安全扫描
OpenClaw
安全
high confidenceThis skill is internally coherent: it wraps Bitrise through the Membrane platform and its instructions consistently require installing and using the Membrane CLI and a Membrane account rather than asking for unrelated credentials or system access.
评估建议
What to consider before installing: 1) This skill delegates Bitrise access to the Membrane platform — you will authenticate to Membrane and Membrane will proxy Bitrise requests, so verify you trust Membrane with your Bitrise data and credentials. 2) The SKILL.md asks you to install @membranehq/cli from npm (or use npx); review the npm package and the upstream repository (https://github.com/membranedev/application-skills and the CLI package) to verify authenticity and inspect permissions. 3) Pref...详细分析 ▾
✓ 用途与能力
The skill claims to integrate with Bitrise but consistently directs the agent to use the Membrane platform/CLI to do so. Requesting a Membrane account and CLI is proportionate to that design; there are no unrelated credentials or platform accesses requested.
✓ 指令范围
SKILL.md only instructs running Membrane CLI commands, creating connections, listing actions, running actions, and using Membrane's proxy. It does not ask the agent to read arbitrary files, other env vars, or send data to unexpected endpoints outside Membrane/Bitrise.
ℹ 安装机制
The skill instructs users to install the @membranehq/cli package via npm (global install or npx usage). This is a standard public-registry install but does mean third-party code will be installed on disk; the skill itself has no packaged install spec.
ℹ 凭证需求
No local env vars or credentials are requested by the skill. However, the integration relies on a Membrane account and connections created through Membrane — that centralizes Bitrise credentials and API traffic to Membrane, so trust in Membrane is required.
✓ 持久化与权限
The skill is instruction-only, not always-enabled, does not request persistent system-wide changes or access to other skills' configs, and uses normal user-invocable operations.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/9
Auto sync from membranedev/application-skills
● 无害
安装命令 点击复制
官方npx clawhub@latest install bitrise
镜像加速npx clawhub@latest install bitrise --registry https://cn.clawhub-mirror.com
数据来源:ClawHub ↗ · 中文优化:龙虾技能库
OpenClaw 技能定制 / 插件定制 / 私有工作流定制
免费技能或插件可能存在安全风险,如需更匹配、更安全的方案,建议联系付费定制