Higher means the install surface and source context are easier to review.
Security Dashboard
How we make skill installs safer
安全页会把安装来源、复核线索、风险分布和最近被标记的 skills 放到同一个 dashboard 里,而不是只给一列低分列表。
目标不是制造恐慌,而是让用户更快看出哪些技能可以放心安装,哪些需要暂停和人工复核。
Count of skills that deserve extra manual review.
The review stream helps identify which skills deserve a deeper audit.
Creator and security pages share the same aggregate view.
How we make skill installs safer
1
公开来源优先
source repo、作者和安装入口必须能互相对应,减少黑箱安装。
source repo、作者和安装入口必须能互相对应,减少黑箱安装。
2
风险集中展示
低分、问题分类和最近标记项不会藏在详情页深处。
低分、问题分类和最近标记项不会藏在详情页深处。
3
复核优先级明确
真正需要人工看一眼的 skills 会被推到同一个 review queue。
真正需要人工看一眼的 skills 会被推到同一个 review queue。
Exactly what we do to improve security
1
收口安装说明
把入口命令、平台标签和 repo 线索统一到同一个 surface。
把入口命令、平台标签和 repo 线索统一到同一个 surface。
2
追踪问题分类
把模板注入、缺少来源、结构风险等问题聚合展示。
把模板注入、缺少来源、结构风险等问题聚合展示。
3
持续刷新队列
最近标记、低分项和评论流会一起更新 review 优先级。
最近标记、低分项和评论流会一起更新 review 优先级。
Safest install surfaces
receiving-code-review
@obra · Use when receiving code review feedback, before implementing suggestions, especially if feedback seems unclear or technically questionable...
Quality
100
Security
100
verification-before-completion
@obra · Use when about to claim work is complete, fixed, or passing, before committing or creating PRs - requires running verification commands and...
Quality
100
Security
100
finishing-a-development-branch
@obra · Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development wo...
Quality
100
Security
100
frontend-slides
@affaan-m · Create stunning, animation-rich HTML presentations from scratch or by converting PowerPoint files.
Quality
100
Security
100
investor-materials
@affaan-m · Create and update pitch decks, one-pagers, investor memos, accelerator applications, financial models, and fundraising materials.
Quality
100
Security
100
design-system-patterns
@wshobson · Build scalable design systems with design tokens, theming infrastructure, and component architecture patterns.
Quality
100
Security
100
Needs review next
BrowserWing Executor API
@openclaw · Enables comprehensive browser automation through HTTP APIs for navigation, interaction, data extraction, and accessibility analysis.
Quality
0
Security
0
Clawdmint 🦞
@openclaw · Facilitates the deployment of NFT collections on Base, allowing AI agents to manage collections and humans to mint easily.
Quality
0
Security
0
4chad 🐸
@openclaw · Enables autonomous trading and token launching on Solana with AI agents, allowing users to manage assets and claim fees securely.
Quality
0
Security
0
Claw Me Maybe - Beeper Desktop API & Multi-Platform Messaging 📟
@openclaw · Integrates Beeper for unified messaging across multiple platforms, enabling seamless communication and chat management.
Quality
0
Security
0
openclaw-defender
@openclaw · **Comprehensive security framework for OpenClaw agents against skill supply chain attacks.**
Quality
0
Security
0
Tinman - AI Failure Mode Research
@openclaw · Tinman is an AI security scanner that identifies unknown failure modes in AI systems through systematic experimentation and self-protection...
Quality
0
Security
0
Severity distribution
issues
issues
issues
Top issue categories
暂无问题分类。
Low security skills
BrowserWing Executor API
@openclaw · Enables comprehensive browser automation through HTTP APIs for navigation, interaction, data extraction, and accessibility analysis.
Quality
0
Security
0
Clawdmint 🦞
@openclaw · Facilitates the deployment of NFT collections on Base, allowing AI agents to manage collections and humans to mint easily.
Quality
0
Security
0
4chad 🐸
@openclaw · Enables autonomous trading and token launching on Solana with AI agents, allowing users to manage assets and claim fees securely.
Quality
0
Security
0
Claw Me Maybe - Beeper Desktop API & Multi-Platform Messaging 📟
@openclaw · Integrates Beeper for unified messaging across multiple platforms, enabling seamless communication and chat management.
Quality
0
Security
0
Recently flagged for review
botmadang
@openclaw · 봇마당(botmadang.org) - AI 에이전트 커뮤니티 플랫폼.
Quality
75
Security
25
clawdtalk-client
@openclaw · ClawdTalk — Voice calls, SMS, and AI Missions for Clawdbot
Quality
75
Security
68
ai-avatar-video
@NeverSight · Create AI avatar and talking head videos with OmniHuman, Fabric, PixVerse via inference.sh CLI.
Quality
92
Security
63
ABM Outbound
@openclaw · Multi-channel ABM automation that turns LinkedIn URLs into coordinated outbound campaigns.
Quality
67
Security
54
Security Issues
低分项通常对应安装源不清晰、缺少复核线索或需要进一步人工审计。