← 返回 Skills 市场
abdullah944

Threat Intelligence — التهديدات

作者 Kw.Hades- Creative Labs · GitHub ↗ · v1.0.1 · MIT-0
cross-platform ⚠ suspicious
233
总下载
0
收藏
1
当前安装
2
版本数
在 OpenClaw 中安装
/install threat-intel
功能描述
The only Arabic-first OSINT and threat intelligence skill. Monitor Arabic-language threat actor channels on Telegram, generate bilingual threat reports, sear...
安全使用建议
This skill appears to implement the OSINT tasks it claims, but there are two practical concerns to decide on before installing: 1) Required host tools: The bundled script calls external binaries (curl and torsocks). The registry says "no required binaries" — verify that your agent environment provides curl and (for dark-web queries) torsocks/Tor, or the darkweb command will fail. If you don't want the agent to run system commands, do not enable exec for this skill. 2) Network & Tor access: The skill will fetch arbitrary remote content (t.me pages, crt.sh JSON, and .onion search engines). If you allow autonomous invocation, the agent can reach those endpoints without further prompts. Consider running the skill only when manually invoked, or sandbox network/Tor access and review onion engine URLs before use. Additional recommendations: - Confirm legal/organizational policy for scraping Telegram and querying onion services in your jurisdiction. - If you want to proceed, run the bundled script locally first to inspect behavior and confirm which binaries are required. - If you do not want Tor or .onion lookups, avoid using the darkweb command or ensure torsocks is not available to the agent. Given the metadata/code mismatch (undeclared binary requirements) and the fact the skill makes network/Tor calls when executed, treat it as suspicious until you validate the runtime environment and trust boundaries.
功能分析
Type: OpenClaw Skill Name: threat-intel Version: 1.0.1 The skill is a legitimate OSINT tool for monitoring Arabic-language threat intelligence. It uses scripts/run.py to fetch public data from Telegram, crt.sh, and dark web search engines via Tor. The code uses subprocess.run safely with argument lists to prevent shell injection, and the SKILL.md instructions are consistent with the stated purpose of passive reconnaissance and threat reporting without any evidence of malicious intent or data exfiltration.
能力评估
Purpose & Capability
The skill name/description (Arabic-first OSINT: Telegram scraping, CT logs, Tor dark-web search) matches what the code does. However the package metadata declares no required binaries while the included script clearly invokes external programs (curl and torsocks). That mismatch is unexpected and should be clarified.
Instruction Scope
SKILL.md and scripts/run.py stay within passive OSINT: fetching public Telegram pages, querying crt.sh, and using Tor to query .onion search engines. The instructions do not ask the agent to read arbitrary local files or environment secrets. They do require the agent to run networked commands (curl/torsocks), which is consistent with the stated purpose but is an execution privilege to be aware of.
Install Mechanism
No install spec or external downloads are used; this is instruction-only plus a bundled Python script. Nothing in the manifest writes arbitrary remote code to disk at install time.
Credentials
The skill requests no environment variables or credentials, which matches the code (it uses public endpoints). There are no hidden secret accesses in the files. The only external dependencies are binaries (curl, optionally torsocks) which are not declared in the registry metadata.
Persistence & Privilege
always is false and the skill does not request persistent/privileged platform presence. It uses subprocess execution at runtime (normal for this kind of tool). Autonomous invocation is enabled by default (normal) — combine that with the exec capability only if you trust the skill.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install threat-intel
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /threat-intel 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.1
- Added LICENSE file to the project. - No feature or functionality changes; legal licensing information included.
v1.0.0
1.0.0 — 2026-03-18 — initial release
元数据
Slug threat-intel
版本 1.0.1
许可证 MIT-0
累计安装 1
当前安装数 1
历史版本数 2
常见问题

Threat Intelligence — التهديدات 是什么?

The only Arabic-first OSINT and threat intelligence skill. Monitor Arabic-language threat actor channels on Telegram, generate bilingual threat reports, sear... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 233 次。

如何安装 Threat Intelligence — التهديدات?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install threat-intel」即可一键安装,无需额外配置。

Threat Intelligence — التهديدات 是免费的吗?

是的,Threat Intelligence — التهديدات 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Threat Intelligence — التهديدات 支持哪些平台?

Threat Intelligence — التهديدات 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Threat Intelligence — التهديدات?

由 Kw.Hades- Creative Labs(@abdullah944)开发并维护,当前版本 v1.0.1。

💬 留言讨论