agent-security-skill-scanner-giteeAI Agent 安全扫描器 - 通用恶意代码检测 + 多语言支持 + CLI 工具
Install via ClawdBot CLI:
clawdbot install caidongyun/agent-security-skill-scanner-giteeGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
webhook → https://example.com/alertContains telemetry, tracking, or analytics calls not mentioned in documentation
telemetry.*sendPotentially destructive shell commands in tool definitions
eval(Generated May 9, 2026
在持续集成/部署流水线中集成 asc-scan 工具,自动扫描代码仓库中的恶意代码和漏洞。适用于 DevSecOps 流程,确保每次代码提交都经过安全检测,防止恶意代码进入生产环境。
在 AI Agent 技能市场或平台中,使用本扫描器对第三方提交的技能包(Skill)进行自动化安全审核。检测恶意代码、敏感信息泄露等风险,保障平台生态安全。
定期扫描企业内部服务器上的脚本文件(Python、Shell 等)和配置文件,识别潜在的恶意代码或异常行为。适用于安全团队进行内部威胁检测和合规审计。
在引入开源代码或接受外部贡献时,使用 asc-scan 快速扫描可疑文件。帮助开源维护者或企业法务团队评估第三方代码的安全性,降低供应链攻击风险。
在发生安全事件后,使用本工具快速扫描受影响主机上的脚本文件,定位恶意载荷或后门。支持 JSON 输出,便于与其他安全工具集成。
向企业提供 asc-scan 命令行工具的付费授权,包括高级规则库更新、优先技术支持等增值服务。可选择按年订阅,适合需要持续安全保障的组织。
将扫描能力通过 API 或 SDK 集成到已有的安全运营中心(SOC)、SIEM 或 DevOps 平台中,按扫描次数或 API 调用量收费。
为 AI 技能市场提供第三方安全审核服务,对提交的技能包进行人工+自动双重检测,出具审核报告,按技能数量或审核复杂程度收费。
💬 Integration Tip
可通过命令行直接调用,或集成到 CI/CD 脚本中。建议在隔离环境中先测试 LLM 分析功能,并配置飞书或邮件告警。
Scored May 9, 2026
Accesses system directories or attempts privilege escalation
/etc/cronCalls external URL not in known-safe list
https://gitee.com/caidongyun/agent-security-skill-scannerAI Analysis
The skill exhibits multiple concerning behaviors including credential file access (~/.ssh/id_rsa), undocumented external data transmission to unknown endpoints, and telemetry injection not disclosed in documentation. While it appears to be a legitimate security scanner, these hidden behaviors create significant risk if the tool itself is compromised or misconfigured.
Audited Apr 17, 2026 · audit v1.0
Meta-skill for AI agent self-improvement. Analyzes runtime logs to detect error patterns, regressions, and inefficiencies, then generates structured improvem...
Stop waiting for prompts. Keep working.
Turn OpenClaw into a learning-loop agent with seeded workspace rules, skill promotion, reflective memory, and proactive maintenance.
Meta-agent skill for orchestrating complex tasks through autonomous sub-agents. Decomposes macro tasks into subtasks, spawns specialized sub-agents with dynamically generated SKILL.md files, coordinates file-based communication, consolidates results, and dissolves agents upon completion. MANDATORY TRIGGERS: orchestrate, multi-agent, decompose task, spawn agents, sub-agents, parallel agents, agent coordination, task breakdown, meta-agent, agent factory, delegate tasks
Complete toolkit for creating autonomous AI agents and managing Discord channels for OpenClaw. Use when setting up multi-agent systems, creating new agents, or managing Discord channel organization.
Billions decentralized identity for agents. Link agents to human identities using Billions ERC-8004 and Attestation Registries. Verify and generate authentic...