Scan Report
This report was generated in Chinese. Some content may be in Chinese.
8 /100
openclaw-soul
OpenClaw自我进化框架一键部署工具
openclaw-soul 是 OpenClaw 框架的自我进化系统部署工具,代码功能与文档声明一致,无恶意行为迹象。涉及的文件部署、shell 执行和定时任务配置均属正常工具行为。
Safe to install
该 skill 可安全使用。注意:部署时会修改系统配置(openclaw.json)和安装 crontab 定时任务,建议在非生产环境首次测试。
Findings 3 items
| Severity | Finding | Location |
|---|---|---|
| Low | 权限声明宽泛 Doc Mismatch | SKILL.md:1 |
| Low | 配置文件包含API密钥环境变量名 Sensitive Access | fallback/evoclaw/config.json:1 |
| Info | 安装定时任务实现持久化 Persistence | SKILL.md:540 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | NONE | WRITE | ✓ Aligned | SKILL.md:120-160 代码复制模板文件到workspace |
| Shell | NONE | WRITE | ✓ Aligned | SKILL.md:160-180 使用cp/mkdir/git命令 |
| Network | NONE | READ | ✓ Aligned | SKILL.md:400-420 向量搜索需要embedding API |
| Environment | NONE | WRITE | ✓ Aligned | SKILL.md:450-480 修改openclaw.json配置 |
24 findings
Medium External URL 外部 URL
https://api.siliconflow.cn/v1 SKILL.md:416 Medium External URL 外部 URL
https://www.moltbook.com/api/v1/agents/me fallback/evoclaw/configure.md:150 Medium External URL 外部 URL
https://www.moltbook.com/api/v1/feed?sort=hot&limit=3 fallback/evoclaw/configure.md:169 Medium External URL 外部 URL
https://api.x.com/2/users/me fallback/evoclaw/configure.md:210 Medium External URL 外部 URL
https://api.x.com/2/users/me/mentions?max_results=5&tweet.fields=created_at fallback/evoclaw/configure.md:223 Medium External URL 外部 URL
https://www.moltbook.com/api/v1 fallback/evoclaw/references/sources.md:28 Medium External URL 外部 URL
https://www.moltbook.com/api/v1/feed?sort=hot&limit=10 fallback/evoclaw/references/sources.md:43 Medium External URL 外部 URL
https://www.moltbook.com/api/v1/posts?sort=new&limit=10&submolt=general fallback/evoclaw/references/sources.md:55 Medium External URL 外部 URL
https://www.moltbook.com/api/v1/posts/ fallback/evoclaw/references/sources.md:62 Medium External URL 外部 URL
https://www.moltbook.com/api/v1/search?q=agent+identity&limit=10 fallback/evoclaw/references/sources.md:69 Medium External URL 外部 URL
https://www.moltbook.com/api/v1/agents/status fallback/evoclaw/references/sources.md:79 Medium External URL 外部 URL
https://www.moltbook.com/api/v1/agents/dm/check fallback/evoclaw/references/sources.md:83 Medium External URL 外部 URL
https://api.x.com/2 fallback/evoclaw/references/sources.md:129 Medium External URL 外部 URL
https://api.x.com/2/users/$ fallback/evoclaw/references/sources.md:145 Medium External URL 外部 URL
https://api.x.com/2/tweets/search/recent?query=AI+agent+identity&max_results=10&tweet.fields=created_at fallback/evoclaw/references/sources.md:159 Medium External URL 外部 URL
https://api.x.com/2/tweets/ fallback/evoclaw/references/sources.md:166 Medium External URL 外部 URL
https://api.example.com/v1 fallback/evoclaw/references/sources.md:205 Medium External URL 外部 URL
https://mastodon.social/api/v1 fallback/evoclaw/references/sources.md:363 Medium External URL 外部 URL
https://mastodon.social/api/v1/accounts/verify_credentials fallback/evoclaw/references/sources.md:368 Medium External URL 外部 URL
https://mastodon.social/api/v1/timelines/home?limit=20 fallback/evoclaw/references/sources.md:375 Medium External URL 外部 URL
