Skill Trust Decision

OpenClaw Skills Collection

项目包含多个硬编码真实API密钥和危险Shell命令文档,但未发现主动恶意行为证据。代码本身功能正常,敏感信息清理机制存在。

Install decision first Source: Manual upload Scanned: Apr 3, 2026
Files 1310
Artifacts 814
Violations 0
Findings 6
Most direct threat evidence
High
硬编码真实API密钥

在 simple_test_silicom.py 中发现 SiliconFlow API 真实密钥 sk-teftcdqwnkilkgeivhqqlqxbyxsdbwhdditinrqvvcfnqcyv

simple_test_silicom.py:15

Why this conclusion was reached

2/4 dimensions flagged
Pass
Declared vs actual capability

Declared resources and inferred behavior are broadly aligned.

Block
Hidden execution and egress

18 high-risk artifacts or egress signals were extracted.

Block
Attack chain and severe findings

The report includes 0 attack-chain steps and 2 severe findings.

Review
Dependencies and supply chain hygiene

1 dependency or supply-chain issues need attention.

What drove the risk score up

真实API密钥硬编码 +20

simple_test_silicom.py:15 和 academic_paper_searcher.py:328 包含真实API密钥

危险Shell命令文档 +10

elite-longterm-memory/SKILL.md:293 和 capability-evolver 测试文件包含危险命令

设备指纹收集 +8

deviceId.js 收集MAC地址、容器ID等硬件标识符

凭证清理机制存在 +-5

sanitize.js 实现了敏感信息过滤,降低风险

测试文件占位符密钥 +-3

多处测试用例中的API密钥为占位符,非真实密钥

Most important evidence

High

硬编码真实API密钥

在 simple_test_silicom.py 中发现 SiliconFlow API 真实密钥 sk-teftcdqwnkilkgeivhqqlqxbyxsdbwhdditinrqvvcfnqcyv

simple_test_silicom.py:15
立即删除或使用环境变量替换
High

硬编码真实API密钥

在 academic_paper_searcher.py 和 simple_paper_search.py 中发现 ScraperAPI 真实密钥

academic_paper_searcher.py:328
立即删除或使用环境变量替换
Medium

危险Shell命令文档

elite-longterm-memory/SKILL.md 文档中包含 rm -rf ~/.openclaw/memory/lancedb/ 命令,虽为文档说明但可能造成数据丢失

skills/elite-longterm-memory/SKILL.md:293
添加安全警告标识或使用更安全的替代方案
Medium

测试中的危险命令

capability-evolver 测试文件包含 rm -rf / 用于验证安全过滤,属于测试用例但可能泄露

skills/capability-evolver/test/skillDistiller.test.js:216
测试用例已正确过滤危险命令,无需修改但需确保测试通过
Medium

设备指纹收集

deviceId.js 收集 MAC 地址、容器 ID、机器 ID 等硬件标识符用于节点身份识别

skills/capability-evolver/src/gep/deviceId.js:70
确保用户知情同意,MAC地址哈希处理后再使用
Low

占位符API密钥

多处测试文件和文档包含占位符密钥如 sk-1234567890abcdef, your-api-key-here

skills/browser-automation/setup.json:28
当前处理正确,测试文件中的占位符不构成风险

Declared capability vs actual capability

Filesystem Pass
Declared READ+WRITE
Inferred WRITE
skills/free-ride/main.py - 配置文件写入
Network Pass
Declared READ+WRITE
Inferred READ+WRITE
skills/capability-evolver/SKILL.md - GitHub API 和 Hub 通信
Shell Pass
Declared WRITE
Inferred WRITE
skills/capability-evolver - git/node/npm 执行

