Scan Report
This report was generated in Chinese. Some content may be in Chinese.
15 /100
vibe-coding-cn
AI 团队协作,自动生成完整项目。5 Agent + SPEC.md + Agent 投票审批 + 需求追溯
Vibe Coding CN 是一个合法的 AI 项目生成技能,核心功能清晰、代码质量良好,无恶意行为发现。存在轻微的权限声明宽泛问题但不影响安全。
Safe to install
可安全使用。建议:1) 限制 filesystem 权限为真正需要的输出目录;2) 移除不必要的 exec 声明;3) 锁定 ws 依赖版本。
Findings 3 items
| Severity | Finding | Location |
|---|---|---|
| Low | 权限声明宽泛 Priv Escalation | executors/vibe-executor-v4.1.js:450 |
| Low | 可选依赖版本范围过宽 Supply Chain | package.json:23 |
| Info | 读取环境变量 Sensitive Access | executors/llm-client.js:14 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | WRITE | WRITE | ✓ Aligned | claw.json:capabilities 声明 file_read/file_write,代码中使用 fs.promises |
| Network | NONE | NONE | — | claw.json:permissions.network=false,llm-client.js 仅在 llmCallback 缺失时使用 sessions_… |
| Shell | ADMIN | WRITE | ✓ Aligned | exec 仅用于打开文件浏览器(open/start/xdg-open),非真正的 shell 执行 |
| Environment | NONE | READ | ✓ Aligned | llm-client.js:14 读取 DASHSCOPE_API_KEY,属于正常凭证使用 |
| Skill Invoke | ADMIN | ADMIN | ✓ Aligned | 使用 sessions_spawn 调用子代理 |
15 findings
Medium External URL 外部 URL
https://clawhub.ai/vibe-coding-cn CLAWHUB-CHECKLIST.md:234 Medium External URL 外部 URL
https://clawhub.ai PUBLISH-MANUALLY.md:15 Medium External URL 外部 URL
https://img.shields.io/badge/version-4.1.0-blue.svg README.md:5 Medium External URL 外部 URL
https://img.shields.io/badge/OpenClaw-Skill-green.svg README.md:6 Medium External URL 外部 URL
https://openclaw.ai README.md:6 Medium External URL 外部 URL
https://img.shields.io/badge/license-MIT-blue.svg README.md:7 Medium External URL 外部 URL
https://img.shields.io/github/stars/openclaw/vibe-coding-cn?style=social README.md:411 Medium External URL 外部 URL
https://img.shields.io/github/forks/openclaw/vibe-coding-cn?style=social README.md:412 Medium External URL 外部 URL
https://docs.openclaw.ai docs/archive/DOCS-INDEX.md:103 Medium External URL 外部 URL
https://clawhub.ai/veeramanikandanr48/spec-miner docs/archive/SPEC-SKILLS-RESEARCH.md:26 Medium External URL 外部 URL
https://clawhub.ai/datadrivenconstruction/specification-extractor docs/archive/SPEC-SKILLS-RESEARCH.md:63 Medium External URL 外部 URL
https://clawhub.ai/kevdogg102396-afk/spec-first-dev docs/archive/SPEC-SKILLS-RESEARCH.md:100 Medium External URL 外部 URL
https://clawhub.ai/vinayakv22/speckit-workflow docs/archive/SPEC-SKILLS-RESEARCH.md:145 Medium External URL 外部 URL
https://clawhub.ai/aungmyokyaw/spec-kit docs/archive/SPEC-SKILLS-RESEARCH.md:185 Medium External URL 外部 URL
https://dashscope.aliyuncs.com/api/v1 executors/llm-client.js:13 File Tree
63 files · 485.3 KB · 20027 lines Markdown 48f · 15040L
JavaScript 8f · 2887L
HTML 2f · 1805L
JSON 3f · 192L
Shell 2f · 103L
├─
▾
docs
│ └─
▾
archive
│ ├─
CLI-REMOVAL-REPORT.md
Markdown
│ ├─
DOCS-INDEX.md
Markdown
│ ├─
EXECUTION-FLOW.md
Markdown
│ ├─
INSTALL-VERIFICATION.md
Markdown
│ ├─
INTEGRATION-GUIDE.md
Markdown
│ ├─
OPTIMIZATION-PLAN.md
Markdown
│ ├─
OPTIMIZATION-SUMMARY.md
Markdown
│ ├─
P0-COMPLETE.md
Markdown
│ ├─
P0-FINAL.md
Markdown
│ ├─
P0-FIX-COMPLETE.md
Markdown
│ ├─
PRD-READING-COMPLETE.md
Markdown
│ ├─
README-COMPLETE.md
Markdown
│ ├─
RELEASE-CHECKLIST.md
Markdown
│ ├─
RELEASE.md
Markdown
│ ├─
SKILL_SUMMARY.md
Markdown
│ ├─
SPEC-SKILLS-RESEARCH.md
Markdown
│ ├─
TEMPLATE-OPTIMIZATION.md
Markdown
│ ├─
USER-EXPERIENCE-FIXES.md
Markdown
│ ├─
V4-COMPLETE.md
Markdown
│ ├─
V4.1-COMPLETE.md
Markdown
│ ├─
VOTE-INTEGRATION-COMPLETE.md
Markdown
│ └─
VOTE-MECHANISM.md
Markdown
├─
▾
examples
│ └─
examples.md
Markdown
├─
▾
executors
│ ├─
analysis-cache.js
JavaScript
│ ├─
incremental-updater.js
JavaScript
│ ├─
llm-client.js
JavaScript
│ ├─
version-manager.js
JavaScript
│ └─
vibe-executor-v4.1.js
JavaScript
├─
▾
scripts
│ ├─
install-local.sh
Shell
│ └─
publish.sh
Shell
├─
▾
templates
│ ├─
analyst.prompt.md
Markdown
│ ├─
architect.prompt.md
Markdown
│ ├─
developer.prompt.md
Markdown
│ └─
tester.prompt.md
Markdown
├─
▾
ui
│ ├─
vibe-dashboard-v2.html
HTML
│ └─
vibe-dashboard.html
HTML
├─
claw.json
JSON
├─
CLAWHUB-CHECKLIST.md
Markdown
├─
CLAWHUB-PUBLISH.md
Markdown
├─
CLEANUP-REPORT.md
Markdown
├─
CODE-REVIEW.md
Markdown
├─
DEPENDENCIES.md
Markdown
├─
ENHANCED-COLLABORATION.md
Markdown
├─
FINAL-RELEASE-REPORT.md
Markdown
├─
INCREMENTAL-ANALYSIS-v2.md
Markdown
├─
index.js
JavaScript
├─
OPENCLAW-INTEGRATION.md
Markdown
├─
ORCHESTRATOR-GUIDE.md
Markdown
├─
package-lock.json
JSON
├─
package.json
JSON
├─
PUBLISH-MANUALLY.md
Markdown
├─
QUICKSTART.md
Markdown
├─
README.md
Markdown
├─
RELEASE-NOW.md
Markdown
├─
server.js
JavaScript
├─
SKILL.md
Markdown
├─
SPEC-MD-FORMAT.md
Markdown
├─
test-p0-e2e.js
JavaScript
├─
TODO-v3.md
Markdown
├─
TRACEABILITY-MATRIX.md
Markdown
├─
UI-GUIDE.md
Markdown
├─
VERSIONING-GUIDE.md
Markdown
└─
WELCOME.md
Markdown
Dependencies 1 items
| Package | Version | Source | Known Vulns | Notes |
|---|---|---|---|---|
ws | ^8.20.0 | npm | No | 可选依赖,仅用于可视化监控;无版本锁定 |
Security Positives
✓ 代码结构清晰,模块化良好(executors/ 目录分离职责)
✓ 文档与实现基本一致,无明显阴影功能
✓ 无凭证窃取行为(DASHSCOPE_API_KEY 仅用于调用自己的 API)
✓ 无远程代码执行、无 Base64 混淆、无敏感文件遍历
✓ 质量门禁机制完善(qualityCheck 函数)
✓ 版本管理完整(version-manager.js)
✓ 无 HTML 注释中的隐藏指令