微信公众号合规检查
v1.0.0扫描微信公众号文章中的违规敏感词并自动改写。覆盖翻墙工具、政治敏感、灰产、 破解逆向、引流卖货等 8 大类 100+ 敏感词。输出违规报告和改写后的安全版本。 Use when publishing WeChat articles, checking "违规", "敏感词", "审核", "公众号合规", or...
⭐ 0· 28·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The skill claims to provide a CLI-style scanner (/wechat-compliance-check) but is instruction-only with no binaries or install spec; however the SKILL.md includes clear step-by-step behavior and a bundled sensitive-words.md so the capability is implementable by the agent. This mismatch (CLI examples without a provided binary) is a usability/integration note rather than a security incoherence.
Instruction Scope
Runtime instructions are limited to reading the included references/sensitive-words.md, scanning and replacing terms in the provided article file, producing a backup and a report, and re-scanning. The instructions do not reference unrelated files, environment variables, network endpoints, or system-level configuration.
Install Mechanism
No install spec and no code files are provided (instruction-only). This is the lowest-risk install model: nothing is downloaded or written outside the agent's normal operation except for the described backups created when running --fix.
Credentials
The skill requires no environment variables, no credentials, and no config paths. That is proportionate to a local text-scanning/rewriting tool.
Persistence & Privilege
always:false and no persistence or modification of other skills or system-wide settings. The skill writes backups of processed files (expected behavior) but does not request permanent agent presence or elevated privileges.
Assessment
This skill appears coherent for its stated purpose, but review these practical points before using it:
- The SKILL.md shows CLI usage but no executable is included; confirm how your agent will perform the scanning/rewriting (the agent must implement the steps described or you must install a separate tool).
- Backups: the --fix mode creates .bak files containing the original content — treat backups as sensitive data and store/delete them securely if the article contains private or regulated information.
- False positives / meaning changes: automatic replacements can alter technical meaning (e.g., ‘注入’ in technical contexts). Pay attention to items marked [REVIEW] and validate rewritten output before publishing.
- Wordlist review & updates: the sensitive-words.md contains regex and context flags; inspect and customize it to your needs and legal obligations (and to avoid overbroad censoring of legitimate technical terms).
- No network/exfiltration is indicated in the skill, but if you integrate this into an automated pipeline, confirm that the agent or any added tooling will not transmit article contents to external services without consent.
If these points are acceptable, the skill is consistent with its description and low-risk from a credential/exfiltration perspective.Like a lobster shell, security has layers — review code before you run it.
chinesevk97bp2vv88h6jhfdzkhpytbh1x847wgxcompliancevk97bp2vv88h6jhfdzkhpytbh1x847wgxcontent-moderationvk97bp2vv88h6jhfdzkhpytbh1x847wgxlatestvk97bp2vv88h6jhfdzkhpytbh1x847wgxwechatvk97bp2vv88h6jhfdzkhpytbh1x847wgx
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🛡️ Clawdis
