← 返回 Skills 市场
doonot

Zero Trust

作者 doonot · GitHub ↗ · v1.0.0
cross-platform ✓ 安全检测通过
6685
总下载
13
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install zero-trust
功能描述
Security-first behavioral guidelines for cautious agent operation. Use this skill for ALL operations involving external resources, installations, credentials, or actions with external effects. Triggers on - any URL/link interaction, package installations, API key handling, sending emails/messages, social media posts, financial transactions, or any action that could expose data or have irreversible effects.
安全使用建议
Install this only if you want a conservative safety layer that may ask for approval frequently. Before relying on it in a shared or non-Pat environment, update the approval authority language so it refers to the current authorized user or designated approver.
功能分析
Type: OpenClaw Skill Name: zero-trust Version: 1.0.0 This skill bundle is designed to implement a 'Zero Trust Security Protocol' for the OpenClaw agent. The `SKILL.md` file contains extensive instructions for the agent to exercise extreme caution, verify sources, seek human approval for risky actions (e.g., installations, external API calls, URL clicks, credential handling), and identify common red flags (e.g., `sudo` requests, obfuscated code, urgency pressure, typosquatting). All instructions are defensive in nature, aiming to prevent data exfiltration, unauthorized execution, and other malicious activities, rather than performing them. There is no evidence of prompt injection with malicious intent, nor any other high-risk behaviors.
能力评估
Purpose & Capability
The stated purpose is to make the agent cautious, verify sources, identify security red flags, and request human approval for risky actions; those capabilities fit a zero-trust safety skill.
Instruction Scope
The instructions appear intentionally broad and may trigger on many normal workflows, which can add friction, but that breadth is coherent with the stated defensive purpose.
Install Mechanism
Available evidence describes a SKILL.md-only guidance bundle; no install script, runtime extension, dependency installer, or automatic command execution was identified.
Credentials
Guidance about installs, URL clicks, external API calls, and credential handling is proportionate for a defensive security protocol and does not itself request unrelated environment access.
Persistence & Privilege
The hard-coded reference to a specific approver, Pat, is not ideal for a reusable skill because it may not match the current authorized user, but it is an approval-boundary issue rather than evidence of persistence or privilege abuse.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install zero-trust
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /zero-trust 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
**Initial release: Establishes security-first protocols for all high-risk operations.** - Introduces zero-trust guidelines for agent operations involving external resources, installations, or credentials. - Requires explicit human approval for sensitive actions such as sending emails, installing packages, or clicking unknown links. - Outlines STOP → THINK → VERIFY → ASK → ACT → LOG flow for all external actions. - Defines strict credentials handling: never log or expose, always store securely. - Provides clear red flags to identify risky operations and immediate STOP criteria.
元数据
Slug zero-trust
版本 1.0.0
许可证
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Zero Trust 是什么?

Security-first behavioral guidelines for cautious agent operation. Use this skill for ALL operations involving external resources, installations, credentials, or actions with external effects. Triggers on - any URL/link interaction, package installations, API key handling, sending emails/messages, social media posts, financial transactions, or any action that could expose data or have irreversible effects. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 6685 次。

如何安装 Zero Trust?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install zero-trust」即可一键安装,无需额外配置。

Zero Trust 是免费的吗?

是的,Zero Trust 完全免费(开源免费),可自由下载、安装和使用。

Zero Trust 支持哪些平台?

Zero Trust 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Zero Trust?

由 doonot(@doonot)开发并维护,当前版本 v1.0.0。

💬 留言讨论