Scan Report
5 /100
openclaw-cn-installer
OpenClaw 中文安装配置助手 - 配置国产 AI 模型
OpenClaw 中文安装配置助手,代码实现与声明功能完全一致,无阴影功能或未声明行为
Safe to install
直接使用
Findings 1 items
| Severity | Finding | Location |
|---|---|---|
| Info | 权限声明与实现基本一致 Doc Mismatch | check-env.js:58 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | WRITE | WRITE | ✓ Aligned | setup-ai.js:31 fs.mkdirSync |
| Network | WRITE | WRITE | ✓ Aligned | test-connection.js:48 HTTPS POST到官方API |
| Shell | NONE | READ | ✓ Aligned | check-env.js:58 execSync which检测命令 |
| Environment | NONE | READ | ✓ Aligned | setup-ai.js:46 仅读取本技能创建的.env |
10 findings
Medium External URL 外部 URL
https://platform.deepseek.com SKILL.md:93 Medium External URL 外部 URL
https://docs.openclaw.ai SKILL.md:107 Medium External URL 外部 URL
https://discord.com/invite/clawd SKILL.md:108 Medium External URL 外部 URL
https://registry.npmmirror.com$ check-env.js:54 Medium External URL 外部 URL
https://registry.npmmirror.com check-env.js:62 Medium External URL 外部 URL
https://api.deepseek.com setup-ai.js:20 Medium External URL 外部 URL
https://open.bigmodel.cn/api/paas/v4 setup-ai.js:28 Medium External URL 外部 URL
https://open.bigmodel.cn setup-ai.js:31 Medium External URL 外部 URL
https://dashscope.aliyuncs.com/compatible-mode/v1 setup-ai.js:36 Medium External URL 外部 URL
https://dashscope.console.aliyun.com setup-ai.js:39 File Tree
5 files · 15.1 KB · 585 lines JavaScript 3f · 425L
Markdown 1f · 124L
JSON 1f · 36L
├─
check-env.js
JavaScript
├─
package.json
JSON
├─
setup-ai.js
JavaScript
├─
SKILL.md
Markdown
└─
test-connection.js
JavaScript
Security Positives
✓ 代码实现与声明功能100%一致
✓ 无混淆编码或隐藏执行逻辑
✓ 网络请求仅发送到官方API端点
✓ 文件操作仅限于~/.openclaw/目录
✓ 不访问敏感路径如~/.ssh、~/.aws等
✓ 无第三方依赖,无供应链风险