.claude/skills/clawmateRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
ClawMate 文件管理 + 预览 + 反馈闭环 + 项目管理。支持文件搜索预览、feedback 处理、项目初始化与前期梳理(Phase I-V)。GitHub: https://github.com/updatedb/clawmate
These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.
These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.
.claude/skills/clawmateRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
.agents/skills/clawmateRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
skills/clawmateRuntime, accounts, dependencies, permissions, network behavior and task quality remain untested.
This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.
clawhub install @updatedb/clawmateclawhub inspect @updatedb/clawmate --version 2.9.1This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.
This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.
The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.
sha256:39a25558229ea858349337316b36cff462f6a8aad268dc4ae443251d33d2e6c4_meta.jsonLICENSE.txtskill-card.mdSKILL.mdClawMate v2.9.1 - security fix: escape unencoded interpolation in examples. ClawHub ClawScan returned `suspicious` for 2.9.0: the file-changing shell and API examples interpolated project data and feedback content without enough validation or encoding. The `task/run` example put the user feedback body into both a single-quoted shell string and JSON, so one apostrophe would close the quote early and the remainder was read as shell tokens. - Added four mandatory parameter-encoding rules. - Rewrote all 9 examples: query params via `curl -G --data-urlencode`, JSON bodies via quoted heredoc (`<<'JSON'`) plus `--data-binary @-`. - src/ was already safe (argv lists, no shell=True, quote() for URLs), so this is a documentation-only fix.