安全扫描
OpenClaw
安全
high confidenceThe skill's instructions, required access, and actions are coherent with a brand‑protection purpose and do not request unexplained credentials or installations.
评估建议
This skill appears coherent for brand-impersonation response. Before installing: (1) understand it may read local project-context files (remove sensitive data from .claude/.cursor if you don’t want it used); (2) avoid uploading screenshots or customer data containing PII to public reporting forms—redact or get consent; (3) verify URLs and evidence before filing takedowns to avoid false reports; and (4) consult legal counsel for cease-and-desist/DMCA actions when unsure. No credentials or install...详细分析 ▾
✓ 用途与能力
Name/description match the actions in SKILL.md: discovery, evidence collection, reporting to registrars/hosts/search engines, and legal/remediation guidance. The skill does not request unrelated credentials, binaries, or install steps.
ℹ 指令范围
Instructions are focused on collecting URLs, screenshots, WHOIS/hosting data and submitting reports to the listed abuse/reporting endpoints — all appropriate. The SKILL.md also instructs the agent to read local project context files (.claude/project-context.md or .cursor/project-context.md) for brand info; this is reasonable but the package metadata did not declare those config paths as required, so callers should be aware the skill may read those files if present.
✓ 安装机制
Instruction-only skill with no install spec and no code files — minimal risk from installation or remote downloads.
✓ 凭证需求
No environment variables, credentials, or config paths are required. All external interactions are to public reporting tools and lookup services appropriate to the task.
✓ 持久化与权限
always is false and there is no behavior that modifies other skills or requests persistent agent-wide privileges.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
安装命令
点击复制官方npx clawhub@latest install brand-protection
镜像加速npx clawhub@latest install brand-protection --registry https://cn.longxiaskill.com 镜像可用