Token导航 LogoToken导航TokenDH.com
研究检索执行命令clawhub未标认证来源可访问clear审计提醒

fenz-skill-auditor芬兹技能审核员

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

9,160

周安装

367

GitHub Stars

1

下载量

2,965
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:fenz-skill-auditor(芬兹技能审核员)
来源仓库:https://github.com/yangran/fenz-skill-auditor
安装命令:
openclaw skills install fenz-skill-auditor
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install fenz-skill-auditor

简介

fenz-skill-auditor 审核 GitHub 存储库中 Claude 技能的安全性与合规性。

  • 适合在 OpenClaw 中生成双语审计报告与最佳实践建议。
  • 通过 openclaw skills install fenz-skill-auditor 命令安装。
  • 不能将输出直接作为最终结论,需人工复核关键结果。
  • 适用宿主包括 OpenClaw,接入前应确认版本、权限和运行环境要求。

SKILL.md

name
skill-audit
description
>-

Skill Audit Workflow

Audit a Claude skill from a GitHub repository. Evaluate effectiveness, token usage, time complexity, permissions, safety, and best-practice compliance. Produce a structured audit report.

Step 1: Clone & Extract

Run the clone script with the user-provided GitHub URL:

bash scripts/clone_and_extract.sh <repo-url>

The script outputs JSON listing all SKILL.md files found. If multiple skills exist in the repo, present the list to the user and ask which one(s) to audit.

If the script exits with a non-zero code:

  • Exit 1: Ask the user to provide a valid GitHub URL
  • Exit 2: Check if the repo exists and is public
  • Exit 3: The repo has no SKILL.md files — inform the user

Step 2: Create Output Directory

Create the audit output directory:

audits/<skill-name>-<YYYYMMDD-HHMMSS>/

Write metadata.json with:

{
  "repo_url": "<url>",
  "timestamp": "<ISO 8601>",
  "auditor": "Fenz.AI",
  "skill_name": "<name>",
  "skill_path": "<path within repo>"
}

Step 3: Save Source Files

Copy all files from the skill directory (the directory containing SKILL.md and its subdirectories) into source/ within the output directory. Then clean up the temp clone directory.

Step 4: Analyze

Read references/audit-criteria.md for detailed rubrics. Evaluate each category:

4a. Effectiveness

Read the skill's SKILL.md and evaluate:

  • Description quality (WHAT + WHEN)
  • Trigger clarity and coverage
  • Workflow definition clarity
  • Examples for complex steps
  • Error handling guidance

Rate: Strong / Adequate / Weak

4b. Token Usage

Run the analysis script:

python3 scripts/analyze_tokens.py <source-dir>

Use the JSON output to assess:

  • SKILL.md line count
  • Progressive disclosure usage
  • Total token footprint
  • Category breakdown

Rate: Low / Medium / High

4c. Time Spending

Evaluate the workflow for:

  • Complexity and branching
  • Number of external tool calls
  • User interaction requirements
  • Scope clarity

Rate: Quick / Moderate / Extended

4d. Permissions

Check the skill for:

  • allowed-tools in frontmatter — what tools are requested?
  • Whether each tool is justified by the workflow
  • Destructive tool usage (Bash without restrictions, Write to system paths)
  • Network access scope
  • File system access scope

Flag any red flags. Rate: Minimal / Moderate / Broad

4e. Safety

Evaluate:

  • Does behavior match the description?
  • Network access patterns
  • File scope boundaries
  • Sensitive data handling
  • Input validation (especially for shell commands)

Rate: Low Risk / Medium Risk / High Risk

4f. Recommendations

Read references/skill-best-practices.md and check the skill against each item. Group findings by priority:

  • High: Safety, correctness, major effectiveness issues
  • Medium: Efficiency, maintainability issues
  • Low: Style and convention suggestions

Step 5: Generate Report

Read assets/audit-report-template.md and fill in all template fields with the analysis results. Save as audit-report.md in the output directory.

Include:

  • All six category ratings with detailed explanations
  • Specific evidence from the skill files for each finding
  • Concrete, actionable recommendations
  • Positive observations (what the skill does well)
  • File appendix with token estimates

Step 6: Log Everything

Maintain process-log.md in the output directory. Append each step as it completes:

## [YYYY-MM-DD HH:MM:SS] Step N: <step name>
- Status: success/failed/skipped
- Details: <what happened>
- Errors: <if any>

Step 7: Generate Social Media Posts

Automatically generate posts from the audit report.

  1. Run: python3 ../post-generator/scripts/extract_findings.py <audit-dir>/audit-report.md
  2. Read ../post-generator/references/writing-guide-en.md and ../post-generator/assets/post-template-twitter-en.md
  3. Generate 2-3 English post variations following the guide
  4. Read ../post-generator/references/writing-guide-zh.md and ../post-generator/assets/post-template-twitter-zh.md
  5. Generate 2-3 Chinese post variations (NOT translations — independently crafted)
  6. Save posts-en.md and posts-zh.md in the audit output directory
  7. Log post generation step to process-log.md

Quality rules:

  • Posts must sound human-written, not AI-generated
  • No banned phrases (see writing guides for anti-pattern lists)
  • Fenz.AI mentioned once, naturally, first post only
  • Max 2 hashtags, no emoji spam
  • English: professional/conversational; Chinese: direct/opinionated with full-width punctuation

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

70.51%
按下载量换算2,091

安全审计

VirusTotal

通过

ClawScan

可疑

Static analysis

通过

权限和风险

执行命令

安装流程涉及命令执行,可能通过 openclaw skills install fenz-skill-auditor 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills