References
全方位安全审计技能。检查文件权限、环境变量、依赖漏洞、配置文件、网络端口、Git 安全、Shell 安全、macOS 安全、密钥检测等。支持 CLI 参数、JSON 输出、配置文件。当用户要求"安全检查"、"漏洞扫描"、"权限检查"、"安全审计"时使用此技能。
v1.0.0
2026/03/23
SX-security-audit v1.0.0 introduces a comprehensive skill for security audits on files, code, dependencies, and systems. - Performs checks on file permissions, world-writable files, dependencies, environment variables, git ignore/security, network ports, shell and macOS security, and secret/key leaks. - Supports CLI usage with selectable modules, severity filtering, JSON output, and custom configuration files. - Integrates precise key/secret detection with regex and entropy checks; covers AWS, GitHub, Slack, OpenAI, JWT, and private keys. - Generates rich, filterable reports with summaries, actionable findings, and can send results in multiple formats to Feishu. - Configuration supports path exclusions, severity thresholds, report formatting, and flexible report delivery via Feishu plugin or webhook.
Security Scan
状态
suspicious
OpenClaw
gpt-5.5
OpenClaw 分析
The main security-audit tool is plausible, but the package also contains undisclosed unrelated scripts that can send chat messages and process payment files.
置信度: high