下载技能包
最后更新
2026/3/27
安全扫描
OpenClaw
可疑
medium confidenceNULL
评估建议
This skill's goal (automatic system monitoring) is reasonable, but its instructions are vague about how checks/reporting/fixes are performed. Before installing or enabling this skill: 1) Require the author to specify exact check commands, required binaries/tools, and whether elevated privileges (sudo) are needed. 2) Require explicit, auditable reporting endpoints (where alerts go) and ensure no external endpoints are implicit. 3) Disable fully autonomous remediation or require explicit confirmat...详细分析 ▾
⚠ 用途与能力
Name/description (主动监控系统状态) align with the instructions to check disk, memory, CPU, network, and processes. However, the SKILL.md promises automatic remediation ('可以自动修复的立刻处理') yet the skill declares no required binaries, privileges, or configuration — a mismatch. Automatic fixes typically require specific tools, commands, or elevated privileges (sudo), which are not documented here.
⚠ 指令范围
Instructions are high-level and allow the agent to 'periodically check' many system aspects and '主动告警' and '自动修复' without specifying how to collect metrics, what commands to run, which files/paths to read, or where to send reports. That vagueness grants the agent broad discretion to run commands or read system state beyond what's necessary for safe monitoring.
✓ 安装机制
This is an instruction-only skill with no install spec and no code files — low install risk. Nothing will be written to disk by an installer. The risk arises from runtime actions the agent may take following the instructions, not from any installation steps.
ℹ 凭证需求
No environment variables, credentials, or config paths are requested — this limits explicit exfiltration risk. At the same time, the agent's runtime instructions imply it may need privileged access or external reporting endpoints (not declared), so the absence of declared requirements is notable and reduces transparency about where alerts or fixes might be sent or what privileges are needed.
⚠ 持久化与权限
always:false (good) and autonomous invocation is allowed (default). Autonomous invocation combined with unspecified automatic remediation increases risk because the agent could take corrective actions without explicit per-action approval. The skill also does not define safeguards like approval prompts, dry-run modes, or an allowlist of remediation actions.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/3/27
NULL
● Pending
安装命令
点击复制官方npx clawhub@latest install auto-monitor-zhouli
镜像加速npx clawhub@latest install auto-monitor-zhouli --registry https://cn.longxiaskill.com