Mandatory security audit for **every** Agent Skill that is newly added, installed, imported, updated, or written. Scope of inspection: the full bundle — SKILL.md, every script next to it (.sh / .py / .js, etc.), and any bundled resource files. Audit dimensions cover skill integrity, prompt injection, data exfiltration, persistence, cross-skill writes, undeclared remote downloads, hardcoded credentials, and more. ===== MUST BE TRIGGERED WHENEVER ===== * The user **adds / creates / installs / imports / updates / writes** any single Skill. * A skill is pulled into the agent's skills directory from ClawdHub, GitHub, a URL, or a local folder. * **Every** newly introduced or modified skill must be audited **individually** — when N skills are added at once, emit a complete report + the §7 final Chinese verdict line for each skill separately. Sampling, merging, or single-summary output is not allowed. ===== Triggering keywords (natural language, Chinese or English) ===== add skill, install skill, create skill, creating a new skill, write a skill, scaffold a skill, new skill, register skill, import skill, update skill, modify skill, bring in skill, hook up skill, audit skill, scan skill, check skill safety, analyze skill, inspect skill, verify skill, skill security, skill supply chain, 这个 skill 安全吗, skill 安全扫描, 检查 skill 安全, 新增 skill, 添加 skill, 安装 skill, 创建 skill, 引入 skill, 更新 skill, 写一个 skill, 接入 skill。 ===== Do NOT trigger for ===== * General system health checks, project debugging, or normal development work that does not touch any skill file.

Install

openclaw skills install @ambarion/skill-integrity-auditor