Real Skill packageSource verifiedClawHub registry

skill-distributor

将 AI 技能包(含 SKILL.md 的目录)先做 32 维生产级预检(frontmatter/slug/版本/脚本语法/敏感信息密钥扫描/提示注入/体积等静态门禁),通过后再以 GitHub 为单一事实源一键发布,并自动同步到 ClawHub、官方 MCP Registry、腾讯 SkillHub 及 Gitee/GitLab 等镜像平台。当用户要求"发布/分发/上架/同步技能"、"检测/测试技能质量/发布前检查/生产级验收"、"把技能推到 GitHub 和其他平台"、"建立技能分发流程"或需要给本地技能目录做版本化分发时使用。检测不过(P0/P1)默认阻断发布;仅显式触发时发布(本地一键命令),无任何自动发布/自动同步机制,密钥本地存储。

Identity and source

Publisher attributionwonregistry owner unverified by skillvetai
Functional categorySoftware Developmentautomatically inferred · 59% rule confidence
Package forminstruction with code7 recorded files
Canonical sourceClawHub registryclawhub:wangdaozhenren:skill-distributor
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses with warnings
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/18/2026.claude/skills/skill-distributor
1 structural issue
  • warning: SKILL.md contains no instruction body after frontmatter. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses with warnings
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/18/2026.agents/skills/skill-distributor
1 structural issue
  • warning: SKILL.md contains no instruction body after frontmatter. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses with warnings
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/18/2026skills/skill-distributor
1 structural issue
  • warning: SKILL.md contains no instruction body after frontmatter. SKILL.md

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @wangdaozhenren/skill-distributor
clawhub inspect @wangdaozhenren/skill-distributor --version 1.1.3

Security evidence

SkillVetAI static result: high signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
6 / 7 inspected as text
Checked
9/18/2026, 4:26:55 PM
Scanner
0.1.3
Policy
1.0.3
1 automated finding
highDynamic code or shell execution is presentscripts/distribute.py:84 · confidence 78%subprocess.Popen(cmd, shell=True
1 High/Critical review queue entry
STATIC_DYNAMIC_CODE_EXECUTIONpending
Open human review queue →
5 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem read — automatically inferred
  • filesystem write — automatically inferred
  • credential access — automatically inferred
3 dependency and API indicators
  • api: gitcode.com
  • api: gitee.com
  • api: github.com
External clawhub result: suspicious

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/18/2026, 10:28:33 AM
Release binding
Matches this record
  • skillspector: suspicious
  • llm: suspicious

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:94b72bfaf5ca142bde42dc266f539bcabfbe98edffd2b8ed9822f65076af35f4
Show up to 7 recorded paths
  • assets/config.example.json
  • assets/server.json.example
  • references/platforms.md
  • scripts/check_env.py
  • scripts/distribute.py
  • scripts/preflight_check.py
  • SKILL.md

Source changelog

Release v1.1.3

Release security diff

mediumCompared fixed releases 1.0.14 and 1.1.3; 0 finding and 0 permission indicators were added.

Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.

Change reasons and limitations
  • file surface changed
  • content hash changed

Observed release history

These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.

1.0.149/17/2026sha256:e2dd45637f548972ed5264e4bf35c1aabc0a842fb9ef9b1343f3a357674ae4fb
1.0.89/16/2026sha256:42d96f9784f6ecb1d417350406077221b204cbeb8d0b7745cc699ac6e3249e8f