扫描报告
20 /100
openclaw-continuous-work
Continuous execution and optimization pipeline skill for OpenClaw. Runs naming audits, content/link audits, module validation, reference mapping, and encoding normalization on a target directory.
Legitimate OpenClaw continuous-work/optimization skill with minor documentation gap around subprocess invocation; no malicious patterns found.
可以安装
Add explicit declaration of subprocess usage in SKILL.md allowed-tools section. Otherwise this skill is safe to deploy.
安全发现 3 项
| 严重性 | 安全发现 | 位置 |
|---|---|---|
| 低危 | Subprocess shell execution not declared in allowed-tools 文档欺骗 | Scripts/RunOptimizationPipeline.py:19 |
| 低危 | Broad filesystem scope not declared 文档欺骗 | Scripts/NamingAudit.py:36 |
| 低危 | File-writing scripts not declared as requiring filesystem:WRITE 文档欺骗 | Scripts/NormalizeEncoding.py:25 |
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 命令执行 | NONE | WRITE | ✓ 一致 | Scripts/RunOptimizationPipeline.py:19 (import subprocess) and line 25 (subproces… |
| 文件系统 | NONE | READ | ✓ 一致 | NamingAudit.py:36 (root.rglob), ContentLinkAudit.py:52 (root.rglob) — reads file… |
| 文件系统 | NONE | WRITE | ✓ 一致 | NormalizeEncoding.py:25-29 (writes normalized bytes), ValidateModuleOrder.py:59 … |
目录结构
27 文件 · 36.0 KB · 1142 行 Python 8f · 704L
Markdown 15f · 381L
JSON 4f · 57L
├─
▾
References
│ ├─
AcceptanceTemplate.md
Markdown
│ ├─
ConflictReport.json
JSON
│ ├─
ConflictReport.md
Markdown
│ ├─
ContinuousExecutionDirective.md
Markdown
│ ├─
GeneralRules.md
Markdown
│ ├─
ModuleGraph.json
JSON
│ ├─
ModuleGraph.md
Markdown
│ ├─
ModuleOrder.json
JSON
│ ├─
ModuleOrderReport.json
JSON
│ ├─
ModuleOrderReport.md
Markdown
│ ├─
ModuleSystem.md
Markdown
│ ├─
ModuleTemplate.md
Markdown
│ ├─
OptimizationChecklist.md
Markdown
│ ├─
OptimizationDirective.md
Markdown
│ ├─
OptimizationRules.md
Markdown
│ ├─
QualityRubric.md
Markdown
│ ├─
ReferenceMap.md
Markdown
│ └─
ReportingTemplate.md
Markdown
├─
▾
Scripts
│ ├─
BuildModuleGraph.py
Python
│ ├─
BuildReferenceMap.py
Python
│ ├─
ContentLinkAudit.py
Python
│ ├─
DetectRuleConflicts.py
Python
│ ├─
NamingAudit.py
Python
│ ├─
NormalizeEncoding.py
Python
│ ├─
RunOptimizationPipeline.py
Python
│ └─
ValidateModuleOrder.py
Python
└─
SKILL.md
Markdown
依赖分析 1 项
| 包名 | 版本 | 来源 | 已知漏洞 | 备注 |
|---|---|---|---|---|
Python standard library only | N/A | stdlib | 否 | No third-party packages in requirements.txt or package.json — uses only json, subprocess, pathlib, re, collections, itertools, argparse, argparse |
安全亮点
✓ All scripts use only Python standard library — no third-party dependencies that could introduce supply-chain risk
✓ No network requests (no urllib, requests, httpx, socket to remote IPs)
✓ No credential or environment variable harvesting
✓ No base64/encoded payloads or obfuscation techniques
✓ No access to sensitive paths (~/.ssh, ~/.aws, .env, key stores)
✓ subprocess targets are hardcoded local script paths — no arbitrary command injection
✓ File writes are confined to text/UTF-8 normalization or auto-generated markdown/JSON reports
✓ Grep scan found zero matches for credential keywords, reverse shell patterns, or suspicious network patterns