https://mastodon.social/api/v1/notifications?types[ fallback/evoclaw/references/sources.md:385 Medium External URL 外部 URL
https://mastodon.social/api/v2/search?q=agent+identity&type=statuses&limit=10 fallback/evoclaw/references/sources.md:392 Medium External URL 外部 URL
http://www.w3.org/2000/svg fallback/evoclaw/tools/soul-viz.py:224 Medium External URL 外部 URL
https://clawic.com/skills/self-improving fallback/self-improving/SKILL.md:5 File Tree
61 files · 526.7 KB · 15619 lines Markdown 38f · 8385L
Python 10f · 4398L
JavaScript 7f · 2493L
TypeScript 1f · 220L
Shell 1f · 64L
JSON 4f · 59L
├─
▾
fallback
│ ├─
▾
evoclaw
│ │ ├─
▾
references
│ │ │ ├─
examples.md
Markdown
│ │ │ ├─
heartbeat-debug.md
Markdown
│ │ │ ├─
schema.md
Markdown
│ │ │ └─
sources.md
Markdown
│ │ ├─
▾
tools
│ │ │ └─
soul-viz.py
Python
│ │ ├─
▾
validators
│ │ │ ├─
check_pipeline_ran.py
Python
│ │ │ ├─
check_workspace.py
Python
│ │ │ ├─
run_all.py
Python
│ │ │ ├─
validate_experience.py
Python
│ │ │ ├─
validate_proposal.py
Python
│ │ │ ├─
validate_reflection.py
Python
│ │ │ ├─
validate_soul.py
Python
│ │ │ └─
validate_state.py
Python
│ │ ├─
_meta.json
JSON
│ │ ├─
config.json
⚠
JSON
│ │ ├─
configure.md
Markdown
│ │ ├─
README.md
Markdown
│ │ └─
SKILL.md
Markdown
│ ├─
▾
hdd
│ │ └─
SKILL.md
Markdown
│ ├─
▾
load-game
│ │ └─
SKILL.md
Markdown
│ ├─
▾
memory-deposit
│ │ └─
▾
scripts
│ │ ├─
auto-commit.sh
Shell
│ │ └─
merge-daily-transcript.js
JavaScript
│ ├─
▾
project-skill-pairing
│ │ └─
SKILL.md
Markdown
│ ├─
▾
save-game
│ │ └─
SKILL.md
Markdown
│ ├─
▾
sdd
│ │ └─
SKILL.md
Markdown
│ └─
▾
self-improving
│ ├─
_meta.json
JSON
│ ├─
boundaries.md
Markdown
│ ├─
corrections.md
Markdown
│ ├─
learning.md
Markdown
│ ├─
memory-template.md
Markdown
│ ├─
memory.md
Markdown
│ ├─
operations.md
Markdown
│ ├─
reflections.md
Markdown
│ ├─
scaling.md
Markdown
│ ├─
setup.md
Markdown
│ └─
SKILL.md
Markdown
├─
▾
references
│ ├─
▾
hooks
│ │ └─
▾
user-observation
│ │ ├─
handler.ts
TypeScript
│ │ └─
HOOK.md
Markdown
│ ├─
agents-template.md
Markdown
│ ├─
bootstrap-guide.md
Markdown
│ ├─
dynamic-personality-addon.md
Markdown
│ ├─
goals-template.md
Markdown
│ ├─
heartbeat-template.md
Markdown
│ ├─
identity-template.md
Markdown
│ ├─
long-term-memory-template.md
Markdown
│ ├─
memory-architecture-template.md
Markdown
│ ├─
memory-rules-addon.md
Markdown
│ ├─
soul-template.md
Markdown
│ ├─
user-template.md
Markdown
│ └─
working-memory-template.md
Markdown
├─
▾
scripts
│ ├─
▾
memory-optimization
│ │ ├─
memory-classifier.js
JavaScript
│ │ ├─
memory-decay.js
JavaScript
│ │ ├─
memory-dedup.js
JavaScript
│ │ ├─
memory-health-check.js
JavaScript
│ │ ├─
memory-index-builder.js
JavaScript
│ │ └─
merge-daily-transcript.js
JavaScript
│ └─
preflight_check.py
Python
├─
_meta.json
JSON
├─
README.md
Markdown
├─
README.zh-CN.md
Markdown
└─
SKILL.md
Markdown
Dependencies 3 items
| Package | Version | Source | Known Vulns | Notes |
|---|---|---|---|---|
openclaw | >=2026.3.0 | npm | No | 核心依赖CLI工具 |
Node.js | * | system | No | 运行环境 |
Git | * | system | No | 版本控制 |
Security Positives
✓ 代码功能与文档声明一致,无阴影功能
✓ 无恶意指标:不含base64编码、eval、凭证收割、远程shell等危险模式
✓ 无敏感路径访问:未访问~/.ssh、~/.aws、.env等凭证路径
✓ 脚本操作符合工具声明的合法用途
✓ 配置文件仅引用环境变量名,未硬编码密钥
✓ 使用fallback机制提供离线安装选项