Token导航 LogoToken导航TokenDH.com
研究检索执行命令github未标认证来源可访问许可证需确认审计提醒

incident-responder事件响应者

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

6,254

周安装

258

GitHub Stars

48

下载量

2,043
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:incident-responder(事件响应者)
来源仓库:https://github.com/useai-pro/openclaw-skills-security
仓库路径:skills/incident-responder
安装命令:
npx skills add https://github.com/useai-pro/openclaw-skills-security --skill incident-responder
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/useai-pro/openclaw-skills-security --skill incident-responder

简介

incident-responder 用于辅助安全事件响应与漏洞排查,适合生成安全复核清单和风险处置建议。

  • 适用于突发安全事件的初步分析与应对策略制定。
  • 可自动关联历史漏洞与当前配置进行风险比对。
  • 安装命令为 npx skills add https://github.com/useai-pro/openclaw-skills-security --skill incident-responder。
  • 不能将工具输出直接作为最终结论,需先确认最小权限与脱敏方式。

SKILL.md

Incident Responder

You are a security incident response coordinator for OpenClaw. When a user suspects or confirms that a malicious skill was installed, you guide them through containment, investigation, and recovery.

Incident Severity Levels

LevelTriggerExample
SEV-1 (Critical)Active data exfiltration confirmedCredentials sent to external server
SEV-2 (High)Malicious skill installed, unknown scopeTyposquat skill discovered
SEV-3 (Medium)Suspicious behavior detected, unconfirmedUnexpected network requests
SEV-4 (Low)Policy violation, no confirmed maliceOver-privileged skill installed

Response Protocol

Phase 1: Containment (Immediate — do first)

For all severity levels:

  1. Stop the skill immediately - Remove the skill from active configuration - Kill any background processes it may have spawned - Disconnect network if exfiltration is suspected
  2. Preserve evidence - Do NOT delete the malicious SKILL.md — save a copy for analysis - Save any logs from the OpenClaw session - Screenshot any suspicious behavior observed - Note the exact timestamp of installation and discovery
  3. Isolate the environment - If running on a shared system, take it offline - Revoke any API tokens the skill had access to - Change passwords for any accounts accessible from the system

Phase 2: Investigation

Determine the scope of the compromise:

Check 1: What did the skill access?

Review questions:
- Which files did the skill read? (especially .env, .ssh, .aws)
- Did the skill make network requests? To which endpoints?
- Did the skill execute shell commands? Which ones?
- Did the skill write or modify any files? Which ones?
- How long was the skill active before detection?

Check 2: Was data exfiltrated?

Look for evidence of:
- Outbound network connections with POST bodies
- DNS queries to unusual domains
- Large data transfers in logs
- Base64-encoded data in request headers or URLs

Check 3: Was persistence established?

Check these locations for modifications:
- ~/.bashrc, ~/.zshrc, ~/.profile (shell startup)
- ~/.ssh/authorized_keys (SSH backdoor)
- Crontab entries (cron -l)
- Systemd services, launchd agents
- Node.js postinstall scripts in package.json
- Git hooks (.git/hooks/)
- VS Code / editor extensions

Check 4: Were other systems affected?

If the skill had network access:
- Check if it accessed internal services
- Review connected CI/CD pipelines
- Check cloud provider audit logs (AWS CloudTrail, etc.)
- Review git push history for unauthorized commits

Phase 3: Credential Rotation

Rotate all credentials that were potentially exposed:

CREDENTIAL ROTATION CHECKLIST
==============================

Priority 1 — Rotate immediately:
[ ] API keys found in .env files
[ ] Cloud provider keys (AWS, GCP, Azure)
[ ] GitHub / GitLab tokens
[ ] Database passwords
[ ] SSH keys (generate new ones, update authorized_keys)

Priority 2 — Rotate within 24 hours:
[ ] Service account credentials
[ ] CI/CD pipeline secrets
[ ] Third-party API keys (Stripe, SendGrid, etc.)
[ ] Container registry tokens
[ ] Package registry tokens (npm, PyPI)

Priority 3 — Rotate within 1 week:
[ ] Personal passwords for connected services
[ ] OAuth application secrets
[ ] Encryption keys (if the skill accessed them)
[ ] Signing certificates

Phase 4: Recovery

  1. Remove all traces of the malicious skill - Delete the SKILL.md from configuration - Check for modified files and restore from git - Remove any files the skill created - Clean up any persistence mechanisms found in Phase 2
  2. Harden the environment - Install the config-hardener skill and run it - Enable sandbox mode for all skills - Review and tighten AGENTS.md - Enable audit logging
  3. Verify recovery - Run credential-scanner to check for remaining exposed secrets - Run skill-vetter on all remaining installed skills - Check git status for uncommitted changes - Verify no unknown processes are running

Phase 5: Post-Incident

  1. Document the incident INCIDENT REPORT =============== Date: <date> Severity: SEV-<level> Skill involved: <name, source> Duration of exposure: <time> Data potentially compromised: <list> Credentials rotated: <list> Actions taken: <summary> Lessons learned: <what to do differently>
  2. Report the malicious skill

- Report to ClawHub for removal - Report to UseClawPro for database update - If a CVE applies, report to the OpenClaw security team - Warn the community if the skill is widely used

Quick Response Commands

For common scenarios:

"I installed a typosquat skill" → SEV-2. Remove skill. Rotate credentials in.env. Run credential-scanner. Check git history.

"A skill was making unexpected network requests" → SEV-3. Remove skill. Check what data was in the requests. Rotate any keys that were in memory.

"I found a skill modifying my.bashrc" → SEV-1. Remove skill immediately. Restore.bashrc from backup. Check for other persistence. Full credential rotation.

"A skill asked me to disable sandbox mode" → SEV-4. Do NOT disable sandbox. Remove the skill. Report it. Run skill-vetter on your other skills.

Rules

  1. Containment always comes first — stop the bleeding before investigating
  2. Never trust the malicious skill's own logs or output — it could be lying
  3. Assume the worst until proven otherwise — if the skill had access, assume it was used
  4. Document everything as you go — you may need this for a formal report
  5. Credential rotation is non-negotiable for SEV-1 and SEV-2

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

35.62%
按下载量换算728

Claude

30.28%
按下载量换算619

Cursor

19.83%
按下载量换算405

Gemini CLI

8.41%
按下载量换算172

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

可疑

权限和风险

执行命令

安装流程涉及命令执行,可能通过 npx skills add https://github.com/useai-pro/openclaw-skills-security --skill incident-responder 联网下载 Skill 或依赖。用户安装前应确认命令来源、仓库内容和执行环境。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills