Real Skill packageSource verifiedClawHub registry

shisan-xinuo-workflow

一句话定位:把任何工程任务强制按「三级跑道(L1 快速通道 / L2-S 短工作流 / L2-F 完整 11 步)+ L1/L2/L3 封闭清单速判 + 三模式」推进的可审计 Agent 工程纪律工作流,核心纪律可平台无关硬注入。适用:任何动手工程任务——编码/多文件/跨模块/修 bug/建组件/审查/用户点名按流程;不适用:纯聊天问答、单文件只读查询、与工程无关的对话。

Identity and source

Publisher attributionzxc663registry owner unverified by skillvetai
Functional categoryAgent Engineering, Security & Governanceautomatically inferred · 55% rule confidence
Package forminstruction with code28 recorded files
Canonical sourceClawHub registryclawhub:zxc663:shisan-xinuo-workflow
Open canonical source ↗

Platform declarations

These states come from the source or distribution context. None of the entries below are SkillVetAI compatibility test results.

OpenClawnative officialProvenance: registry distribution

Independent structural checks

These checks parse the fixed package against dated platform rules. They do not execute the Skill or verify task behavior.

Claude Codepasses structure
Checker 0.1.0 · agent-skills-2026-08-13+claude-code-docs-2026-08-13 · 9/2/2026.claude/skills/shisan-xinuo-workflow

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenAI Codexpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+codex-docs-2026-08-13 · 9/2/2026.agents/skills/shisan-xinuo-workflow

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

OpenClawpasses structure
Checker 0.1.0 · agent-skills-2026-08-13+openclaw-docs-2026-08-13 · 9/2/2026skills/shisan-xinuo-workflow

Runtime, accounts, dependencies, permissions, network behavior and task quality remain untested.

Installation and inspection

This command is recorded from the source ecosystem and resolves the registry's latest release. The fixed release shown on this page should be inspected before adoption.

clawhub install @zxc663/shisan-xinuo-workflow
clawhub inspect @zxc663/shisan-xinuo-workflow --version 1.0.9

Security evidence

SkillVetAI static result: high signal

This automated, non-executing scan is bound to this release hash. It is not a safety certification and may contain false positives or false negatives.

Status
completed
Coverage
full text content
Files
28 / 28 inspected as text
Checked
9/2/2026, 4:32:29 AM
Scanner
0.1.3
Policy
1.0.3
2 automated findings
highRemote content is piped directly to a shellreferences/never-list.md:44 · confidence 98%curl <url> | bash
highRemote content is piped directly to a shellreferences/security.md:95 · confidence 98%curl <url> | bash
2 High/Critical review queue entries
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
STATIC_DOWNLOAD_PIPE_TO_SHELLpending
Open human review queue →
3 inferred permission indicators
  • network access — automatically inferred
  • filesystem write — automatically inferred
  • browser control — automatically inferred
5 dependency and API indicators
  • api: clawhub.ai
  • api: genai.owasp.org
  • api: github.com
  • api: modelcontextprotocol.io
  • api: slsa.dev
External clawhub result: suspicious

This is registry-supplied evidence for the recorded release, not an independent SkillVetAI scan. Check the canonical source for the full report, scanner versions, scope, and current moderation state.

Evidence checked
9/1/2026, 5:22:26 PM
Release binding
Matches this record
  • skillspector: suspicious
  • llm: suspicious

Recorded files

The catalog stores hashes and an inventory summary for change detection. It does not republish the package contents.

Package content hashsha256:7b2ebef4ed25a283d67ad920c9e47b433518bf2c14b70877fe70b96b017580b2
Show up to 28 recorded paths
  • references/details.md
  • references/injection-core.md
  • references/local-model-glossary.md
  • references/never-list.md
  • references/new-project-bootstrap.md
  • references/platform-adaptation.md
  • references/rules.md
  • references/security.md
  • references/skill-usage.md
  • references/workflows.md
  • skill-card.md
  • SKILL.md
  • templates/acceptance-criteria-template.md
  • templates/agents/critic.md
  • templates/agents/risk-reviewer.md
  • templates/agents/security-auditor.md
  • templates/hooks/hooks.example.json
  • templates/hooks/README.md
  • templates/hooks/session-end.example.sh
  • templates/hooks/session-start.example.sh
  • templates/memory-anchor.md
  • templates/plan-template.md
  • templates/project-rules.md
  • templates/prompt-budget.template.md
  • templates/retrospective-template.md
  • templates/rollback-point-template.md
  • templates/task-record-template.md
  • templates/workspace-memory-template.md

Source changelog

shisan-xinuo-workflow 1.0.9 - Updated core documentation in SKILL.md to reflect new version 2.1.1 and refinements in workflow descriptions. - Revised references/injection-core.md for alignment with platform injection guidance. - Removed obsolete skill-card.md file to simplify project files.

Release security diff

mediumCompared fixed releases 1.0.7 and 1.0.9; 0 finding and 0 permission indicators were added.

Both fixed releases were scanned under the current scanner and policy, so finding, permission and dependency changes are available.

Change reasons and limitations
  • file surface changed
  • content hash changed

Observed release history

These older immutable releases were observed by prior successful syncs. They remain recorded when a newer release becomes current.

1.0.78/30/2026sha256:dae894ddeea4e02ccabb04051d5246920ec52ee9b90367a3312ff0f65ff52e1f
1.0.48/30/2026sha256:7581f21922305a3775dff25a137fe204b6ef0da4f4f3c603bb2ebf9c1cdba6ec
1.0.28/29/2026sha256:c168f9e7607a0e657d2ecd4cc4f2da49d162affbb98db3be870d2c1bd7d479d8
1.0.18/27/2026sha256:46c26a93d7720e3e7d8e1d21690b4e7559843c4f6a2aad76bd3cdb554a9a05fa