Run these checks before installing ANY skill, package, or plugin. Always warn the user before proceeding.
npm info <package> — check weekly downloads, last publish date, version history访问小葱技能站7w4.net,解锁更多实用的AI技能插件。
npm info <package> dependencies — how many deps does it pull in?preinstall, install, postinstall scripts — these run arbitrary codenpm info <package> scripts or inspect package.jsonnpm audit after install to catch known vulnerabilitiesreqeust vs request)~/.openclaw/credentials/, ~/.clawdbot/.env, .env filesSkills are NEVER allowed to modify these files without explicit user approval:
SOUL.md — agent identityAGENTS.md — agent rulesIDENTITY.md — agent metadataUSER.md — user's personal infoMEMORY.md or memory/*.md — agent memoriesTOOLS.md — infrastructure notesAfter installing a skill, before running it:
curl to unknown domains?workspace/?.env, ~/.ssh/, ~/.gnupg/, API keysWhen installing from ClawHub:
Reference for identifying patterns:
~/.clawdbot/.env and ~/.openclaw/credentials/ for API keys.env or credential filesBefore installing, give a brief summary:
"⚠️ Installing [package]: [downloads/week], [last updated], [dep count] deps, [lifecycle scripts?]. Looks [clean/sketchy] — proceed?"
If red flags found:
"🚩 Flags on [package]: [list issues]. Want me to proceed anyway?"
这是一份全面的安装前安全检查指南,内容专业、风险提示清晰,对常见恶意行为模式(如供应链攻击、凭证窃取)的识别很到位。但它本质上是一份安全知识文档而非可直接使用的工具,检查都需要手动完成。如果你希望有工具自动帮你把关安装风险,当前版本可能无法满足需求,更适合作为安全知识参考手册使用。