胡来给你算一卦
AdvisoryAudited by Static analysis on May 13, 2026.
Overview
No suspicious patterns detected.
Findings (0)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
NoteHigh Confidence
ASI04: Agentic Supply Chain VulnerabilitiesWhat this means
This does not show unsafe behavior, but it may make it harder to confirm exactly which release is being reviewed or installed.
Why it was flagged
The registry metadata supplied for review lists Version 1.0.0, while the packaged _skillhub_meta.json lists version 1.0.2, creating a minor package/version consistency gap.
Skill content
"version": "1.0.2"
Recommendation
If exact version provenance matters, verify the listing and package metadata match before relying on the skill.