Suspicious artifacts and egress

Critical API Key
sk-teftcdqwnkilkgeivhqqlqxbyxsdbwhdditinrqvvcfnqcyv

simple_test_silicom.py:15

Critical API Key
sk-abcdefghijklmnopqrstuvwxyz

skills/capability-evolver/test/sanitize.test.js:10

Critical API Key
ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

skills/capability-evolver/test/sanitize.test.js:19

Critical API Key
gho_abcdefghijklmnopqrstuvwxyz1234567890

skills/capability-evolver/test/sanitize.test.js:21

Critical API Key
AKIAIOSFODNN7EXAMPLE

skills/capability-evolver/test/sanitize.test.js:29

Critical Dangerous Command
rm -rf /

skills/capability-evolver/test/skillDistiller.test.js:216

Critical Dangerous Command
rm -rf ~

skills/elite-longterm-memory/SKILL.md:293

Critical Encoded Execution
base64 -d

环境认知与文件交付检查清单.md:122

High API Key
API_KEY = "4ee886477b1a5044ec24da7a198950e8"

academic_paper_searcher.py:328

High IP Address
6.6.87.2

quick_ultimate_optimization_20260319_115138/submission_package/reports/visual_verification_report.md:14

High API Key
api_key = "4ee886477b1a5044ec24da7a198950e8"

simple_paper_search.py:15

High API Key
api_key = "sk-teftcdqwnkilkgeivhqqlqxbyxsdbwhdditinrqvvcfnqcyv"

simple_test_silicom.py:15

Dependencies and supply chain

PackageVersionSourceKnown vulnNotes
requests * pip No 无版本锁定,存在依赖解析风险
evolver file:../evolver npm No 本地文件依赖

