Real Skill packageSource verifiedClawHub registry

AI Security & Red Teaming(AI安全与红队测试)

AI 安全与红队测试实操手册——覆盖 AI 系统六大攻击面(提示注入、越权与工具滥用、数据与隐私泄露、幻觉与质量缺陷、供应链与模型投毒、拒绝服务),OWASP LLM Top 10 风险映射,完整红队测试流程(目标定义/攻击面建模/用例设计/执行/报告/修复复测),直接与间接提示注入测试用例库、Agent 越权与沙箱逃逸测试、训练数据泄露与记忆攻击测试、幻觉检测基准,附漏洞分级与修复建议、零依赖本地工具一键生成风险清单、测试用例与报告模板。面向 AI 工程、安全测试、信息安全负责人,与 AI 治理/智能体治理形成"制度+技术"闭环。

Identity and source

Publisher attributionzhaoxinghua09-cellregistry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 63% rule confidence
Package forminstruction with code20 recorded files
Canonical sourceClawHub registryclawhub:zhaoxinghua09-cell:ai-security-redteam
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 8/27/2026.claude/skills/ai-security-redteam

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 8/27/2026.agents/skills/ai-security-redteam

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 8/27/2026skills/ai-security-redteam

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @zhaoxinghua09-cell/ai-security-redteam
clawhub inspect @zhaoxinghua09-cell/ai-security-redteam --version 1.0.0

Security evidence

SkillVetAI static result: no findings detected

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
19 / 20 inspected as text
Checked
8/27/2026, 10:18:59 PM
Scanner
0.1.3
Policy
1.0.3
3 inferred permission indicators
  • shell execution — automatically inferred
  • network access — automatically inferred
  • filesystem write — automatically inferred
2 dependency and API indicators
  • api: clawhub.ai
  • api: www.w3.org
External clawhub result: clean

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
8/27/2026, 4:33:26 PM
Release binding
Matches this record
  • vt: clean
  • skillspector: clean
  • llm: clean

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:18bebe3bee2670fe4af1906afe486253931e6417189ce8b20f64260bd92bc474
Show up to 20 recorded paths
  • ATTESTATION.md
  • LICENSE.md
  • manifest.json
  • references/01-AI安全风险全景.md
  • references/02-红队测试流程.md
  • references/03-提示注入测试.md
  • references/04-越权与逃逸测试.md
  • references/05-数据与隐私测试.md
  • references/06-幻觉与质量测试.md
  • references/07-供应链与拒绝服务.md
  • references/08-报告与修复.md
  • references/09-FAQ.md
  • SECURITY_AUDIT.md
  • skill-card.md
  • SKILL.md
  • tools/ai_redteam_toolkit.py
  • verify/ai_redteam_quality_test.py
  • verify/gen_security_radar.py
  • verify/security_results.json
  • verify/security-radar.svg

Source changelog

v1.0.0: hands-on AI security and red team testing playbook - six attack surfaces (prompt injection, overreach/tool misuse, data & privacy leakage, hallucination, supply chain/poisoning, DoS), OWASP LLM Top 10 mapping, 5-step red team workflow with authorization boundaries, direct/indirect prompt-injection test case library, agent overreach & sandbox escape tests, training-data leakage & memorization tests, hallucination baselines, vulnerability grading and remediation; 5-command zero-dependency toolkit