Token导航 LogoToken导航TokenDH.com
运维执行命令clawhub未标认证来源可访问clear审计通过

osoposop 分析

Agent Skill

osop 用于辅助安全审计、权限检查和凭据风险排查,适合在 OpenClaw 中需要复核安全边界、认证流程或敏感配置时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

3,293

周安装

140

GitHub Stars

公开资料未说明

下载量

1,154
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:osop(osop 分析)
来源仓库:https://github.com/archie0125/osop
安装命令:
openclaw skills install osop
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install osop

简介

osop 用于辅助安全审计、权限检查和凭据风险排查。

  • 适合在 OpenClaw 中复核安全边界、认证流程或敏感配置时使用。
  • 通过 clawhub 安装,提供自动化检查与风险提示功能。
  • 使用前需确认权限范围、维护状态,注意可能触发的文件读写与命令执行。
  • 建议结合日志与策略文档验证检查结果的实际影响。

SKILL.md

name
osop
description
OSOP workflow authoring, validation, risk analysis, and self-optimization for AI agents
version
1.2.0
emoji
\F4CB
homepage
https://osop.ai
metadata
openclaw
requires
anyBins
config
primaryEnv
OSOP_MCP_URL
install
package
pyyaml
always
false
user-invocable
true
disable-model-invocation
false

OSOP — Open Standard Operating Procedures

Universal protocol for defining, validating, risk-assessing, and executing process workflows. Works with any AI coding agent.

Capabilities

When this skill is active, the agent can:

  • Create OSOP workflow definitions from natural language
  • Validate workflow YAML against the OSOP schema
  • Risk Assess workflows for security issues, permission gaps, destructive commands
  • Execute workflows with dry-run mode for safety
  • Render workflows as Mermaid diagrams
  • Optimize workflows using execution history — detect slow steps, failure hotspots
  • Convert between OSOP and external formats (GitHub Actions, BPMN, Airflow)
  • Report on workflow executions as standalone HTML

Sub-Skills

This pack includes 4 specialized skills:

SkillCommandWhat it does
osop-log/osop-logRecord a structured session log after completing work
osop-report/osop-reportConvert .osop + .osoplog.yaml to HTML report
osop-review/osop-reviewSecurity & risk analysis of workflows
osop-optimize/osop-optimizeImprove workflows from execution history

OSOP Node Types (v1.0)

16 supported node types in 4 categories:

Actors: human, agent, company, department Technical: api, cli, db, git, docker, cicd, infra, mcp Flow Control: system, event, gateway, data

Use subtype for domain specialization (e.g., type: agent, subtype: llm).

Edge Modes

13 modes: sequential, conditional, parallel, loop, event, fallback, error, timeout, compensation, message, dataflow, signal, weighted, spawn.

Quick Start

1. Define a workflow

osop_version: "1.0"
id: "deploy-staging"
name: "Deploy to Staging"
description: "Build, test, and deploy to staging environment."
version: "1.0.0"
tags: [deploy, staging]

nodes:
  - id: "build"
    type: "cli"
    name: "Build Project"
    description: "Run the build command"
  - id: "test"
    type: "cicd"
    subtype: "test"
    name: "Run Tests"
    description: "Execute test suite"
  - id: "deploy"
    type: "infra"
    name: "Deploy to Staging"
    description: "Push to staging environment"
    security:
      risk_level: "medium"
      approval_gate: true

edges:
  - from: "build"
    to: "test"
    mode: "sequential"
  - from: "test"
    to: "deploy"
    mode: "conditional"
    when: "tests.passed == true"

2. Review for risks

Run /osop-review deploy-staging.osop to check for security issues before execution.

3. Execute and log

After running, use /osop-log to record what happened as a structured .osoplog.yaml.

4. Generate report

Run /osop-report to create a standalone HTML report with dark mode and expandable nodes.

Session Logging

After completing multi-step tasks, this skill produces:

  • .osop — workflow definition (what should happen)
  • .osoplog.yaml — execution record (what actually happened)

These files can be visualized at https://osop-editor.vercel.app or converted to HTML.

Security Metadata

Nodes can declare security.risk_level (low/medium/high/critical), security.permissions, security.secrets, and approval_gate for risk analysis.

Self-Optimization Loop

  1. Execute workflow → produce .osoplog
  2. Aggregate stats from past runs
  3. Run /osop-optimize → get improvement suggestions
  4. Apply approved changes → execute improved workflow
  5. Repeat — the SOP gets better each iteration

Links

  • Spec: https://github.com/Archie0125/osop-spec
  • Visual Editor: https://osop-editor.vercel.app
  • Examples: https://github.com/Archie0125/osop-examples
  • Website: https://osop.ai

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

98.34%
按下载量换算1,135

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

通过

权限和风险

执行命令

安装流程涉及命令执行,可能通过 openclaw skills install osop 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills