references全方位安全审计技能。检查文件权限、环境变量、依赖漏洞、配置文件、网络端口、Git 安全、Shell 安全、macOS 安全、密钥检测等。支持 CLI 参数、JSON 输出、配置文件。当用户要求"安全检查"、"漏洞扫描"、"权限检查"、"安全审计"时使用此技能。
Install via ClawdBot CLI:
clawdbot install 13256659129/referencesGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Accesses sensitive credential files or environment variables
~/.ssh/id_rsaSends data to undocumented external endpoint (potential exfiltration)
send → https://...Hardcoded API key or token pattern found in skill definition
ghp_xxxxxxxx...Potentially destructive shell commands in tool definitions
eval(Generated Mar 28, 2026
Integrate this skill into CI/CD pipelines to automatically scan code repositories for vulnerabilities, such as hardcoded secrets, insecure dependencies, and misconfigured permissions. It helps teams enforce security policies before deployment, reducing risks in production environments.
Use the skill to conduct regular security audits for compliance with standards like GDPR or SOC 2, checking file permissions, environment variables, and network exposures. It generates detailed reports that can be shared with auditors to demonstrate due diligence and identify areas for improvement.
Maintainers can run this skill to scan their projects for supply chain vulnerabilities via npm audit, detect accidental secret leaks in Git history, and ensure secure configurations. This helps protect community contributions and maintain trust by proactively addressing security issues.
Deploy the skill on macOS and Linux systems within corporate networks to monitor for world-writable files, unauthorized network ports, and insecure shell configurations. It supports automated reporting to platforms like Feishu, enabling IT teams to respond quickly to potential threats.
Offer this skill as part of a cloud-based security service, where users pay a subscription fee for automated audits, real-time alerts, and detailed reports. Revenue is generated through tiered pricing based on scan frequency, number of assets, and advanced features like Feishu integration.
Provide professional services to customize the skill for specific client needs, such as adding custom check modules or integrating with internal tools. Revenue comes from one-time project fees and ongoing support contracts, targeting industries with strict security requirements.
Distribute the skill as an open-source tool with basic functionality free to use, while charging for premium features like advanced reporting, priority support, and automated Feishu notifications. Revenue is driven by upsells to enterprise users seeking enhanced capabilities.
💬 Integration Tip
Ensure npm and necessary CLI tools are installed in the environment, and configure Feishu webhooks or plugins beforehand to enable seamless report delivery for automated workflows.
Scored Jun 21, 2026
Accesses system directories or attempts privilege escalation
/var/log/Calls external URL not in known-safe list
https://...Uses known external API (expected, informational)
qyapi.weixin.qq.comAI Analysis
The skill is a legitimate security auditing tool designed to scan for vulnerabilities and misconfigurations. While it accesses sensitive files and environment variables, this is consistent with its stated purpose. The external API call to a Feishu webhook is documented and appears to be for reporting results, not for unauthorized data exfiltration.
Audited Apr 17, 2026 · audit v1.0
App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility o...
电脑运行效率助手核心技能 - 跨平台系统状态监控与安全优化。 支持 macOS/Windows/Linux,提供系统诊断、性能评估、智能清理、内存优化、定时巡检。
清空系统废纸篓/回收站(macOS/Linux/Windows)。触发词:「清空废纸篓」「清空垃圾桶」「empty trash」「清理废纸篓」。斜杠命令:/clean-rubbish。
通过SSH/SCP从远程Windows、macOS或Linux电脑复制文件到本地Mac,支持路径转换、中文编码和自动故障诊断。
Control and automate the Linux desktop GUI on X11. Use this skill to take screenshots, find and click UI elements, type text, send keyboard shortcuts, scroll...
This skill should be used when the user asks to "connect Apple Notes Snapshot to a host", "run notesctl mcp", "diagnose why Apple Notes Snapshot failed to at...