Skills Plugins MCP Prompt Model 导航 博客 资讯 我的中心
安全与权限 #ai-agent#audit#openclaw#scanner#security#skill

skill-security-guard

skill-security-guard 静态扫描器的 DSH 社区 Bundle:对技能包做 7 维确定性扫描、A-F 风险评级并给出修复建议。

rrrrrredy @rrrrrredy ⬇ 1 ★ 1 main

安装

dsh plugin --profile web add github:rrrrrredy/skill-security-guard
下载安装清单

需要可复现安装时,可在仓库后追加 #commit 固定提交。

skill-security-guard 静态扫描器的 DSH 社区 Bundle:对技能包做 7 维确定性扫描、A-F 风险评级并给出修复建议。

该插件未提供要点说明,请参考仓库 README。

ai-agentauditopenclawscannersecurityskill
  1. 安装并启动 DeepSeek Harness:npx @deepseek-ai/dsh web
  2. 在终端执行上面的安装命令(CLI 会解析插件并核验来源)
  3. 用 dsh plugins list 确认已安装,必要时重启 Harness 生效

插件以当前 dsh 进程的权限运行,安装时可能执行代码。请先通读仓库源码与许可证,确认无破坏性命令与越权访问;本站只做索引,不对第三方插件安全性作担保。

代码仓库github.com/rrrrrredy/skill-security-guard
许可证MIT
主要语言main
下载量1
GitHub 星标1
最近推送2026-08-17
收录日期2026-09-19
分类安全与权限

事实信息来自公开插件目录快照(2026-10-01),介绍文案由本站再加工。

以下为插件仓库 README 全文(原始内容,由公开目录抓取整理)。

# skill-security-guard

[![CI](https://github.com/rrrrrredy/skill-security-guard/actions/workflows/ci.yml/badge.svg)](https://github.com/rrrrrredy/skill-security-guard/actions/workflows/ci.yml)
[![License: MIT](https://img.shields.io/badge/License-MIT-yellow.svg)](LICENSE)
[![Python](https://img.shields.io/badge/python-3.10%2B-blue.svg)](https://www.python.org/)

Static security scanner for agent skill packages.

`skill-security-guard` performs a deterministic 7-dimension scan, assigns an A-F risk rating, reports confidence levels, and gives remediation guidance. The CLI uses only the Python standard library, so it runs on Windows, macOS, and Linux without project dependencies.

It can be used as an OpenClaw skill, as a DeepSeek Harness community Bundle, or as a standalone scanner for local skill packages.

## What It Scans

- Prompt-injection and instruction-override patterns
- Sensitive file reads and data exfiltration patterns
- Compliance red lines such as tunneling, restricted-system access, highly sensitive data handling, and sensitive config backup/upload
- Malicious script patterns in `scripts/`
- Dependency installation from non-default or suspicious sources
- Over-broad or unclear `description` trigger scopes
- Frontmatter compliance (`name` and `description`)

## Quick Start

```bash
git clone https://github.com/rrrrrredy/skill-security-guard.git
cd skill-security-guard

python scripts/scan.py path/to/SKILL.md
python scripts/scan.py path/to/skill-directory
python scripts/scan.py path/to/skills.zip
python scripts/scan.py --text "inline skill text"
```

Shell wrapper:

```bash
bash scripts/scan.sh path/to/skill-directory
```

JSON output:

```bash
python scripts/scan.py path/to/skill-directory --format json
```

Ignore a reviewed rule for one run:

```bash
python scripts/scan.py path/to/skill-directory --ignore R3-N5
```

## Example Output

Safe skill:

```text
Skill Security Report: safe-skill
Rating: A (100/100)

Issues: none

Passed dimensions:
- Prompt injection
- Sensitive file access / data exfiltration
- Compliance violations
- Malicious scripts
- Dependency safety
- Description trigger reasonability
- Frontmatter compliance
```

