Real Skill packageSource verifiedClawHub registryAutomatic security hold

Poly-Mal-Scan_恶意代码扫描器

FWold 多语言(PHP/JS/Bash)恶意代码/webshell 扫描检测器: 用法、MCP 接入、规则库持续更新、运行依赖。扫描文件/代码、挂载/测试 detect_mcp_server MCP、新增调准特征码规则、排查误报漏报时启用。

Identity and source

Publisher attributiontsherryyannregistry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 53% rule confidence
Package forminstruction with code53 recorded files
Canonical sourceClawHub registryclawhub:tsherryyann:poly-mal-scan
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/3/2026.claude/skills/poly-mal-scan

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/3/2026.agents/skills/poly-mal-scan

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/3/2026skills/poly-mal-scan

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

Installation commands are hidden while this fixed release is under an automatic security hold. Review the evidence and canonical source manually.

Security evidence

SkillVetAI static result: critical signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
partial text content
Files
40 / 52 inspected as text
Checked
9/3/2026, 4:23:02 AM
Scanner
0.1.3
Policy
1.0.3
20 automated findings
criticalDestructive command targets a system rootbash_security/bash_ast_normalize.py:14 · confidence 98%rm -rf /
highRemote content is piped directly to a shellbash_security/bash_categories.json:27 · confidence 98%curl | bash
highRemote content is piped directly to a shellbash_security/bash_malicious_commands.json:124 · confidence 98%curl|sh
highDynamic code or shell execution is presentSKILL.md:127 · confidence 78%eval(
highDynamic code or shell execution is presentjs_security/js_ast_normalize.py:18 · confidence 78%eval(
highDynamic code or shell execution is presentjs_security/js_common.py:76 · confidence 78%eval(
highDynamic code or shell execution is presentjs_security/js_detect_rules.py:68 · confidence 78%eval(
highDynamic code or shell execution is presentjs_security/js_logic_engine.py:127 · confidence 78%eval(
highDynamic code or shell execution is presentphp_security/detect_rules.py:65 · confidence 78%eval(
highDynamic code or shell execution is presentphp_security/logic_engine.py:81 · confidence 78%eval (
highDynamic code or shell execution is presentphp_security/php_ast_normalize.py:13 · confidence 78%eval(
highDynamic code or shell execution is presentphp_security/php_common.py:77 · confidence 78%exec(
highEncoded content is decoded and executedSKILL.md:30 · confidence 90%base64
highEncoded content is decoded and executedjs_security/js_ast_normalize.py:17 · confidence 90%fromCharCode
highEncoded content is decoded and executedjs_security/js_detect_rules.py:7 · confidence 90%base64
highEncoded content is decoded and executedjs_security/js_logic_engine.py:127 · confidence 90%atob
highEncoded content is decoded and executedphp_security/detect_rules.py:19 · confidence 90%base64
highEncoded content is decoded and executedphp_security/logic_engine.py:4 · confidence 90%base64
highEncoded content is decoded and executedphp_security/php_ast_normalize.py:10 · confidence 90%base64
highEncoded content is decoded and executedbash_security/bash_file_write.json:97 · confidence 90%base64
20 High/Critical review queue entries
STATIC_DESTRUCTIVE_ROOT_COMMANDpending
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_DYNAMIC_CODE_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
STATIC_OBFUSCATED_EXECUTIONpending
Open human review queue →
5 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/3/2026, 6:44:26 AM
Release binding
Matches this record
  • vt: clean
  • skillspector: suspicious
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:d4a75e883215bb4ebfd3a73218b36e67fc055e064cb92ef3916ab070e0fd4bbc
Show up to 30 recorded paths
  • bash_security/bash_ast_normalize.py
  • bash_security/bash_ast_tree.py
  • bash_security/bash_categories.json
  • bash_security/bash_cmd_dect.py
  • bash_security/bash_common.py
  • bash_security/bash_detect_rules.py
  • bash_security/bash_file_write_dect.py
  • bash_security/bash_file_write.json
  • bash_security/bash_malicious_commands.json
  • bash_security/bash_malicious_variables.json
  • bash_security/bash_raw_traits.json
  • bash_security/bash_self_replicate_dect.py
  • bash_security/bash_self_replicate.json
  • bash_security/bash_threat_func_dect.py
  • bash_security/bash_threatening_funcs.json
  • bash_security/bash_trait_dect.py
  • bash_security/bash_var_dect.py
  • bash_security/bashdect.py
  • bash_security/特征码来源.md
  • code_language_recognition.py
  • detect_mcp_server.py
  • js_security/js_ast_normalize.py
  • js_security/js_ast_tree.py
  • js_security/js_categories.json
  • js_security/js_common.py
  • js_security/js_detect_rules.py
  • js_security/js_dynamic_code_dect.py
  • js_security/js_file_write_dect.py
  • js_security/js_logic_engine.py
  • js_security/js_raw_traits.json

Source changelog

- Added detailed usage and implementation documentation as SKILL.md, covering all major features and concepts of poly-mal-scan. - Describes supported languages (PHP, JavaScript, Bash), scanning modes (CLI, MCP), detection architecture, and rules update process. - Includes step-by-step guides for rule updates, running tests, and integrating with MCP (multi-language protocol). - Explains project structure, running dependencies, coding conventions, and troubleshooting triggers. - Makes it easy for users to locate relevant tools, update threat signatures, and ensure scan reliability across environments.

Release security diff

mediumCompared fixed releases 0.0.1 and 0.0.2; 0 finding and 0 permission indicators were added.

Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.

Change reasons and limitations
  • content hash changed

Observed release history

These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.

0.0.19/2/2026sha256:c30cb0db11ccab85f91d939cb6a0262feb19f1f9506edceaec307a1833b841ca