安全决策报告
lua-scripter (declared in SKILL.md) / self-improving-agent (in _meta.json)
Legitimate Lua development assistant skill with self-improvement hooks. All scripts are readable, no malicious patterns detected, no network/credential access.
为什么得出这个结论
0/4 个维度触发 通过
声明与实际能力
声明资源与推断能力基本一致。
通过
隐藏执行与外联
当前没有明显的高危外联或执行信号。
通过
攻击链与高危发现
没有形成明确的恶意路径。
复核
依赖与供应链卫生
没有完整依赖信息,供应链判断需要保留弹性。
风险分是怎么被拉高的
Minor doc inconsistency +5
SKILL.md declares 'lua-scripter' but _meta.json shows 'self-improving-agent' - cosmetic only
最关键的证据
当前没有结构化安全发现。
声明能力 vs 实际能力
文件系统 通过
声明 NONE
→ 推断 WRITE
extract-skill.sh creates ./skills/<name>/SKILL.md with path validation 命令执行 通过
声明 NONE
→ 推断 READ
Scripts use CLAUDE_TOOL_OUTPUT env var for error detection 环境变量 通过
声明 READ
→ 推断 READ
error-detector.sh reads CLAUDE_TOOL_OUTPUT (documented hook behavior) 网络访问 通过
声明 NONE
→ 推断 NONE
No network calls in any script 可疑产物与外联
没有提取到明显 IOC。
依赖与供应链
没有结构化依赖告警。
文件构成
16 个文件 · 1616 行
Markdown 10 个文件 · 1197 行Shell 3 个文件 · 296 行TypeScript 1 个文件 · 62 行JavaScript 1 个文件 · 56 行JSON 1 个文件 · 5 行
其他文件 · examples.md · openclaw-integration.md · extract-skill.sh · hooks-setup.md · SKILL-TEMPLATE.md · SKILL.md +6
安全亮点
No network calls or data exfiltration detected
No credential harvesting or sensitive path access
No base64 encoding or obfuscation
Path validation in extract-skill.sh prevents directory traversal
Shell scripts are simple and readable with clear purpose
No remote script execution (curl|bash, wget|sh)
No supply chain risks - no external dependencies