ai-intelligent-asset-management
Skill presents itself as a functional IT asset management system but contains zero executable code, creating a deceptive facade with suspicious embedded metadata.
Why this conclusion was reached
1/4 dimensions flaggedDeclared resources and inferred behavior are broadly aligned.
No obvious high-risk egress or execution signals were found.
The report includes 3 attack-chain steps and 2 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
Attack Chain
reconnaissance · SKILL.md:1
deception · SKILL.md:27
concealment · SKILL.md:1
What drove the risk score up
SKILL.md references app.py and requirements.txt for installation, but no such files exist in the repository
YAML frontmatter with openclaw metadata embedded in SKILL.md is non-standard and suspicious
Claims to be a functional Python+FastAPI system but contains zero code files
No requirements.txt, no package.json, no dependency declarations
Most important evidence
Documentation claims executable application with no code
SKILL.md installation section instructs users to 'pip install -r requirements.txt' and 'python app.py', but neither requirements.txt nor app.py (or any code file) exists in the repository. This is either an abandoned project or a deceptive placeholder.
SKILL.md:27 Embedded YAML metadata in SKILL.md
SKILL.md contains YAML frontmatter (lines 1-9) with openclaw metadata including 'requires: { bins: [] }'. This non-standard documentation structure is unusual and may contain hidden configurations.
SKILL.md:1 Description mismatch between SKILL.md and skill.json
SKILL.md describes 'IT 资产管理,硬件/软件全生命周期' while skill.json has generic 'AI intelligent ai-intelligent-asset-management'. The inconsistency suggests hasty or deceptive creation.
skill.json:1 Declared capability vs actual capability
No code files present to infer capabilities No code files present to infer capabilities No code files present to infer capabilities Suspicious artifacts and egress
No obvious IOC was extracted.
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md skill.json