← 返回 Skills 市场
948
总下载
0
收藏
1
当前安装
1
版本数
在 OpenClaw 中安装
/install volcengine-security-kms
功能描述
Key lifecycle management with Volcengine KMS. Use when users need key creation, rotation policies, encryption/decryption workflows, or key permission troubleshooting.
安全使用建议
This skill claims to manage Volcengine KMS but is missing essential operational details (authentication and concrete API/CLI steps). Before installing or using it:
- Treat it as advisory documentation rather than an actionable integration until the author documents auth and invocation details.
- Ask the publisher to declare required credentials (e.g., VOLCENGINE_ACCESS_KEY_ID, VOLCENGINE_SECRET_ACCESS_KEY, REGION/ENDPOINT) and the minimum IAM permissions needed for each operation.
- Do not expose high-privilege or long-lived keys to the agent; prefer least-privilege scoped credentials or ephemeral roles.
- If you intend to let the agent perform real KMS operations, test in a non-production account with narrowly scoped permissions and audit logs enabled.
- If the skill will run autonomously with access to credentials, require explicit confirmation and review of the credential scope first.
If the author clarifies that the skill is purely a checklist/documentation (no runtime API calls), it would be lower risk; if it is intended to perform real KMS operations, the current lack of declared credentials/config is a red flag and should be corrected.
功能分析
Type: OpenClaw Skill
Name: volcengine-security-kms
Version: 1.0.0
The skill bundle defines an OpenClaw agent skill for Volcengine KMS key management. All files, including `SKILL.md` (which contains instructions for the AI agent), are aligned with the stated purpose. There is no evidence of malicious prompt injection, unauthorized data access, external communication, or code execution. The `SKILL.md` even includes 'Safety Rules' promoting secure handling of secrets and permissions, indicating a focus on secure operation rather than malicious intent.
能力评估
Purpose & Capability
The skill's name and description state it manages Volcengine KMS (create/rotate/encrypt/decrypt/etc.), but the package declares no required environment variables, no credentials, and no config paths. Real KMS operations require cloud credentials (API key/secret, role, or SDK config) and often a region/endpoint; their absence is a mismatch between stated purpose and declared requirements.
Instruction Scope
SKILL.md contains high-level steps (confirm key purpose, create/select key, run encrypt/decrypt/sign, return metadata) and sensible safety rules, but it is purely advisory and lacks concrete runtime instructions: no API endpoints, no authentication flow, no SDK/CLI commands. That vagueness could lead an agent to attempt to use whatever credentials are available in the environment without explicit guidance.
Install Mechanism
This is an instruction-only skill with no install spec and no code files. That keeps the on-disk footprint minimal and is consistent with a documentation-style skill.
Credentials
No environment variables or primary credential are declared even though interacting with Volcengine KMS would normally require credentials (access key, secret, possibly region/endpoint). This omission is disproportionate and ambiguous: either the skill is only documentation (then it should say so), or it expects the agent to use existing credentials — which should be explicitly declared and scoped.
Persistence & Privilege
The skill does not request always:true and is user-invocable; it does not demand elevated persistence. Autonomous invocation is allowed (platform default) but is not combined here with broad declared credentials.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install volcengine-security-kms - 安装完成后,直接呼叫该 Skill 的名称或使用
/volcengine-security-kms触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial ClawHub publish for Volcengine skills with agents metadata.
元数据
常见问题
Volcengine Security Kms 是什么?
Key lifecycle management with Volcengine KMS. Use when users need key creation, rotation policies, encryption/decryption workflows, or key permission troubleshooting. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 948 次。
如何安装 Volcengine Security Kms?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install volcengine-security-kms」即可一键安装,无需额外配置。
Volcengine Security Kms 是免费的吗?
是的,Volcengine Security Kms 完全免费(开源免费),可自由下载、安装和使用。
Volcengine Security Kms 支持哪些平台?
Volcengine Security Kms 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Volcengine Security Kms?
由 cinience(@cinience)开发并维护,当前版本 v1.0.0。
推荐 Skills