安全扫描
OpenClaw
安全
high confidenceThe skill is an instruction-only narrative-detection helper whose requested resources and runtime instructions align with its stated purpose; no surprising installs, credentials, or external endpoints are requested.
评估建议
This skill appears internally consistent and low-risk: it’s an instruction-only analyzer that doesn’t request credentials, install software, or call external endpoints. Before using it for important decisions, however, consider: 1) provenance — the package files and registry metadata show inconsistent owner/version information (author shown as “Morpheus” but registry owner differs), so prefer skills with clear authors and homepages for high-stakes use; 2) data you feed — don’t paste private cred...详细分析 ▾
ℹ 用途与能力
The skill's name, description, and runtime instructions all describe the same task (classify narratives as signal/noise/manipulation). No unrelated binaries, credentials, or config paths are requested. Note: there are minor provenance inconsistencies in the registry metadata vs packaged files (registry metadata lists a different owner/version than _meta.json and skill.yml), which is not a functional mismatch but reduces provenance reliability.
✓ 指令范围
SKILL.md contains a narrowly scoped, stepwise procedure (identify triggers, asymmetry, verifiability, historical comparison, classification, risk, next checks). It does not instruct the agent to read arbitrary files, access environment variables, or transmit data to external endpoints. Safety rules explicitly discourage assuming malice and making guarantees.
✓ 安装机制
This is an instruction-only skill with no install spec and no code files to execute. That minimizes on-disk risk and there are no download URLs or package installs to review.
✓ 凭证需求
The skill declares no required environment variables, credentials, or config paths, and the instructions do not reference secrets. The requested scope of access is proportionate to a narrative-analysis helper.
ℹ 持久化与权限
always:false (default) and model invocation is enabled (default) — this is the normal configuration for skills. Because the skill has no extra credentials or install behavior, its autonomous-invocation capability does not by itself raise additional concern.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
安装命令
点击复制官方npx clawhub@latest install matrix-detection
镜像加速npx clawhub@latest install matrix-detection --registry https://cn.longxiaskill.com 镜像可用