Identity and source Publisher attribution liuboacean registry owner unverified by skillvetai
Functional category Awaiting category review review pending · 0% rule confidence
Package form instruction with code 22 recorded files
Canonical source ClawHub registry clawhub:liuboacean:mubu-integration
Open canonical source ↗ Platform declarations These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.
Independent structural checks These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.
Claude Code passes structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 8/28/2026 .claude/skills/mubu-integrationRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
OpenAI Codex passes structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 8/28/2026 .agents/skills/mubu-integrationRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
OpenClaw passes structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 8/28/2026 skills/mubu-integrationRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
Installation and inspection This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.
clawhub install @liuboacean/mubu-integrationCopy
clawhub inspect @liuboacean/mubu-integration --version 1.3.15Copy inspection command
Security evidence SkillVetAI static result: high signal This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.
Status completed
Coverage full text content
Files 22 / 22 inspected as text
Checked 8/28/2026, 11:22:40 AM
Scanner 0.1.3
Policy 1.0.3 2 automated findings high Instructions or code access sensitive credential locations scripts/mubu/config.py:171 · confidence 85% ~/.ssh/id_rsahigh Instructions or code access sensitive credential locations tests/test_mubu_api.py:1378 · confidence 85% ~/.ssh/id_rsa2 High/Critical review queue entries STATIC_SENSITIVE_CREDENTIAL_ACCESS pending
STATIC_SENSITIVE_CREDENTIAL_ACCESS pending
Open human review queue → 5 inferred permission indicators network access — automatically inferred filesystem read — automatically inferred filesystem write — automatically inferred credential access — automatically inferred browser control — automatically inferred 150 dependency and API indicators pypi: certifi ==2026.6.17 \ pypi: --hash =sha256:024c88eeec92ca068db80f02b8b07c9cef7b9fe261d1d535abfd5abd6f6af432 \ pypi: --hash =sha256:2227dcbaafe0d2f59279d1762ddddc37783ed4354594f194ffc31d20f41fc3db pypi: charset-normalizer ==3.4.9 \ pypi: --hash =sha256:0327fcd59a935777d83410750c50600ee9571af2846f71ce40f25b13da1ef380 \ pypi: --hash =sha256:03d07803992c6c7bbc976327f34b18b6160327fc81cb82c9d504720ac0be3b62 \ pypi: --hash =sha256:04ce310cb89c15df659582aee80a0603788732a5e017d5bd5c81158106ce249c \ pypi: --hash =sha256:0d861473f743244d349b50f850d10eb87aeb22bbdcc8e64f79273c94af5a8226 \ pypi: --hash =sha256:0e94703ec9684807f20cfb5eed95c70f67f2a8f21ad620146d7b5a13677b93e5 \ pypi: --hash =sha256:0fa1aec2d32bcc03c8fa0f6f1712caad1adc38509f31142112e5c9daf5b9c833 \ pypi: --hash =sha256:16b65ea0f2465b6fb52aa22de5eca612aa964ddfec00a912e26f4656cbef890b \ pypi: --hash =sha256:16d10d789dd9bcca1173c95af82c58433122564b7bc39385124be735a35cbe99 \ pypi: --hash =sha256:19ac87f93086ce37b86e098888555c4b4bc48102279bae3350098c0ed664b501 \ pypi: --hash =sha256:1d22856ffbe153a602df38e4a5464f0b748a54002e0d69ac6d2ad0a197cc99ec \ pypi: --hash =sha256:21e764fd1e70b6a3e205a0e46f3051701f98a8cb3fad66eeb80e48bb502f8698 \ pypi: --hash =sha256:231ddcbb35e2ff8973e1365db41fe0572662893b99a05deb183b68ad4c0c8bd4 \ pypi: --hash =sha256:253a4a220747e8b5faf57ec320c4f5efb0cef05f647420bf267143ec15dba10a \ pypi: --hash =sha256:280081916dc341820640489a66e4696049401ef1cf6dd672f672e70ad915aca3 \ pypi: --hash =sha256:2a441ea71902098ffe78c5abe6c494f44160b4af614ed16c3d9a3b1d17fd8ee2 \ pypi: --hash =sha256:304b13570067b2547562e308af560b3963857b1fa90bd6afd978130130fe2d6a \ pypi: --hash =sha256:32286a2c8d167e897177b673176c1e3e00d4057caf5d2b64eef9a3666b03018e \ pypi: --hash =sha256:33bdcc2a32c0a0e861f60841a512c8acc658c87c2ac59d89e3a46dacf7d866e4 \ pypi: --hash =sha256:375b83ed0aecfce76c16d198fbc21f3b11b337d68662bea0a995046682a11419 \ pypi: --hash =sha256:3c09a49d6cde137258beb3d551994a2927fd35ad5cf96aed573f61bbd67c5f84 \ pypi: --hash =sha256:3d92613ec25e43b05f042302531ec0f00b8445190e43325880cbd6ab7c2581da \ pypi: --hash =sha256:40a126142a56b2dfc0aacbad1de8310cbf60da7656db0e6b16eebd48e3e93519 \ pypi: --hash =sha256:416c229f77e5ea25b3dfd4b582f8d73d7e43c22320302b9ab128a2d3a0b38efe \ pypi: --hash =sha256:432786d3561e69aeeae6c7e8648964ce0ad05736120135601f87ac26b9c83381 \ pypi: --hash =sha256:43b9e366a31fdd1c87d0eb08f579b4a82b723ea54338f040d6b4e518a026ea29 \ pypi: --hash =sha256:440eede837960000d74978f0eba527be106b5b9aee0daf779d395276ed0b0614 \ pypi: --hash =sha256:45b0cc4e3556cd875e09102988d1ab8356c998b596c9fced84547c8138b487a0 \ pypi: --hash =sha256:476743fe6dfe14a2da12e3ac79125dc84a3b2cf8094369a47a1529b0cd8549fe \ pypi: --hash =sha256:4773092f8019072343a7447203308b176e10199920eb02d6195e81bbb3274c29 \ pypi: --hash =sha256:4b3dac63058cc36820b0dd072f89898604e2d39686fe05321729d00d8ac185a0 \ pypi: --hash =sha256:4d1c96a7a18b9690a4d46df09e3e3382406ae3213727cd1019ebade1c4a81917 \ pypi: --hash =sha256:51307f5c71007673a2bf8232ad973483d281e74cb99c8c5a990af1eefa6277d9 \ pypi: --hash =sha256:51447e9aa2684679af07ca5021c3db526e0284347ebf4ffcec1154c3350cfe32 \ pypi: --hash =sha256:58150c9f9b9a552505912d182ccdf26f6396fb6094816ceebcbb20eecabaed94 \ pypi: --hash =sha256:5b10cd92fc5c498b35a8635df6d5a100207f88b63a4dc1de7ef9a548e1e2cd63 \ pypi: --hash =sha256:5e226f6218febc71f6c1fc2fafb91c226f75bdc1d8fb12d66823716e891608fd \ External clawhub result: suspicious This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.
Evidence checked 8/28/2026, 4:55:01 AM
Release binding Matches this record skillspector: suspicious llm: suspicious Recorded files The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.
Package content hash sha256:88d6546ac6d152f1842e9e632f35ffb6233ebdf8468c90a0c016cd789cdb629a
Show up to 22 recorded paths CHANGELOG.mdCONTRIBUTING.mddocs/hellogithub-pitch.mddocs/positioning.mddocs/v2ex-post.mddocs/xiaoshuopai-tutorial.mdexamples/weekly.mdREADME.mdREADME.zh-CN.mdrequirements-dev.txtrequirements.txtruff.tomlscripts/gen_assets.pyscripts/mubu_api.pyscripts/mubu/__init__.pyscripts/mubu/cli.pyscripts/mubu/client.pyscripts/mubu/config.pyscripts/mubu/convert.pyskill-card.mdSKILL.mdtests/test_mubu_api.pySource changelog v1.3.15: P0 信任修复(create 缺 name 参数坏命令)+测试计数对齐;P1 client 429 限流退避/get_doc 解析保护/search include_content、ruff CI 门禁、Auto-refresh auth 措辞/Troubleshooting 表/cli rename 帮助、分发素材;115 tests green
Release security diff medium Compared fixed releases 1.3.14 and 1.3.15; 0 finding and 0 permission indicators were added.
Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.
Change reasons and limitations file surface changed content hash changed Observed release history These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.
1.3.14 8/25/2026 sha256:f0ed0cc1568bb7e823ff52941046ac97aa7f223e789f0e15bbb69f3bd30bba87