安全扫描
OpenClaw
安全
high confidenceNULL
评估建议
This skill appears internally consistent and low-risk because it's a collection of Markdown rules, templates, and guidance with no installs or credential requests. Before enabling: 1) Verify the source repository (metadata lists a GitHub URL and an author) if you want provenance or to check licensing/attribution; 2) Review a few templates and code examples to confirm they are copy-pasteable and appropriate for your stack (the framework emphasizes runnable examples and CI testing); 3) Note the sk...详细分析 ▾
✓ 用途与能力
The skill is a documentation framework (Diataxis + style guides + templates). It declares no binaries, no environment variables, no config paths, and contains many Markdown reference/rule files — all of which are appropriate for a docs framework. Nothing requested by the skill appears unrelated to its stated purpose.
ℹ 指令范围
SKILL.md and companion files instruct the agent to use the included rules and templates as the source of truth for writing/planning/auditing docs. This is coherent for the skill's purpose. One thing to note: the skill explicitly tells the agent not to fall back on other training data when those conflict with its rules—this is a functional design choice (not a security risk) but could cause the agent to prefer the skill's guidance over other trusted sources. The instructions do not ask the agent to read or transmit external secrets or system files.
✓ 安装机制
No install spec and no code files that execute — the skill is instruction-only (Markdown files). That results in minimal disk/write risk. All included files are documentation text; there are no download URLs, extracted archives, or package installs to evaluate.
✓ 凭证需求
The skill requires no environment variables, no credentials, and no config paths. There are no requests for sensitive tokens or unrelated service keys. The requested resources are proportionate to a documentation/template skill.
✓ 持久化与权限
The skill is not marked always:true and does not request persistent or system-wide privileges. It is agent-invocable by default (disable-model-invocation is false), which is normal for skills; however user-invocable is false and agentic is false per the metadata. There is no indication it modifies other skills or global configuration.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.12026/3/5
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install developer-docs-framework
镜像加速npx clawhub@latest install developer-docs-framework --registry https://cn.longxiaskill.com