File composition

1310 files · 268826 lines
Markdown 643 files · 111380 linesPython 238 files · 80983 linesJavaScript 197 files · 43143 linesJSON 171 files · 29748 linesShell 18 files · 2357 linesText 25 files · 662 lines
Files of concern · 7
skills/ui-design-system/token-generation.md Markdown · 324 lines
skills/clawdbot-filesystem/config.json JSON · 40 lines
quick_search_results.csv CSV · 147 lines
https://arxiv.org/pdf/1001.2772v1 · https://arxiv.org/pdf/0703031v2 · https://arxiv.org/pdf/2211.05409v1 · https://arxiv.org/pdf/1907.09258v1 · https://arxiv.org/pdf/0211004v1 · https://arxiv.org/pdf/1012.1381v7 · https://arxiv.org/pdf/1411.6015v1 · https://arxiv.org/pdf/2106.07806v3 · https://arxiv.org/pdf/1211.2693v1 · https://arxiv.org/pdf/1607.04770v1 · https://arxiv.org/pdf/1606.05112v1 · https://arxiv.org/pdf/0306108v1 · https://arxiv.org/pdf/2407.08176v1 · https://arxiv.org/pdf/2002.11672v3 · https://arxiv.org/pdf/2011.05106v2 · https://arxiv.org/pdf/2204.06033v1 · https://arxiv.org/pdf/2501.03569v1 · https://arxiv.org/pdf/2504.21007v3 · https://arxiv.org/pdf/1509.00440v1 · https://arxiv.org/pdf/2410.12614v1 · https://arxiv.org/pdf/1111.5423v1 · https://arxiv.org/pdf/2005.13021v2 · https://arxiv.org/pdf/1711.06392v3 · https://arxiv.org/pdf/1901.00775v2 · http://www.youtube.com/watch?v=pWWw7\_6cQ-U · https://arxiv.org/pdf/1601.00037v2 · https://arxiv.org/pdf/2412.07415v1 · https://arxiv.org/pdf/1812.02852v1 · https://arxiv.org/pdf/2111.07407v1 · https://arxiv.org/pdf/2401.08330v2 · https://arxiv.org/pdf/1904.04727v2 · https://arxiv.org/pdf/1002.1185v1 · https://arxiv.org/pdf/1811.06375v1 · https://arxiv.org/pdf/1403.1515v2 · https://jhang2020.github.io/Projects/Shap-Mix/Shap-Mix.html. · https://arxiv.org/pdf/2501.02842v1 · https://arxiv.org/pdf/2201.07642v1 · https://arxiv.org/pdf/2407.15216v1
bridge_engineering_papers_20260314_1711.csv CSV · 147 lines
https://arxiv.org/pdf/2603.10484v1 · https://arxiv.org/pdf/2603.12069v1 · https://arxiv.org/pdf/2603.12210v1 · https://arxiv.org/pdf/2603.11987v1 · https://arxiv.org/pdf/2603.11975v1 · https://arxiv.org/pdf/2603.11935v1 · https://arxiv.org/pdf/2603.12260v1 · https://arxiv.org/pdf/2603.12257v1 · https://arxiv.org/pdf/2603.12252v1 · https://arxiv.org/pdf/2603.12152v1 · https://arxiv.org/pdf/2603.12146v1 · https://arxiv.org/pdf/2603.11995v1 · https://arxiv.org/pdf/2603.11872v1 · https://arxiv.org/pdf/2603.11868v1 · https://arxiv.org/pdf/2603.12244v1 · https://arxiv.org/pdf/2603.12206v1 · https://arxiv.org/pdf/2603.12187v1 · https://arxiv.org/pdf/2603.12105v1 · https://arxiv.org/pdf/2603.11542v1 · https://arxiv.org/pdf/2603.12262v1 · https://arxiv.org/pdf/2603.12250v1 · https://arxiv.org/pdf/2603.12222v1 · https://arxiv.org/pdf/2603.12226v1 · https://arxiv.org/pdf/2603.12216v1 · https://arxiv.org/pdf/2603.12204v1 · https://arxiv.org/pdf/2405.13996v2 · https://arxiv.org/pdf/cond-mat/0210418v1 · https://arxiv.org/pdf/2510.07606v1 · https://arxiv.org/pdf/2511.00099v1 · https://arxiv.org/pdf/1910.03560v2 · https://arxiv.org/pdf/2102.03983v1 · https://arxiv.org/pdf/2108.05010v1 · https://arxiv.org/pdf/1808.04572v3 · https://arxiv.org/pdf/2406.04710v2 · https://arxiv.org/pdf/2009.08525v1 · https://arxiv.org/pdf/2110.04600v2 · https://arxiv.org/pdf/cs/0306108v1 · https://arxiv.org/pdf/1601.07392v2 · https://arxiv.org/pdf/2406.04780v1 · https://arxiv.org/pdf/1707.03869v3 · https://arxiv.org/pdf/2302.08893v4 · https://arxiv.org/pdf/2506.09781v2 · https://arxiv.org/pdf/1904.04104v1 · https://arxiv.org/pdf/2105.13961v3 · https://arxiv.org/pdf/2306.04338v1 · https://arxiv.org/pdf/2006.16189v4 · https://arxiv.org/pdf/2109.09307v4 · https://arxiv.org/pdf/1905.04749v2 · https://arxiv.org/pdf/2201.12150v2 · https://arxiv.org/pdf/2304.02381v2 · https://arxiv.org/pdf/2402.01393v3 · https://arxiv.org/pdf/2303.15563v1 · https://arxiv.org/pdf/1706.01513v2 · https://arxiv.org/pdf/1705.05172v1 · https://arxiv.org/pdf/1906.01101v1 · https://arxiv.org/pdf/2302.04143v2 · https://arxiv.org/pdf/1711.00146v1 · https://arxiv.org/pdf/2403.12562v2 · https://arxiv.org/pdf/1706.09552v1 · https://arxiv.org/pdf/1705.03921v1 · https://arxiv.org/pdf/1710.05468v9 · https://arxiv.org/pdf/1811.09385v2 · https://udtiri.com/submission/. · https://arxiv.org/pdf/2503.18082v1 · https://arxiv.org/pdf/2209.08538v1 · https://arxiv.org/pdf/2103.09512v1 · https://arxiv.org/pdf/2010.15021v1 · https://arxiv.org/pdf/1110.5230v1 · https://arxiv.org/pdf/2501.16662v2 · https://arxiv.org/pdf/2601.04750v1 · https://arxiv.org/pdf/2402.17861v3 · https://arxiv.org/pdf/2307.12479v2 · https://arxiv.org/pdf/2308.12400v1 · https://arxiv.org/pdf/2112.01298v2 · https://arxiv.org/pdf/2401.15284v6 · https://arxiv.org/pdf/2504.16770v1 · https://arxiv.org/pdf/2508.15680v1 · https://arxiv.org/pdf/2211.12434v1 · https://arxiv.org/pdf/2311.18252v3 · https://arxiv.org/pdf/2504.14689v1 · https://arxiv.org/pdf/2304.04780v1 · https://arxiv.org/pdf/2204.10358v1 · https://arxiv.org/pdf/1301.2158v1 · https://arxiv.org/pdf/2410.11896v1 · https://arxiv.org/pdf/2304.13269v4 · https://arxiv.org/pdf/1812.04814v1 · https://arxiv.org/pdf/1703.06597v1 · https://arxiv.org/pdf/1304.3429v1 · https://www.gamesim.ai · https://arxiv.org/pdf/1903.02172v1 · https://arxiv.org/pdf/2110.08637v1 · https://arxiv.org/pdf/2310.09243v1 · https://arxiv.org/pdf/2510.16889v1 · https://arxiv.org/pdf/2402.19295v1 · https://arxiv.org/pdf/2111.08260v2 · https://arxiv.org/pdf/1807.09221v1 · https://arxiv.org/pdf/1909.10225v1 · https://arxiv.org/pdf/2205.04675v2 · https://arxiv.org/pdf/2107.14072v2 · http://www.fer.unizg.hr/crv/ccvw2013 · https://arxiv.org/pdf/1310.0319v3 · https://arxiv.org/pdf/2111.11066v1 · https://arxiv.org/pdf/1910.13796v1 · https://arxiv.org/pdf/1905.12487v1 · https://arxiv.org/pdf/1310.0315v1 · https://arxiv.org/pdf/2311.10051v1 · https://arxiv.org/pdf/2311.14544v1 · https://arxiv.org/pdf/2003.04390v4 · https://arxiv.org/pdf/1905.13613v2 · https://arxiv.org/pdf/2205.15014v1 · https://arxiv.org/pdf/1911.06045v3 · https://arxiv.org/pdf/2205.08157v1 · https://arxiv.org/pdf/1810.00482v1 · https://arxiv.org/pdf/2203.07057v2 · https://arxiv.org/pdf/1907.01463v1
final_research_output/literature_list.json JSON · 3047 lines
