← 返回 Skills 市场
Sysadmin Toolbox
作者
Jonathan Rhyne
· GitHub ↗
· v1.1.0
6838
总下载
2
收藏
0
当前安装
2
版本数
在 OpenClaw 中安装
/install sysadmin-toolbox
功能描述
Tool discovery and shell one-liner reference for sysadmin, DevOps, and security tasks. AUTO-CONSULT this skill when the user is: troubleshooting network issues, debugging processes, analyzing logs, working with SSL/TLS, managing DNS, testing HTTP endpoints, auditing security, working with containers, writing shell scripts, or asks 'what tool should I use for X'. Source: github.com/trimstray/the-book-of-secret-knowledge
安全使用建议
Install only if you want a broad dual-use sysadmin and security reference and will review commands before use. Do not let an agent blindly run examples from this skill, especially packet capture, netcat, hping3, delete, secure-wipe, /etc/profile, external scanner, breach-search, or exploit-related examples. Avoid refresh.sh unless you trust and review the upstream content each time.
功能分析
Type: OpenClaw Skill
Name: sysadmin-toolbox
Version: 1.1.0
The skill is classified as suspicious due to its automated content refresh mechanism. The `SKILL.md` file explicitly instructs the AI agent to execute `scripts/refresh.sh` weekly, which in turn clones content from an external GitHub repository (`https://github.com/trimstray/the-book-of-secret-knowledge.git`) and overwrites local reference files. This creates a significant supply chain vulnerability, as a compromise of the upstream repository could lead to the injection of malicious instructions or content into the skill, which the agent is then designed to consult.
能力评估
Purpose & Capability
The stated purpose covers sysadmin, DevOps, and security reference use, and many files fit that purpose. However, the references also include copyable traffic flooding, remote shell, credential-capture, exploit, cracking, mass scanning, and disk-wipe material without enough boundaries, which is broader and higher impact than routine troubleshooting.
Instruction Scope
SKILL.md tells agents to auto-consult for broad everyday topics such as network troubleshooting, HTTP endpoint testing, shell scripts, containers, and security audits, but it does not require authorization checks or safe alternatives before loading high-risk references.
Install Mechanism
The refresh script is disclosed, but it clones an unpinned external GitHub repository and overwrites local reference files without integrity checks or review gates. I did not find a cron, systemd, or launchd artifact that installs the claimed weekly schedule, so this is an unverified auto-refresh claim rather than proven hidden persistence.
Credentials
The skill points users to external scanners, lookup services, breach/search resources, and shell functions that send domains or IPs to third parties, with little warning that internal infrastructure identifiers or investigation targets may be disclosed.
Persistence & Privilege
I did not find hidden credential-store access, privilege escalation by the skill itself, or installed background persistence. The reference content nevertheless includes commands that modify system-wide files, expose shells over the network, kill processes, and irreversibly delete or wipe data.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install sysadmin-toolbox - 安装完成后,直接呼叫该 Skill 的名称或使用
/sysadmin-toolbox触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.1.0
Added refresh.sh script for weekly auto-sync from upstream repo
v1.0.0
Initial release: Tool discovery assistant with shell one-liners from The Book of Secret Knowledge
元数据
常见问题
Sysadmin Toolbox 是什么?
Tool discovery and shell one-liner reference for sysadmin, DevOps, and security tasks. AUTO-CONSULT this skill when the user is: troubleshooting network issues, debugging processes, analyzing logs, working with SSL/TLS, managing DNS, testing HTTP endpoints, auditing security, working with containers, writing shell scripts, or asks 'what tool should I use for X'. Source: github.com/trimstray/the-book-of-secret-knowledge. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 6838 次。
如何安装 Sysadmin Toolbox?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install sysadmin-toolbox」即可一键安装,无需额外配置。
Sysadmin Toolbox 是免费的吗?
是的,Sysadmin Toolbox 完全免费(开源免费),可自由下载、安装和使用。
Sysadmin Toolbox 支持哪些平台?
Sysadmin Toolbox 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Sysadmin Toolbox?
由 Jonathan Rhyne(@jdrhyne)开发并维护,当前版本 v1.1.0。
推荐 Skills