← 返回 Skills 市场
Whitehat Security
作者
Vlad Ursul
· GitHub ↗
· v1.0.3
· MIT-0
146
总下载
0
收藏
0
当前安装
4
版本数
在 OpenClaw 中安装
/install whitehat-security
功能描述
WhiteHat Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with WhiteHat Security data.
安全使用建议
This skill appears internally consistent, but follow these precautions before installing or using it: 1) Verify you trust the @membranehq package on npm (check the publisher, npm page, and GitHub repo) before running a global install; consider using a container or isolated environment. 2) Use the Membrane-hosted OAuth flow rather than giving API keys directly (the skill recommends this). 3) Confirm what WhiteHat permissions the connector requests (prefer least privilege / read-only where possible). 4) If you have sensitive production data, review Membrane's privacy, data handling and retention policies and the connector's scope before connecting. 5) If anything in the published repository or package looks different from the SKILL.md guidance, pause and investigate—source is listed as unknown in the registry metadata.
功能分析
Type: OpenClaw Skill
Name: whitehat-security
Version: 1.0.3
The skill requires the installation of a global npm package (@membranehq/cli) and delegates all authentication and API interactions to the Membrane SaaS platform. While these actions are aligned with the stated purpose of integrating WhiteHat Security, the reliance on an external CLI for shell execution and a third-party service for credential management constitutes a high-privilege dependency. No evidence of intentional malice or data exfiltration was found in SKILL.md or _meta.json.
能力评估
Purpose & Capability
The name/description match the instructions: the SKILL.md directs the agent to use the Membrane CLI and the whitehat-security connector to manage WhiteHat Security data. Required capabilities (network access, a Membrane account) are coherent with the described integration.
Instruction Scope
Runtime instructions are limited to installing and using the Membrane CLI, logging in (browser-based or headless code flow), creating/listing connections, discovering and running actions. The instructions do not tell the agent to read arbitrary local files, export unrelated credentials, or call unexpected external endpoints.
Install Mechanism
There is no formal install spec in the registry metadata, but SKILL.md tells users to run `npm install -g @membranehq/cli@latest`. Installing a global npm package is expected for a CLI-based integration but carries the usual supply-chain risk—verify the package identity and source before installing and consider running it in a controlled environment.
Credentials
The skill declares no environment variables or credentials; it relies on Membrane to handle auth. This is proportionate: no unexplained SECRET/TOKEN requests or config paths are present.
Persistence & Privilege
The skill is not always-enabled and does not request persistent system-wide configuration or access to other skills' secrets. Agent autonomous invocation is allowed (platform default) but not combined with elevated privileges here.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install whitehat-security - 安装完成后,直接呼叫该 Skill 的名称或使用
/whitehat-security触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.3
Auto sync from membranedev/application-skills
v1.0.2
Revert refresh marker
v1.0.1
Refresh update marker
v1.0.0
Auto sync from membranedev/application-skills
元数据
常见问题
Whitehat Security 是什么?
WhiteHat Security integration. Manage data, records, and automate workflows. Use when the user wants to interact with WhiteHat Security data. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 146 次。
如何安装 Whitehat Security?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install whitehat-security」即可一键安装,无需额外配置。
Whitehat Security 是免费的吗?
是的,Whitehat Security 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Whitehat Security 支持哪些平台?
Whitehat Security 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Whitehat Security?
由 Vlad Ursul(@gora050)开发并维护,当前版本 v1.0.3。
推荐 Skills