High-risk skill:

```text
Skill Security Report: high-risk-skill
Rating: F (0/100)

Issues (5):
- [high/confirmed] M4-REMOTE-SCRIPT-EXEC: Remote script execution detected
- [high/confirmed] S2-EXFILTRATION: Sensitive data exfiltration pattern detected
- [medium/confirmed] P1-PROMPT-INJECTION: Prompt-injection instruction detected
```

## Input Support

- `SKILL.md` or any local text/code file
- Skill directory containing one or more `SKILL.md` files
- `.zip` packages, extracted with path traversal checks and size/file-count limits
- `-` for stdin
- `--text` for inline text
- Public `http://` or `https://` text URLs, capped by response size and timeout

Directory and zip scans include `SKILL.md` and files under `scripts/` by default. Reference docs are skipped to reduce false positives; use `--include-references` when you explicitly want to scan reference markdown too.

## Requirements

- Python 3.10+
- No runtime package dependencies

The scanner CI job tests Python 3.11 and 3.12 on Ubuntu. The DeepSeek Harness Bundle job tests Node.js 22.19 and 24 on both Ubuntu and Windows with Python 3.11.

## DeepSeek Harness

The `dsh-skill-security-guard` community Bundle registers this repository's existing `SKILL.md` through the native Cordis Skill Provider API. It packages the same scanner and detection rules rather than maintaining a second implementation.

After the package is published, install it into a profile:

```bash
dsh plugin --profile headless add dsh-skill-security-guard@0.1.0
dsh --profile headless --dump-config
dsh --profile headless "Use skill-security-guard to scan ./path/to/a-skill."
```

Then ask the agent to use `skill-security-guard` to scan a file, directory, zip, URL, or inline skill text. Python 3.10+ is required when the scanner runs. See [`integrations/deepseek-harness`](integrations/deepseek-harness) for compatibility, privacy boundaries, local package verification, and uninstall instructions.

This is a community plugin, not an official DeepSeek plugin.

## Rating Model

- `A`: no findings
- `B`: advisory-only or light findings
- `C`: medium-risk findings that should be reviewed
- `D`: multiple confirmed medium-risk findings or serious degradation
- `F`: direct high-risk finding, such as exfiltration, tunneling, destructive commands, or remote script execution

The exact detection patterns and scoring rules live in [`references/detection-rules.md`](references/detection-rules.md).

## Development

Run tests:

```bash
python -m unittest discover -s tests -p "test_*.py"
```

Run sample scans:

```bash
python scripts/scan.py tests/fixtures/safe-skill
python scripts/scan.py tests/fixtures/high-risk-skill
```

Run the scanner against this repository:

```bash
python scripts/scan.py .
```

## Project Structure

```text
skill-security-guard/
├── SKILL.md
├── scripts/
│   ├── scan.py
│   └── scan.sh
├── references/
│   └── detection-rules.md
├── tests/
│   ├── fixtures/
│   └── test_scan.py
└── .github/workflows/ci.yml
```

The DeepSeek Harness integration, including its package manifest, source, build scripts, and tests, lives in [`integrations/deepseek-harness`](integrations/deepseek-harness).

## Limits

This is a static scanner. It does not execute skills, monitor runtime behavior, prove package provenance, or replace human security review. Findings are intentionally conservative and should be reviewed before blocking a skill.

## Contributing

Contributions are welcome. See [CONTRIBUTING.md](CONTRIBUTING.md) for local development and rule-design guidance.

For vulnerability reports, see [SECURITY.md](SECURITY.md).

## License

[MIT](LICENSE)

数据来源:公开的 DeepSeek Harness 插件目录与各插件 GitHub 仓库。本站为独立第三方目录,与 DeepSeek、幻方(High-Flyer)及插件作者均无隶属或背书关系。

每日精选 Skill 推荐,免费送到你邮箱

输入邮箱,每天接收一个精选 AI Agent 技能推荐。完全免费,持续更新。

提交后我们会发送一封确认邮件,点击邮件里的链接才会开始收信。

完全免费,取消任意时间。我们不会发送垃圾邮件。