Skill Trust Decision

用户工作区 (Multi-Skill Workspace)

工作区包含多个风险点:clawhub skills 使用虚构的 API 名称,多处硬编码 API 密钥,但核心技能(skill-vetting/find-skills/self-improving-agent-cn)本身功能合法

Install decision first Source: Manual upload Scanned: Apr 5, 2026
Files 614
Artifacts 256
Violations 0
Findings 3
Most direct threat evidence
01
用户信任 Nano Banana Pro 名称 Entry · clawhub skills/SKILL.md
02
API 密钥被硬编码在文档中 Escalation · skills/tts-automation/SKILL.md
03
密钥泄露可能导致 API 滥用或费用损失 Impact · skills/tts-automation/SKILL.md

Why this conclusion was reached

2/4 dimensions flagged
Pass
Declared vs actual capability

Declared resources and inferred behavior are broadly aligned.

Block
Hidden execution and egress

9 high-risk artifacts or egress signals were extracted.

Block
Attack chain and severe findings

The report includes 3 attack-chain steps and 2 severe findings.

Pass
Dependencies and supply chain hygiene

Dependencies are present but no obvious high-risk issue stands out.

Attack Chain

01
用户信任 Nano Banana Pro 名称

Entry · clawhub skills/SKILL.md:1

02
API 密钥被硬编码在文档中

Escalation · skills/tts-automation/SKILL.md:96

03
密钥泄露可能导致 API 滥用或费用损失

Impact · skills/tts-automation/SKILL.md:96

What drove the risk score up

clawhub skills 使用虚构 API 名称 +20

声明使用 'Google Nano Banana Pro (Gemini 3 Pro Image)' 和 'gemini-3-pro-image-preview' 模型,这些不是真实的 Google API 产品

硬编码 API 密钥 +25

skills/tts-automation/SKILL.md:96 包含硬编码密钥 sk-1f3847debc3e492e81f64115b20c6d82

Most important evidence

High Doc Mismatch

虚构的 API 名称

clawhub skills 声明使用 'Google Nano Banana Pro (Gemini 3 Pro Image)' API 和 'gemini-3-pro-image-preview' 模型,这些不是真实的 Google 产品名称

clawhub skills/SKILL.md:1
验证此 API 的真实性,或使用标准 Gemini API
High Credential Theft

SKILL.md 中硬编码 API 密钥

skills/tts-automation/SKILL.md 第96行包含硬编码的 API 密钥

skills/tts-automation/SKILL.md:96
将 API 密钥移至环境变量 GEMINI_API_KEY,不要在文档或代码中明文存储
Medium Supply Chain

预扫描发现多处硬编码密钥

ClawSafe 预扫描发现 workspace 中多处文件包含疑似硬编码 API 密钥

multiple files
全面清理 workspace 中的硬编码密钥,统一使用环境变量管理

Declared capability vs actual capability

Filesystem Pass
Declared WRITE
Inferred WRITE
技能用于生成/处理图片和文件
Network Pass
Declared READ
Inferred READ
调用外部 API 生成图片
Shell Pass
Declared NONE
Inferred NONE
仅使用 uv run 执行脚本,无裸 shell 调用
Environment Pass
Declared READ
Inferred READ
读取 GEMINI_API_KEY 环境变量

Suspicious artifacts and egress

Critical API Key
sk-1f3847debc3e492e81f64115b20c6d82

2026-3-10afu的js备份.txt:9

Critical API Key
sk-JPxFOBXYC8ieSrEN9OgCjYJ4V06XqkykhVtma4gw8ONxNuwE

2026-3-10afu的js备份.txt:55

Critical Dangerous Command
rm -rf /

skills/skill-vetting/references/patterns.md:20

High IP Address
120.0.0.0

expert-review-2026-03-09-browser-stealth-explained.md:47

High API Key
accessToken = "your_access_token"

feishu-calendar-integration.md:20

High API Key
api_key='sk-1f3847debc3e492e81f64115b20c6d82'

memory/2026-03-14.md:55

High API Key
API_KEY = "sk-1f3847debc3e492e81f64115b20c6d82"

scripts/vectorize-and-store.py:19

High API Key
API_KEY = 'sk-1f3847debc3e492e81f64115b20c6d82'

search_knowledge.py:22

High API Key
apiKey = "sk-1f3847debc3e492e81f64115b20c6d82"

skills/tts-automation/SKILL.md:96

Medium External URL
http://127.0.0.1:11434/v1

2026-3-10afu的js备份.txt:31

Medium External URL
https://api.xiaomimimo.com/anthropic

2026-3-10afu的js备份.txt:54

Medium External URL
https://open.bigmodel.cn/api/paas/v4

2026-3-10afu的js备份.txt:77

Dependencies and supply chain

PackageVersionSourceKnown vulnNotes
google-genai >=1.0.0 pip No clawhub skills 使用,官方 Google 库
pillow >=10.0.0 pip No clawhub skills 使用,标准图像处理库

