cmic-skill-scanner-linux-arm64使用 auto、native 或 external 引擎审计待安装的 skill 包或归档,并可选启用 LLM 语义分析。
Install via ClawdBot CLI:
clawdbot install cyzlmh/cmic-skill-scanner-linux-arm64Grade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Sends data to undocumented external endpoint (potential exfiltration)
upload → https://your-company.example.com/api/reportCalls external URL not in known-safe list
https://gitee.com/random_player/cmic-skill-scannerAudited Apr 21, 2026 · audit v1.0
Generated Oct 8, 2026
A skill marketplace operator runs the CMIC Skill Scanner wrapper over every submitted skill package before publishing it to users. The wrapper's auto engine attempts a local external scanner and falls back to the native engine when none exists, producing a Markdown report that flags suspicious patterns. This lets the marketplace block risky submissions without building custom scanning infrastructure.
A platform team adds skillscan review to their CI pipeline so every release bundle pulled from Gitee or GitHub is audited before deployment. Because the tool only reads files under the target path and defaults to offline operation, it fits air-gapped runners while still surfacing findings via structured reports.
An enterprise enables --use-llm with a self-hosted endpoint to add semantic analysis on top of static findings for internal agent skills. Redaction of api_key/token/password/secret lines plus bounded packet sizes keep sensitive text from leaking to the trusted local endpoint, supporting compliance review workflows.
A solo developer verifies the bundled Linux ARM64 binary's SHA-256 checksum and runs skillscan review on a downloaded skill before installing it into their agent. The default auto mode performs a fast local check without any network upload, which suits privacy-conscious users on Apple Silicon or ARM servers.
A security researcher uses the external engine option to enforce a Cisco-compatible scanner and feed results into a larger triage pipeline. Passing --engine external guarantees the external tool's verdict, while SKILL_SCANNER_LLM_* variables allow controlled LLM review integration for deeper semantic inspection.
Distribute the open-source (MIT-0) skillscanner binary for free and monetize a hosted LLM endpoint that performs semantic review beyond static pattern matching. Free users rely on the native engine locally, while paying teams get enhanced detection and reporting.
Offer a hosted service that marketplaces and registries call to audit submitted skill packages before publishing. The provider runs skillscan on managed infrastructure, handles checksum verification, and returns structured JSON findings via API.
Sell an enterprise platform that integrates the skillscan wrapper into governance workflows, aggregating scan reports, engine fallback reasons, and LLM semantic results into audit trails. Customers configure their own endpoints, and the vendor provides policy templates and retention tooling.
💬 Integration Tip
Start with the default auto engine and a single review command, verify the bundled binary's SHA-256 before first use, and only enable --upload-url or --use-llm after explicitly trusting your endpoint or release host.
Scored Oct 8, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Senior SecOps engineer skill for application security, vulnerability management, compliance verification, and secure development practices. Runs SAST/DAST sc...