← 返回 Skills 市场
jdrhyne

Sysadmin Toolbox

作者 Jonathan Rhyne · GitHub ↗ · v1.1.0
cross-platform ⚠ suspicious
6389
总下载
2
收藏
49
当前安装
2
版本数
在 OpenClaw 中安装
/install sysadmin-toolbox
功能描述
Tool discovery and shell one-liner reference for sysadmin, DevOps, and security tasks. AUTO-CONSULT this skill when the user is: troubleshooting network issues, debugging processes, analyzing logs, working with SSL/TLS, managing DNS, testing HTTP endpoints, auditing security, working with containers, writing shell scripts, or asks 'what tool should I use for X'. Source: github.com/trimstray/the-book-of-secret-knowledge
安全使用建议
Install only if you want a broad dual-use sysadmin and security reference and are comfortable reviewing commands before use. Do not let an agent copy commands from it blindly, especially packet capture, netcat, hping3, delete, secure-wipe, /etc/profile, or external web-scanner examples. Avoid auto-refresh unless you trust and review the upstream content each time.
功能分析
Type: OpenClaw Skill Name: sysadmin-toolbox Version: 1.1.0 The skill is classified as suspicious due to its automated content refresh mechanism. The `SKILL.md` file explicitly instructs the AI agent to execute `scripts/refresh.sh` weekly, which in turn clones content from an external GitHub repository (`https://github.com/trimstray/the-book-of-secret-knowledge.git`) and overwrites local reference files. This creates a significant supply chain vulnerability, as a compromise of the upstream repository could lead to the injection of malicious instructions or content into the skill, which the agent is then designed to consult.
能力评估
Purpose & Capability
The stated sysadmin, DevOps, and security-reference purpose mostly matches the files, but the references include raw remote shell examples, credential-capture packet filters, traffic flooding, whole-disk wiping, and exploit/backdoor resources without clear authorization or safety framing.
Instruction Scope
SKILL.md asks agents to auto-consult for broad everyday topics such as network troubleshooting, logs, shell scripts, security audits, and containers, which can surface high-risk command snippets in contexts that are not explicitly authorized security work.
Install Mechanism
The refresh script is disclosed and purpose-aligned, but it clones an external GitHub repository and overwrites local reference files without pinning, integrity verification, or review gates. I found no cron or systemd artifact that actually schedules it weekly, so the automatic-refresh claim is under-specified rather than proven hidden execution.
Credentials
Several references send domains, IPs, URLs, files, or investigation targets to third-party web services and APIs, which is coherent for a toolbox but under-disclosed for internal or sensitive infrastructure data.
Persistence & Privilege
I did not find hidden persistence, credential-store access, or privilege escalation by the skill itself. However, the reference content includes system-wide and persistence-like commands such as modifying /etc/profile, netcat shell listeners, destructive deletes, and disk-wipe examples.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install sysadmin-toolbox
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /sysadmin-toolbox 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.1.0
Added refresh.sh script for weekly auto-sync from upstream repo
v1.0.0
Initial release: Tool discovery assistant with shell one-liners from The Book of Secret Knowledge
元数据
Slug sysadmin-toolbox
版本 1.1.0
许可证
累计安装 241
当前安装数 49
历史版本数 2
常见问题

Sysadmin Toolbox 是什么?

Tool discovery and shell one-liner reference for sysadmin, DevOps, and security tasks. AUTO-CONSULT this skill when the user is: troubleshooting network issues, debugging processes, analyzing logs, working with SSL/TLS, managing DNS, testing HTTP endpoints, auditing security, working with containers, writing shell scripts, or asks 'what tool should I use for X'. Source: github.com/trimstray/the-book-of-secret-knowledge. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 6389 次。

如何安装 Sysadmin Toolbox?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install sysadmin-toolbox」即可一键安装,无需额外配置。

Sysadmin Toolbox 是免费的吗?

是的,Sysadmin Toolbox 完全免费(开源免费),可自由下载、安装和使用。

Sysadmin Toolbox 支持哪些平台?

Sysadmin Toolbox 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Sysadmin Toolbox?

由 Jonathan Rhyne(@jdrhyne)开发并维护,当前版本 v1.1.0。

💬 留言讨论