Trusted — Risk Score 5/100
Last scan:1 day ago Rescan
5 /100
one-person-company-os
AI-era solo company operating system with round-based execution and stage management
This is a legitimate business-process automation skill for managing solo company operations. All code functionality is properly declared in SKILL.md with no hidden malicious behavior detected.
Skill Nameone-person-company-os
Duration73.5s
Enginepi
Safe to install
This skill is safe to use. No security concerns were identified. All subprocess usage is for legitimate purposes (Python version probing and package installation) and is fully documented.
ResourceDeclaredInferredStatusEvidence
Filesystem WRITE WRITE ✓ Aligned SKILL.md declares workspace creation; scripts write to user-specified directorie…
Shell WRITE WRITE ✓ Aligned ensure_python_runtime.py:200 runs package managers (apt-get, brew, etc.) with su…
Network NONE NONE No external HTTP requests; URLs in code are XML schema namespaces for DOCX gener…
Environment READ READ ✓ Aligned probe_python() reads sys.executable and version info only
Skill Invoke READ READ ✓ Aligned Skill invokes other local scripts as documented in SKILL.md
Clipboard NONE NONE No clipboard access detected
Browser NONE NONE No browser automation detected
Database NONE NONE No database access detected
29 findings
🔗
Medium External URL 外部 URL
https://clawhub.ai/api/v1/download?slug=one-person-company-os&version=0.5.7
PUBLISHING.md:98
🔗
Medium External URL 外部 URL
https://clawhub.ai/skills/one-person-company-os
release/platform-check-2026-04-02.md:34
🔗
Medium External URL 外部 URL
https://clawhub.ai/living-hi/one-person-company-os
release/platform-check-2026-04-02.md:35
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/package/2006/content-types
scripts/common.py:342
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/package/2006/relationships
scripts/common.py:355
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/officeDocument/2006/relationships/officeDocument
scripts/common.py:356
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/package/2006/relationships/metadata/core-properties
scripts/common.py:357
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/officeDocument/2006/relationships/extended-properties
scripts/common.py:358
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/officeDocument/2006/relationships/styles
scripts/common.py:366
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/wordprocessingml/2006/main
scripts/common.py:373
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/officeDocument/2006/extended-properties
scripts/common.py:417
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/officeDocument/2006/docPropsVTypes
scripts/common.py:418
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/package/2006/metadata/core-properties
scripts/common.py:428
🔗
Medium External URL 外部 URL
http://purl.org/dc/elements/1.1/
scripts/common.py:429
🔗
Medium External URL 外部 URL
http://purl.org/dc/terms/
scripts/common.py:430
🔗
Medium External URL 外部 URL
http://purl.org/dc/dcmitype/
scripts/common.py:431
🔗
Medium External URL 外部 URL
http://www.w3.org/2001/XMLSchema-instance
scripts/common.py:432
🔗
Medium External URL 外部 URL
http://schemas.microsoft.com/office/word/2010/wordprocessingCanvas\
scripts/common.py:480
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/markup-compatibility/2006\
scripts/common.py:481
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/officeDocument/2006/relationships\
scripts/common.py:483
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/officeDocument/2006/math\
scripts/common.py:484
🔗
Medium External URL 外部 URL
http://schemas.microsoft.com/office/word/2010/wordprocessingDrawing\
scripts/common.py:486
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/drawingml/2006/wordprocessingDrawing\
scripts/common.py:487
🔗
Medium External URL 外部 URL
http://schemas.openxmlformats.org/wordprocessingml/2006/main\
scripts/common.py:489
🔗
Medium External URL 外部 URL
http://schemas.microsoft.com/office/word/2010/wordml\
scripts/common.py:490
🔗
Medium External URL 外部 URL
http://schemas.microsoft.com/office/word/2010/wordprocessingGroup\
scripts/common.py:491
🔗
Medium External URL 外部 URL
http://schemas.microsoft.com/office/word/2010/wordprocessingInk\
scripts/common.py:492
🔗
Medium External URL 外部 URL
http://schemas.microsoft.com/office/2006/wordml\
scripts/common.py:493
🔗
Medium External URL 外部 URL
http://schemas.microsoft.com/office/word/2010/wordprocessingShape\
scripts/common.py:494

File Tree

107 files · 390.4 KB · 10310 lines
Python 13f · 5331L Markdown 75f · 4402L JSON 14f · 573L YAML 1f · 4L
├─ 📁 agents
│ ├─ 📁 roles
│ │ ├─ 📋 control-tower.json JSON 42L · 1.1 KB
│ │ ├─ 📋 customer-success.json JSON 38L · 856 B
│ │ ├─ 📋 data-analyst.json JSON 36L · 772 B
│ │ ├─ 📋 designer.json JSON 36L · 838 B
│ │ ├─ 📋 devops-sre.json JSON 37L · 839 B
│ │ ├─ 📋 engineer-tech-lead.json JSON 42L · 1017 B
│ │ ├─ 📋 finance.json JSON 34L · 733 B
│ │ ├─ 📋 founder-ceo.json JSON 40L · 945 B
│ │ ├─ 📋 growth-sales.json JSON 40L · 930 B
│ │ ├─ 📋 legal-compliance.json JSON 35L · 801 B
│ │ ├─ 📋 product-strategist.json JSON 41L · 968 B
│ │ └─ 📋 qa-reliability.json JSON 37L · 850 B
│ └─ 📋 openai.yaml YAML 4L · 700 B
├─ 📁 assets
│ ├─ 📁 examples
│ │ └─ 📁 zh-round-mode
│ │ ├─ 📝 00-公司总览.md Markdown 17L · 401 B
│ │ ├─ 📝 01-当前回合.md Markdown 14L · 496 B
│ │ ├─ 📝 02-校准记录.md Markdown 8L · 342 B
│ │ └─ 📝 03-阶段切换记录.md Markdown 6L · 298 B
│ └─ 📁 templates
│ ├─ 📝 artifact-delivery-index-template.md Markdown 44L · 1.2 KB
│ ├─ 📝 artifact-deployment-template.md Markdown 29L · 509 B
│ ├─ 📝 artifact-docx-ready-template.md Markdown 87L · 1.6 KB
│ ├─ 📝 artifact-growth-template.md Markdown 28L · 486 B
│ ├─ 📝 artifact-internal-draft-template.md Markdown 42L · 657 B
│ ├─ 📝 artifact-launch-feedback-template.md Markdown 28L · 527 B
│ ├─ 📝 artifact-non-software-delivery-template.md Markdown 46L · 899 B
│ ├─ 📝 artifact-output-guide-template.md Markdown 52L · 1.5 KB
│ ├─ 📝 artifact-production-template.md Markdown 39L · 698 B
│ ├─ 📝 artifact-quality-template.md Markdown 36L · 668 B
│ ├─ 📝 artifact-software-delivery-template.md Markdown 38L · 791 B
│ ├─ 📝 artifact-standard-spec-template.md Markdown 44L · 626 B
│ ├─ 📝 artifact-validate-evidence-template.md Markdown 27L · 491 B
│ ├─ 📝 bootstrap-flow-template.md Markdown 8L · 442 B
│ ├─ 📝 calibration-flow-template.md Markdown 8L · 202 B
│ ├─ 📝 calibration-rules-template.md Markdown 22L · 436 B
│ ├─ 📝 company-overview-template.md Markdown 27L · 804 B
│ ├─ 📝 current-round-template.md Markdown 16L · 470 B
│ ├─ 📝 current-stage-deliverable-template.md Markdown 34L · 1.2 KB
│ ├─ 📝 current-stage-template.md Markdown 18L · 501 B
│ ├─ 📝 execution-rules-template.md Markdown 29L · 656 B
│ ├─ 📝 organization-template.md Markdown 23L · 315 B
│ ├─ 📝 product-positioning-template.md Markdown 18L · 417 B
│ ├─ 📝 reminder-rules-template.md Markdown 6L · 238 B
│ ├─ 📝 role-brief-template.md Markdown 29L · 290 B
│ ├─ 📝 role-index-template.md Markdown 14L · 321 B
│ ├─ 📝 round-flow-template.md Markdown 8L · 205 B
│ ├─ 📝 scheduler-spec-template.md Markdown 11L · 348 B
│ ├─ 📝 stage-flow-template.md Markdown 8L · 238 B
│ └─ 📝 stage-role-deliverable-matrix-template.md Markdown 75L · 1.0 KB
├─ 📁 orchestration
│ ├─ 📋 handoff-schema.json JSON 34L · 791 B
│ └─ 📋 stage-defaults.json JSON 81L · 1.5 KB
├─ 📁 references
│ ├─ 📝 bootstrap-playbook.md Markdown 27L · 608 B
│ ├─ 📝 calibration-playbook.md Markdown 27L · 478 B
│ ├─ 📝 chinese-workspace-conventions.md Markdown 27L · 541 B
│ ├─ 📝 openclaw-runtime.md Markdown 69L · 1.7 KB
│ ├─ 📝 round-execution-playbook.md Markdown 21L · 502 B
│ └─ 📝 stage-transition-playbook.md Markdown 23L · 387 B
├─ 📁 release
│ ├─ 📁 assets
│ │ ├─ 📦 company-overview-preview.svg 1.1 KB
│ │ ├─ 📦 repo-social-card.svg 1.3 KB
│ │ ├─ 📦 round-preview.svg 1.1 KB
│ │ └─ 📦 workspace-preview.svg 1.9 KB
│ ├─ 📝 clawhub-listing.md Markdown 101L · 5.5 KB
│ ├─ 📝 first-run-ux-test-2026-04-02.md Markdown 65L · 2.7 KB
│ ├─ 📝 github-announcement.md Markdown 22L · 930 B
│ ├─ 📝 media-kit.md Markdown 29L · 822 B
│ ├─ 📝 platform-check-2026-04-02.md Markdown 61L · 1.7 KB
│ ├─ 📝 README.md Markdown 103L · 3.8 KB
│ ├─ 📝 README.zh-CN.md Markdown 100L · 3.4 KB
│ ├─ 📝 release-checklist.md Markdown 37L · 1.7 KB
│ ├─ 📝 sample-outputs.md Markdown 41L · 921 B
│ ├─ 📝 social-posts.md Markdown 42L · 1023 B
│ ├─ 📝 taglines.md Markdown 7L · 342 B
│ ├─ 📝 v0.3.0-github-release.md Markdown 106L · 2.4 KB
│ ├─ 📝 v0.3.3-github-release.md Markdown 78L · 1.9 KB
│ ├─ 📝 v0.4.0-github-release.md Markdown 81L · 2.0 KB
│ ├─ 📝 v0.5.0-github-release.md Markdown 60L · 1.7 KB
│ ├─ 📝 v0.5.1-github-release.md Markdown 46L · 1.4 KB
│ ├─ 📝 v0.5.2-github-release.md Markdown 13L · 509 B
│ ├─ 📝 v0.5.3-github-release.md Markdown 14L · 690 B
│ ├─ 📝 v0.5.4-github-release.md Markdown 13L · 451 B
│ ├─ 📝 v0.5.5-github-release.md Markdown 12L · 374 B
│ ├─ 📝 v0.5.6-github-release.md Markdown 21L · 952 B
│ └─ 📝 v0.5.7-github-release.md Markdown 22L · 889 B
├─ 📁 scripts
│ ├─ 🐍 build_agent_brief.py Python 306L · 14.9 KB
│ ├─ 🐍 calibrate_round.py Python 122L · 5.8 KB
│ ├─ 🐍 checkpoint_save.py Python 106L · 5.9 KB
│ ├─ 🐍 common.py Python 1583L · 74.5 KB
│ ├─ 🐍 ensure_python_runtime.py Python 315L · 16.2 KB
│ ├─ 🐍 generate_artifact_document.py Python 233L · 14.0 KB
│ ├─ 🐍 init_company.py Python 166L · 8.6 KB
│ ├─ 🐍 localization.py Python 1461L · 47.1 KB
│ ├─ 🐍 preflight_check.py Python 87L · 5.8 KB
│ ├─ 🐍 start_round.py Python 138L · 6.1 KB
│ ├─ 🐍 transition_stage.py Python 172L · 8.6 KB
│ ├─ 🐍 update_round.py Python 132L · 6.2 KB
│ └─ 🐍 validate_release.py Python 510L · 19.4 KB
├─ 📝 AGENTS.md Markdown 74L · 2.0 KB
├─ 📝 CHANGELOG.md Markdown 121L · 8.5 KB
├─ 📝 CLAUDE.md Markdown 56L · 1.1 KB
├─ 📝 CONTRIBUTING.md Markdown 26L · 994 B
├─ 📝 GUIDE.md Markdown 102L · 2.9 KB
├─ 📝 GUIDE.zh-CN.md Markdown 109L · 3.4 KB
├─ 📝 PUBLISHING.md Markdown 111L · 4.2 KB
├─ 📝 README.md Markdown 365L · 12.1 KB
├─ 📝 README.zh-CN.md Markdown 359L · 11.4 KB
├─ 📝 RELEASE-NOTES.md Markdown 260L · 12.4 KB
├─ 📝 SAMPLE-OUTPUTS.md Markdown 86L · 2.2 KB
├─ 📝 SECURITY.md Markdown 17L · 777 B
└─ 📝 SKILL.md Markdown 509L · 16.5 KB

Security Positives

✓ SKILL.md is comprehensive (509 lines) and declares all scripts, execution modes, and capabilities
✓ All subprocess calls are legitimate: Python version probing, package installation (brew/apt-get/winget), and test execution
✓ No credential harvesting or sensitive file access (~/.ssh, ~/.aws, .env, api_key, password, token)
✓ No external C2 communication or data exfiltration
✓ No base64-encoded execution, eval(), exec(), or __import__() abuse
✓ No hidden functionality in HTML comments or obfuscated code
✓ No remote script execution (curl|bash, wget|sh)
✓ No supply chain risks: no unpinned dependencies, no third-party packages required
✓ Clear separation between script execution (Mode A), manual persistence (Mode B), and chat-only (Mode C)
✓ Confirmation boundaries documented for high-risk actions