免费的吗?

是的,Skill Safe Install (L0 Strict) 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Skill Safe Install (L0 Strict) 支持哪些平台?

Skill Safe Install (L0 Strict) 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Skill Safe Install (L0 Strict)?

由 1231qaz2wsx(@1231qaz2wsx)开发并维护,当前版本 v1.0.1。

💬 留言讨论