.claude/skills/huawei-cloud-skill-auditRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
Audit Huawei Cloud skills for quality, security, and compliance using a three-check pipeline: skillspector (AI security) and gitleaks (credential leak). Generates structured reports with issue details and fix strategies. Triggers include: "审计技能","技能审计","检查技能质量","扫描技能问题","技能安全审计", "audit skill","check skill quality","scan skills for issues","skill audit", "华为云技能审计","技能合规检查","skill gate","质量门禁","技能检查", "audit huawei cloud skill","verify skill compliance","技能质量检查","跑审计","安全扫描".
These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.
These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.
.claude/skills/huawei-cloud-skill-auditRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
.agents/skills/huawei-cloud-skill-auditRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
skills/huawei-cloud-skill-auditRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
Installation commands are hidden while this fixed release is under an automatic security hold. Review the evidence and canonical source manually.
This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.
rm -rf /curl|shwget|basheval(eval(exec(base64chmod 777This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.
The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.
sha256:79b5cbb36435e55ad15d6060270e36437bfd1595f2e3c2ac6f81b0572541af04references/acceptance-criteria.mdreferences/cli-installation-guide.mdreferences/gitcode-security-scanner.mdreferences/iam-policies.mdreferences/security-audit-guide.mdreferences/verification-method.mdscripts/check_protocol.pyscripts/check_registry.pyscripts/checks/__init__.pyscripts/checks/gitleaks_builtin_check.pyscripts/checks/gitleaks_check.pyscripts/checks/gitleaks_rules.jsonscripts/checks/hwcloud_spec_check.pyscripts/checks/markdownlint_check.pyscripts/checks/runtime_security_check.pyscripts/checks/runtime_security_rules.jsonscripts/checks/skill_quality_rules.jsonscripts/checks/skillcheck_check.pyscripts/checks/skillspector_builtin_check.pyscripts/checks/skillspector_check.pyscripts/checks/skillspector_rules.jsonscripts/ensure_cli.shscripts/hcloud-run.shscripts/install_cli.shscripts/skill_audit.pyskill-card.mdSKILL.mdskillcheck.toml**Expanded to a three-check security pipeline with new runtime detection.** - Added a third check: runtime_security (36 CWE-based runtime patterns + 3 skill-quality rules). - Upgraded skillspector to 51 rules / 609 patterns (was 47/439). - Updated gitleaks integration to 42 rules (was 222, now high-confidence only). - Workflow now always executes all 39 runtime_security rules, regardless of scan level. - Documentation and command options updated to reflect stricter AST and severity handling. - Telemetry opt-out changed from `SKILL_QUALITY_REPORT=0` to `SKILL_QUALITY_DISABLE=1`.