https://arxiv.org/pdf/1402.7136v1 · https://arxiv.org/pdf/0602634v4 · https://arxiv.org/pdf/1712.08276v2 · https://arxiv.org/pdf/2007.05761v2 · https://arxiv.org/pdf/1410.6972v3 · https://arxiv.org/pdf/2408.03766v3 · https://arxiv.org/pdf/1102.1242v2 · https://arxiv.org/pdf/2306.02813v2 · https://arxiv.org/pdf/1603.02237v2 · https://arxiv.org/pdf/1212.6495v2 · https://arxiv.org/pdf/1307.6233v2 · https://arxiv.org/pdf/1804.04106v6 · https://arxiv.org/pdf/2101.12563v4 · https://arxiv.org/pdf/1808.04351v1 · https://arxiv.org/pdf/2510.01772v1 · https://arxiv.org/pdf/2402.18846v2 · https://arxiv.org/pdf/2510.15750v1 · https://arxiv.org/pdf/1705.02956v1 · https://arxiv.org/pdf/1910.10473v2 · https://arxiv.org/pdf/0306067v1 · https://arxiv.org/pdf/1004.3640v1 · https://arxiv.org/pdf/2507.02208v1 · https://arxiv.org/pdf/1912.06552v1 · https://arxiv.org/pdf/1911.00955v2 · https://arxiv.org/pdf/1509.08130v7 · https://arxiv.org/pdf/1807.07485v3 · https://arxiv.org/pdf/2101.03906v2 · https://arxiv.org/pdf/1910.07640v1 · https://arxiv.org/pdf/2007.09855v5 · https://arxiv.org/pdf/2502.01634v1 · https://arxiv.org/pdf/2510.07895v1 · https://arxiv.org/pdf/1805.00861v1 · https://arxiv.org/pdf/2511.17415v1 · https://arxiv.org/pdf/2203.09179v3 · https://arxiv.org/pdf/1302.4245v3 · https://arxiv.org/pdf/2002.02826v3 · https://arxiv.org/pdf/1911.09946v3 · https://arxiv.org/pdf/1809.04967v3 · https://arxiv.org/pdf/1110.4411v1 · https://arxiv.org/pdf/2104.09778v2 · https://arxiv.org/pdf/1901.01727v1 · https://arxiv.org/pdf/2011.01647v2 · https://arxiv.org/pdf/2212.06370v4 · https://arxiv.org/pdf/2303.06516v3 · https://arxiv.org/pdf/2509.20161v1 · https://arxiv.org/pdf/1402.4180v1 · https://arxiv.org/pdf/2308.05381v4 · https://arxiv.org/pdf/2303.08710v1 · https://arxiv.org/pdf/2511.13766v1 · https://arxiv.org/pdf/2207.14156v1 · https://arxiv.org/pdf/2310.11435v1 · https://arxiv.org/pdf/1908.11476v1 · https://arxiv.org/pdf/1706.07500v1 · https://arxiv.org/pdf/2110.05265v1 · https://arxiv.org/pdf/1612.07827v2 · https://arxiv.org/pdf/1811.04058v4 · https://arxiv.org/pdf/1704.00873v1 · https://arxiv.org/pdf/1701.04695v3 · https://arxiv.org/pdf/2111.12870v1 · https://arxiv.org/pdf/2011.11583v5 · https://arxiv.org/pdf/1908.05571v1 · https://arxiv.org/pdf/2504.12931v1 · https://arxiv.org/pdf/2505.05830v1 · https://arxiv.org/pdf/2107.07580v2 · https://arxiv.org/pdf/1203.6306v1 · https://arxiv.org/pdf/2603.12046v1 · https://arxiv.org/pdf/2312.09246v1 · https://arxiv.org/pdf/2407.12312v1 · https://arxiv.org/pdf/1812.08597v1 · https://arxiv.org/pdf/2406.14485v8 · https://arxiv.org/pdf/2511.10482v1 · https://arxiv.org/pdf/2410.14590v1 · https://arxiv.org/pdf/2407.12950v2 · https://arxiv.org/pdf/2509.02388v1 · https://arxiv.org/pdf/2408.04746v1 · https://arxiv.org/pdf/2408.07224v1 · https://arxiv.org/pdf/2504.10708v1 · https://arxiv.org/pdf/2311.00301v1 · https://arxiv.org/pdf/2501.00258v1 · https://arxiv.org/pdf/2209.06346v2
skills/verified-agent-identity/package-lock.json JSON · 2957 lines
https://paulmillr.com/funding/ · https://www.buymeacoffee.com/ricmoo · https://gitcoin.co/grants/13/ethersjs-complete-simple-and-tiny-2 · https://www.patreon.com/feross · https://feross.org/support · https://opencollective.com/fastify · https://paypal.me/jimmywarting · https://opencollective.com/node-fetch · https://paypal.me/kozjak
paper/skew_bridge_ml_paper_final.md Markdown · 801 lines
Other files · paper_index.json · index.js · solidify.js · solidify.js · evolve.js

Security positives

capability-evolver 实现了敏感信息清理机制 (sanitize.js),可过滤 API 密钥、凭证、私钥等
skills/browser-automation 正确处理了本地和远程模式的自动切换
skills/free-ride 通过环境变量获取 API 密钥,符合安全实践
capability-evolver 测试文件包含完整的安全过滤测试用例
项目整体结构清晰,skill 功能描述较为完整