Real Skill packageSource verifiedClawHub registry

MC Server Plugin Security

我的世界(Minecraft)服务器插件安全经验库。记录已验证有效的加固做法(经验)和踩过的安全坑(漏洞原理+判定+解法),全部脱敏。涉及 AuthMe 登录插件、Bukkit/Spigot/Paper/Leaf/Folia/Arclight/NeoForge 插件安全、登录绕过、session 劫持、ForceOp、插件消息伪造、权限漏洞、0day 排查、jar 静态检查、插件版本比对与升级时使用;搭建或维护 MC 服务器前先查看,避免重蹈覆辙。触发词:AuthMe、登录插件、MC 插件安全、ForceOp、session 劫持、插件 0day、绕登录、Bukkit、Paper、Leaf、插件升级、jar 检查。

Identity and source

Publisher attributionmowenQWQregistry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 68% rule confidence
Package forminstruction bundle4 recorded files
Canonical sourceClawHub registryclawhub:mowenqwq:mc-server-plugin-security
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/7/2026.claude/skills/mc-server-plugin-security

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/7/2026.agents/skills/mc-server-plugin-security

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/7/2026skills/mc-server-plugin-security

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @mowenqwq/mc-server-plugin-security
clawhub inspect @mowenqwq/mc-server-plugin-security --version 0.1.5

Security evidence

SkillVetAI static result: no findings detected

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
4 / 4 inspected as text
Checked
9/7/2026, 1:08:41 AM
Scanner
0.1.3
Policy
1.0.3
1 inferred permission indicators
  • network access — automatically inferred
3 dependency and API indicators
  • api: api.github.com
  • api: clawhub.ai
  • api: github.com
External clawhub result: suspicious

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/6/2026, 5:45:12 PM
Release binding
Matches this record
  • skillspector: clean
  • llm: suspicious

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:116df1dcd2e4f81231803f1ae3a9084c3a8f1945974b1113661a95e474d4767e
Show up to 4 recorded paths
  • LICENSE
  • README.md
  • skill-card.md
  • SKILL.md

Source changelog

mc-server-plugin-security v0.1.5 - 新增详细的 Skill 文档规范和更新流程,强调脱敏与持续自查,明确活文档的操作规则 - 扩充说明:记录 AuthMe 登录插件与多种 MC 服务器平台的安全经验、漏洞知识和防御措施 - 完善快速问题索引、章节主题地图,便于按实际症状高效定位解决方案 - 汇总和细化:插件安全典型事件(如 AuthMe 0day/ForceOp/exploit)、版本验证、升级、静态检查等经验与实践 - 明确约束沉淀内容不得含有任何真实环境或身份信息,细化脱敏与自查清单