安全扫描
OpenClaw
安全
high confidenceNULL
评估建议
This skill appears coherent and does what it says: it instructs you to use the Membrane CLI to connect to Formstack via OAuth and run proxyed actions. Before installing or running it: verify the Membrane project (@membranehq) and its npm package/GitHub repo (the SKILL.md includes links), review what permissions Membrane requests during the OAuth flow, avoid entering Formstack API keys directly (the skill explicitly advises against that), and be cautious installing global npm packages on shared s...详细分析 ▾
✓ 用途与能力
The name/description (Formstack integration) matches the instructions: all actions are performed via the Membrane CLI which proxies requests to Formstack. There are no unrelated credentials, binaries, or config paths requested.
✓ 指令范围
SKILL.md directs the agent to install and use the Membrane CLI, create connections via interactive OAuth flows, list/run actions, and proxy raw Formstack API requests through Membrane. It does not instruct reading unrelated files, exporting environment variables, or exfiltrating data to unexpected endpoints.
ℹ 安装机制
The skill is instruction-only and recommends installing the Membrane CLI via `npm install -g @membranehq/cli`. NPM global installs execute package install scripts and therefore carry moderate risk compared with no install; however, this is proportional to the stated need to have a CLI. The SKILL.md references an official homepage and GitHub repo which you should verify before installing.
✓ 凭证需求
The skill declares no required environment variables or credentials and relies on Membrane to manage Formstack OAuth. That is proportionate for the stated purpose. Note: actual credentials will be stored/managed by the Membrane CLI after the user authenticates in-browser — verify Membrane's storage/permission behavior if concerned.
✓ 持久化与权限
The skill does not request 'always' presence and uses normal autonomous invocation behavior. It does not attempt to modify other skills or system-wide agent settings in the provided instructions.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.22026/3/27
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install formstack
镜像加速npx clawhub@latest install formstack --registry https://cn.longxiaskill.com