闲社服务运行正常AI智能体自动化平台
c

ClawHub技能审计

技能标识:clawhub-skill-audit

Audit locally installed skills against ClawHub: detect version drift, find new publish candidates, review security flags, and triage ownership conflicts. Use when: reviewing whether published skills need updates, deciding what new local skills are ready to open-source, investigating hidden/flagged skills on ClawHub, or running the weekly skill lifecycle check.

作者:admin | 来源记录:ClawHub
登记来源
ClawHub
版本
V 1.0.0
检测标记
后台标记通过
免费
免费获取
0
收藏
来源与检测标记为平台登记信息,并不代表已展示可复核的检测报告。使用前请核对版本、依赖和所需权限,建议先在隔离环境中运行。
概述
安装方式
版本历史

ClawHub技能审计

ClawHub 技能审计

维护已发布 ClawHub 技能的健康状态:检测漂移、发现新候选技能、审查安全标记。

使用时机

  • - 每周(澳大利亚东部标准时间周一09:00 — 通过 launchd 自动执行)
  • 当 Nissan 询问我们需要更新 ClawHub 技能吗?时
  • 在发布包含新技能的重大版本之前
  • 当技能出现异常行为,且该问题可能已在较新 ClawHub 版本中修复时

所需工具

  • - clawhub CLI(npm 全局安装:~/.npm-global/bin/clawhub)
  • scripts/skill-lifecycle/drift-detector.py — 版本对比
  • scripts/clawhub_audit.py — 本地安全合规检查
  • scripts/skill-lifecycle/publish-skill.sh — 发布门禁

完整手册

完整分步指南请参见 playbooks/clawhub-skill-lifecycle/PLAYBOOK.md。

快速审计(3条命令)

1. 检查漂移(本地 vs 已发布)

bash /Users/loki/.pyenv/versions/3.14.3/bin/python3 \ ~/.openclaw/workspace/scripts/skill-lifecycle/drift-detector.py

2. 检查隐藏/标记技能

bash for skill in agent-hive llm-eval-router fastapi-studio-template observability-lgtm \ insight-engine fact-checker agent-budget-governance demo-precacher \ gateway-env-injector mistral-agents-orchestrator multi-agent-pipeline \ tweet-humanizer tweet-pipeline notion-content-pipeline security-auditor; do result=$(clawhub inspect $skill 2>&1 | grep -E Owner:|Latest:|hidden|security|flag|pending) echo $skill: $result done

查找:hidden while security scan is pending 或任何标记/警告文本。

3. 查找新候选技能(从未发布)

bash for d in ~/.openclaw/workspace/skills/*/; do name=$(basename $d) has_version=$(grep -m1 ^version: $d/SKILL.md 2>/dev/null | wc -c) published=$(clawhub inspect $name 2>/dev/null | grep Owner: nissan) if [ $has_version -gt 0 ] && [ -z $published ]; then ver=$(grep -m1 ^version: $d/SKILL.md | awk {print $2} | tr -d \) echo 候选技能: $name @ $ver fi done

发布技能更新

bash

1. 在 SKILL.md 前置元数据中更新版本号


2. 添加 CHANGELOG.md 条目


3. 运行发布门禁(检查版本 + 变更日志)


bash ~/.openclaw/workspace/scripts/skill-lifecycle/publish-skill.sh <技能名称>

4. 发布


clawhub publish ~/.openclaw/workspace/skills/<技能名称>

修复安全标记技能

  1. 1. 运行本地合规检查:
bash /Users/loki/.pyenv/versions/3.14.3/bin/python3 \ ~/.openclaw/workspace/scripts/clawhub_audit.py <技能名称>
  1. 2. 修复标记的问题(通常包括:未声明的环境变量、缺少 network.outbound、可疑模式)
  1. 3. 更新补丁版本号,添加 CHANGELOG 条目,重新发布。

所有权冲突

如果 clawhub publish 返回 Error: Only the owner can publish updates:

  • - 该技能从 ClawHub 安装,属于其他账户
  • 不要尝试以相同 slug 重新发布
  • 选项:fork 为 reddi-<名称>,或仅保留本地使用
  • 如需 fork:复制技能目录 → 重命名为 reddi-<名称> → 更新 SKILL.md 中的 name: → 发布新 slug

已知的 nissan 拥有 slug(截至 2026-03-25)

agent-hive, llm-eval-router, fastapi-studio-template, observability-lgtm,
insight-engine, fact-checker, agent-budget-governance, demo-precacher,
gateway-env-injector, mistral-agents-orchestrator, multi-agent-pipeline,
tweet-humanizer, tweet-pipeline, notion-content-pipeline

已知的带有本地改进的社区技能

技能已发布所有者建议操作
humanizerbiostartechnologyFork 为 reddi-humanizer
self-improving-agent
pskoett | 审计差异,然后 fork 或仅本地使用 |

注意事项

  • - clawhub explore 返回空结果 — 请逐个使用 clawhub inspect
  • 技能目录中的 _meta.json = 漂移追踪器。缺失则漂移检测器无法对比。发布后,clawhub 会写入此文件。
  • 安全扫描通常很快(几分钟),但可能需要数小时。隐藏 ≠ 失败 — 请等待后重新检查。
  • 速率限制:每小时最多发布 5 个新技能。按 5 个一组分批操作,组间等待约 60 秒。
  • ClawHub 版本领先本地:fastapi-studio-template、insight-engine、fact-checker、demo-precacher 的已发布版本高于本地。运行 clawhub update 拉取并同步。

标签

skill ai

通过对话安装

以下为平台配置的接入选项,并非逐项实测通过。能否安装取决于客户端支持、技能来源和运行环境:

OpenClaw WorkBuddy QClaw Kimi Claude

方式一:安装 SkillHub 和技能

帮我安装 SkillHub 和 clawhub-skill-audit-1775968631 技能

方式二:设置 SkillHub 为优先技能安装源

设置 SkillHub 为我的优先技能安装源,然后帮我安装 clawhub-skill-audit-1775968631 技能

通过命令行安装

skillhub install clawhub-skill-audit-1775968631

下载

⬇ 下载 clawhub-skill-audit v1.0.0(免费)

文件大小: 2.85 KB | 发布时间: 2026-4-13 09:45

v1.0.0 最新 2026-4-13 09:45
New skill: audit locally installed skills against ClawHub for version drift and security flags
返回顶部