Real Skill packageSource verifiedClawHub registry

bailian-ai-toolkit

在用户明确选择阿里云百炼时,使用项目内固定版本的 bl CLI 完成生成、理解、语音、搜索和文件处理任务,并在任何本地文件上传前执行逐文件隐私检查。

Identity and source

Publisher attributionCryptocxfregistry owner unverified by skillvetai
Functional categoryAwaiting category reviewreview pending · 0% rule confidence
Package forminstruction with code5 recorded files
Canonical sourceClawHub registryclawhub:cryptocxf:bailian-ai-toolkit
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/18/2026.claude/skills/bailian-ai-toolkit

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/18/2026.agents/skills/bailian-ai-toolkit

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/18/2026skills/bailian-ai-toolkit

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @cryptocxf/bailian-ai-toolkit
clawhub inspect @cryptocxf/bailian-ai-toolkit --version 1.0.1

Security evidence

SkillVetAI static result: high signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
5 / 5 inspected as text
Checked
9/18/2026, 4:41:00 AM
Scanner
0.1.3
Policy
1.0.3
1 automated finding
highPackage contains a path commonly used for secrets.npmrc · confidence 88%.npmrc
1 High/Critical review queue entry
STATIC_SENSITIVE_FILE_IN_PACKAGEpending
Open human review queue →
2 inferred permission indicators
  • network access — automatically inferred
  • filesystem read — automatically inferred
3 dependency and API indicators
  • npm: bailian-cli 1.26.0
  • api: github.com
  • api: registry.npmjs.org
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/18/2026, 2:13:36 AM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:24a1608f5481f1060393f886684178a6b4540089b025e1f9f9cae5298c4f3858
Show up to 5 recorded paths
  • .npmrc
  • package-lock.json
  • package.json
  • SKILL.md
  • tests/security.test.cjs

Source changelog

**Changelog for bailian-ai-toolkit v1.0.1:** - Rewrote SKILL.md to clarify strict privacy, security, and file handling policies when using bailian-cli, with emphasis on explicit user authorization, local file checks, and credential safety. - Updated usage instructions to require the use of a fixed, project-local version of bailian-cli (v1.26.0) with locked dependencies. - Added formal processes for authentication (favoring OAuth), restricted handling of secrets, and detailed procedures for file uploads and cloud retention. - Introduced new command templates reflecting updated file and credential practices. - Added configuration and lock files (.npmrc, package-lock.json, package.json) and a security test. - Removed skill-card.md.