Trusted — Risk Score 5/100
Last scan:19 hr ago Rescan
5 /100
lua-scripter (declared in SKILL.md) / self-improving-agent (in _meta.json)
Lua development assistant with self-improvement hooks for learning capture
Legitimate Lua development assistant skill with self-improvement hooks. All scripts are readable, no malicious patterns detected, no network/credential access.
Skill Namelua-scripter (declared in SKILL.md) / self-improving-agent (in _meta.json)
Duration33.8s
Enginepi
Safe to install
This skill is safe to use. The minor documentation mismatch (SKILL.md name vs _meta.json name) is non-security-relevant.
ResourceDeclaredInferredStatusEvidence
Filesystem NONE WRITE ✓ Aligned extract-skill.sh creates ./skills/<name>/SKILL.md with path validation
Shell NONE READ ✓ Aligned Scripts use CLAUDE_TOOL_OUTPUT env var for error detection
Environment READ READ ✓ Aligned error-detector.sh reads CLAUDE_TOOL_OUTPUT (documented hook behavior)
Network NONE NONE No network calls in any script

File Tree

16 files · 36.8 KB · 1616 lines
Markdown 10f · 1197L Shell 3f · 296L TypeScript 1f · 62L JavaScript 1f · 56L JSON 1f · 5L
├─ 📁 .learnings
│ ├─ 📝 ERRORS.md Markdown 5L · 75 B
│ ├─ 📝 FEATURE_REQUESTS.md Markdown 5L · 84 B
│ └─ 📝 LEARNINGS.md Markdown 5L · 99 B
├─ 📁 assets
│ ├─ 📝 LEARNINGS.md Markdown 45L · 1.1 KB
│ └─ 📝 SKILL-TEMPLATE.md Markdown 177L · 3.3 KB
├─ 📁 hooks
│ └─ 📁 openclaw
│ ├─ 📜 handler.js JavaScript 56L · 1.6 KB
│ ├─ 📜 handler.ts TypeScript 62L · 1.8 KB
│ └─ 📝 HOOK.md Markdown 23L · 589 B
├─ 📁 references
│ ├─ 📝 examples.md Markdown 374L · 8.1 KB
│ ├─ 📝 hooks-setup.md Markdown 223L · 4.8 KB
│ └─ 📝 openclaw-integration.md Markdown 248L · 5.5 KB
├─ 📁 scripts
│ ├─ 🔧 activator.sh Shell 20L · 680 B
│ ├─ 🔧 error-detector.sh Shell 55L · 1.3 KB
│ └─ 🔧 extract-skill.sh Shell 221L · 5.2 KB
├─ 📋 _meta.json JSON 5L · 139 B
└─ 📝 SKILL.md Markdown 92L · 2.5 KB

Security Positives

✓ No network calls or data exfiltration detected
✓ No credential harvesting or sensitive path access
✓ No base64 encoding or obfuscation
✓ Path validation in extract-skill.sh prevents directory traversal
✓ Shell scripts are simple and readable with clear purpose
✓ No remote script execution (curl|bash, wget|sh)
✓ No supply chain risks - no external dependencies