File composition

614 files · 140626 lines
Markdown 320 files · 79463 linesHTML 86 files · 34309 linesPython 73 files · 9689 linesJSON 38 files · 7212 linesText 73 files · 6690 linesJavaScript 16 files · 2313 lines
Files of concern · 7
agents/config.json JSON · 50 lines
skills/feishu-multi-agent-manager/package-lock.json JSON · 5324 lines
https://opencollective.com/babel · https://opencollective.com/eslint · https://opencollective.com/typescript-eslint · https://opencollective.com/browserslist · https://tidelift.com/funding/github/npm/browserslist · https://tidelift.com/funding/github/npm/caniuse-lite · https://eslint.org/version-support · https://opencollective.com/fast-check · https://www.patreon.com/feross · https://feross.org/support · [email protected]
memory/2026-03-08.md Markdown · 2415 lines
https://feishu.cn/docx/U9PIdZ5SooMa9TxTXabcv8TGnhb · https://feishu.cn/docx/AafbdknDaoglGpx3RAvcluyUnAM · https://feishu.cn/docx/Mc5td0zf5oKY4bxHNRMc4E6Inyc · https://feishu.cn/docx/B52uds8WLo02Swx5SGdcfClxnSh · https://feishu.cn/docx/BiwWdBiUyoV8XzxrzL6cItginTh · https://feishu.cn/docx/NyVtdMB1NomyooxHnoTcHKw5nRh · https://feishu.cn/docx/NyVtdMB1NomyooxHnoTcHKw5nRh(V1.2,31 · https://feishu.cn/docx/AaC9dkA8QoAmAKx3hQqcLqFznRf(分块写入 · https://feishu.cn/docx/I49YdfIQ8omBxBxtW3Mc3PAWnBc · https://feishu.cn/docx/NTWmdppaWoxzpwxIjpQcZPiFn9f · https://feishu.cn/docx/CEoRdPxG2oiwlzxg9i9c9M1sngf · https://feishu.cn/docx/TNIVdysYHoJ0tex1wTMc5yE8nAc · https://feishu.cn/docx/AaC9dkA8QoAmAKx3hQqcLqFznRf(108 · https://feishu.cn/docx/AaC9dkA8QoAmAKx3hQqcLqFznRf(V1.1,追加 · https://feishu.cn/docx/AaC9dkA8QoAmAKx3hQqcLqFznRf(V1.2,追加 · https://weda.tencentcloudapi.com · https://tcb.cloud.tencent.com/dev · https://cloud.tencent.com/document/product/876 · https://servicewechat.com/wxa-dev-logic/download_redirect?type=win32_x64&from=mpwiki&download_version=2012510280&version_type=1 · https://mp.weixin.qq.com/ · https://mermaid.live/edit#pako:Sy9KLMhQ8AniUgACx+iMktwc3dSKgtSiEt2i1LLM1HKFMCM9g1gFXV07BafoZw1zn+...
memory/triple-line-sync-log.md Markdown · 1963 lines
https://scns3ak4jrto.feishu.cn/docx/GeG0dywMxof8dLx1tcUckSFNndh##
worklog.txt Text · 1784 lines
https://mermaid.live/edit#pako:Sy9KLMhQ8AniUgACx+iMktwc3dSKgtSiEt2i1LLM1HKFMCM9g1gFXV07BafoZw1zn+/e8nT9nqez9ynkZual5CYWxEK0glU4A1Xsfr578rOupU8ndj3tmv+ieS9E3iW6oCg/KzW5RLe4NDc3sagSaHxBflEJkvGu0U92dD7d2PRs3rZn8 · https://scns3ak4jrto.feishu.cn/docx/KaBld2wpyoKL5yxLYuPcSCPOne4 · https://scns3ak4jrto.feishu.cn/docx/GQsbd042WoNdbHxaBbscO9D8nW6 · https://scns3ak4jrto.feishu.cn/base/bascnZQh8v5K6d2m4E7p9Lr1tYw · https://feishu.cn/docx/NQCBdAXzeoBoi0xLJX7cPBHDnm3 · https://feishu.cn/docx/CvCBd5N2co0n02xXPZscQPEsnOL
memory/2026-03-07.md Markdown · 1386 lines
https://scns3ak4jrto.feishu.cn/docx/GeG0dywMxof8dLx1tcUckSFNndh
backups/html-expert-review-v2.0/SKILL.md Markdown · 1046 lines
https://mermaid.live/edit#pako:... · https://mermaid.live/edit · https://mermaid.live/edit#pako: · https://mermaid.live/edit#pako:$base64 · http://www.w3.org/2000/svg
Other files · index.js · people.txt · bom-物料管理规则 - 专家评点-v9-pyramid.html · SKILL.md · expert-review-2026-03-08-voice-redpacket-journey.html

Security positives

skill-vetting 是专业的安全审查工具,包含全面的恶意模式库
self-improving-agent-cn 功能合理,无越权操作
find-skills 使用标准 npx skills CLI,无安全风险
clawhub skills 的 generate_image.py 代码结构清晰,使用标准 google-genai 库