Real Skill packageSource verifiedClawHub registry

enterprise-skills-studio

一套通用、跨平台的"技能工程台",把企业最佳实践、业务流程与个人经验,结构化为 Agent 可调用、可治理、可复用的能力模块(受治理的业务工作流制品)。产出遵循 agentskills.io 开放标准,可在 WorkBuddy、Codex等桌面 Agent 间移植。覆盖技能全生命周期:学习理解 → 构建设计 → 个人转企业级 → 治理审查 → 安全审计 → 持续进化 → 跨平台适配 → 门户分发。内置 24 个能力模式 + 16 个可脚本工具,ROI 筛选、查重、评测套件等。安全侧借鉴SkillSpector 方法论,融合16 类审计与多种安全策略。支持自更新钉置,企业可禁用写盘或限定可信源。

Identity and source

Publisher attributionjiwei1122registry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 60% rule confidence
Package forminstruction with code46 recorded files
Canonical sourceClawHub registryclawhub:jiwei1122:enterprise-skills-studio
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 8/27/2026.claude/skills/enterprise-skills-studio

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 8/27/2026.agents/skills/enterprise-skills-studio

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 8/27/2026skills/enterprise-skills-studio

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @jiwei1122/enterprise-skills-studio
clawhub inspect @jiwei1122/enterprise-skills-studio --version 1.1.0

Security evidence

SkillVetAI static result: high signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
partial text content
Files
40 / 46 inspected as text
Checked
8/27/2026, 9:45:13 AM
Scanner
0.1.3
Policy
1.0.3
10 automated findings
highRemote content is piped directly to a shellscripts/review_checklist.py:156 · confidence 98%curl|sh
highRemote content is piped directly to a shellscripts/skillsec_audit.py:399 · confidence 98%curl|sh
highRemote content is piped directly to a shellREADME.md:30 · confidence 98%curl|sh
highRemote content is piped directly to a shellreferences/skill-spector-method.md:26 · confidence 98%curl|sh
highInstructions or code access sensitive credential locationsreferences/governance.md:50 · confidence 85%~/.ssh/id_rsa
highDynamic code or shell execution is presentscripts/skillsec_audit.py:457 · confidence 78%eval(
highDynamic code or shell execution is presentreferences/skill-spector-method.md:30 · confidence 78%eval(
highEncoded content is decoded and executedscripts/skillsec_audit.py:175 · confidence 90%b64decode
highEncoded content is decoded and executedreferences/skill-spector-method.md:26 · confidence 90%b64decode
mediumPrompt-override language requires reviewreferences/skill-spector-method.md:23 · confidence 62%ignore previous instructions
9 High/Critical review queue entries
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
STATIC_SENSITIVE_CREDENTIAL_ACCESSpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
Open human review queue →
5 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
4 dependency and API indicators
  • api: api.github.com
  • api: github.com
  • api: keepachangelog.com
  • api: raw.githubusercontent.com
External clawhub result: suspicious

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
8/27/2026, 9:07:50 AM
Release binding
Matches this record
  • skillspector: suspicious
  • llm: suspicious

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:01f1e39793cc49f88b529e15578f77b334d8ca7b0333c976507bf3516c8dc816
Show up to 30 recorded paths
  • .gitignore
  • assets/SKILL.md.template
  • CHANGELOG.md
  • LICENSE
  • README.md
  • references/agentic-governance.md
  • references/cases.md
  • references/composer.md
  • references/cross-platform.md
  • references/discovery.md
  • references/evaluation.md
  • references/evolution.md
  • references/framework.md
  • references/governance.md
  • references/learning.md
  • references/lifecycle-ops.md
  • references/personal-to-enterprise.md
  • references/planning.md
  • references/principles.md
  • references/process-systems.md
  • references/roi.md
  • references/scoping.md
  • references/self-update.md
  • references/skill-spector-method.md
  • references/training.md
  • scripts/compose.py
  • scripts/cross_platform_check.py
  • scripts/dupe_check.py
  • scripts/eval_gen.py
  • scripts/evolution_log.py

Source changelog

Security企业级安全合规加固。 新增 `scripts/skillsec_audit.py:纯标准库静态审计器,覆盖 16 类——过度能动 / 输出处理 / 叛变特工 / 触发滥用 / MCP 最低特权 / MCP 工具中毒 / 提示注入 / 数据外流 / 特权升级 / 供应链 / 系统提示漏出 / 记忆中毒 / 工具滥用 / 危险 AST / 污染追踪 / YARA 签名。 与既有 `review_checklist.py` 互补:`review` 偏治理/质量/AI 安全语义层体检;`audit` 偏"过度能动"视角的 16 类风险审计。