🦞郭哥 · AI Skill 精选库
返回精选库
📝 内容营销自研已跑🔒 会员专享

skill-scanner

Scan any agent skill for security risks before you install or use it. Powered by…

来源:郭亚军 · 目录:skill-scanner
试试这样说

开通会员后可一键复制该技能的调用提示语。

复制提示语
安装说明

开通会员后可查看并复制完整安装步骤。

复制安装说明
一键安装包

下载该技能完整目录(含 SKILL.md 与附属文件),解压即装。

下载安装包

Tencent Zhuque Skill Scanner

Agent Skills security scanner powered by Tencent Zhuque Lab A.I.G. Compatible with any agent platform that supports skills (e.g. OpenClaw, Qclaw, WorkBuddy, CodeBuddy, Cursor, Windsurf, Claude Code, etc.).

Security Declaration

Local-only analysis: this scanner performs static analysis by reading skill files only. No file contents, credentials, or personal data are sent externally.


Language Detection Rule — EXECUTE BEFORE ANYTHING ELSE

Detect the language of the user's triggering message and lock the output language for the entire run. This detection is an internal step only — do NOT output any text that reveals the detection result, such as "当前输出语言为中文", "Detected language: English", or similar meta-statements. Simply use the detected language silently for all subsequent output.

User message languageOutput language
ChineseChinese — entire output in Chinese
EnglishEnglish — entire output in English
Other languageMatch that language
Cannot determineDefault to Chinese

All output — scan start prompt, table headers, labels, prose, verdict, and footer — must be written exclusively in the detected language. Do NOT mix languages or announce the language choice at any point.


Scan Start Prompt

Before starting the scan, output the following line with {skill} replaced by the actual skill name. Translate it to match the detected output language.

🔍 腾讯朱雀实验室 A.I.G Skill Scanner 正在检测 {skill} 的安全性,请稍候...


Scan Workflow

Determine which mode to use based on the user's request:

User intentMode
Scan all skills on a platform, or asks "are my skills safe?" without specifying a fileMode A — Full-platform scan
Scan a specific skill file or a named skillMode B — Single-skill audit

Mode A — Full-platform scan

Use this mode when the user wants to check the security of all skills on a given agent platform.

A-1. Identify the platform

Determine which agent platform the user is referring to. Common platforms include but are not limited to: OpenClaw, Cursor, Windsurf, CodeBuddy, WorkBuddy, Claude Code, qclaw, etc.

How to determine:

A-2. Discover skills

Once the platform is identified, use the platform-specific method below to enumerate all installed skills. Do NOT output a list of all discovered skill names and paths before scanning — proceed directly to auditing each skill one by one.

CRITICAL — No skill may be skipped: Both user-installed skills and system/platform built-in skills must be included. If a platform ships pre-installed or bundled skills, they must be discovered and audited with the same rules as user-installed ones.

Platform-specific skill discovery methods:

PlatformDiscovery method
OpenClawAsk the Agent: "你的 skill 有哪些" or "list your skills" to get the full skill list
CodeBuddyScan both the system directory ~/.codebuddy/plugins/marketplaces/ and the user directory ~/.codebuddy/plugins/ for all skill files and subdirectories. Also check if the platform exposes a built-in skill list via its tools (e.g. use_skill tool's <available_skills> section) and include those.
CursorScan the local directory ~/.cursor/extensions/ and project-level .cursor/skills/ for skill definitions
WindsurfScan the local directory ~/.windsurf/skills/ and project-level .windsurf/skills/ for skill files
Claude CodeScan project-level .claude/skills/ directory and check ~/.claude/skills/ for global skills
qclawAsk the Agent: "你的 skill 有哪些" or "list your skills" to get the full skill list
WorkBuddyAsk the Agent: "你的 skill 有哪些" or "list your skills" to get the full skill list
Other / UnknownAsk the Agent for its skill list

Note: The paths above are common defaults and may vary by version or user configuration. If the expected directory does not exist or is empty, fall back to asking the Agent or asking the user for the correct skill storage location.

A-3. Audit each skill

For each discovered skill, perform the local audit described in the Local Audit section below. Output a separate report card for each skill, then a final summary at the end.

剩余内容仅限会员查看

skill-scanner」的完整方法论、话术模板与执行步骤都在下半部分。 开通会员即可解锁全部技能,并下载安装包直接接入 WorkBuddy。

  • 全部技能完整正文
  • 复制提示语
  • 下载 .zip 安装包
  • 新技能自动解锁
开通会员 · 年卡低至 ¥67/月
已有卡密?点此激活

同类技能 · 内容营销