安全扫描
OpenClaw
安全
high confidenceAn instruction-only Chinese contract-review skill that is internally consistent: it asks for no credentials, contains no code or suspicious install steps, and its instructions align with the stated purpose.
评估建议
This skill appears coherent and low-risk as an instruction-only contract-review helper, but consider the following before installing or using it:
- Privacy: You will likely provide full contract text (may contain PII or confidential business information). Understand where the text is sent (the agent/model provider) and whether you need to redact sensitive details or use a local model.
- Dependency note: SKILL.md mentions "pip install python-docx" but there is no install step in the registry entr...详细分析 ▾
✓ 用途与能力
Name/description (Chinese contract review, risk identification, compliance suggestions) aligns with the content of SKILL.md. The skill does not request unrelated binaries, credentials, or config paths.
✓ 指令范围
Runtime instructions are limited to receiving a user-provided contract, analyzing clauses, citing laws, and producing recommendations/reports. The SKILL.md does not instruct the agent to read unrelated system files, access environment variables, or transmit data to external endpoints beyond normal model usage.
ℹ 安装机制
This is instruction-only and has no install spec (low risk). The SKILL.md mentions a dependency string ("pip install python-docx") in its front-matter, but there is no formal install specification. That is not malicious but may mean .docx parsing won't work automatically in some environments — it's an implementation/integration gap rather than a security problem.
✓ 凭证需求
No environment variables, credentials, or config paths are requested. The absence of sensitive requirements is proportional to a contract-review tool.
✓ 持久化与权限
always is false and the skill is user-invocable (normal). It does not request persistent/system-wide privileges or modify other skills' configs.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/3/28
中国合同审查工具:劳动合同/销售合同/租赁合同/服务合同审查,风险识别,修改建议
● 无害
安装命令
点击复制官方npx clawhub@latest install china-contract-review
镜像加速npx clawhub@latest install china-contract-review --registry https://cn.longxiaskill.com