ZappushZappush
SkillsUse CasesBenchmarkCommunitySign In
      Back to Skills
      john-niu-07

      Safety Report

      Test Safety

      @john-niu-07

      Security guard skill for OpenClaw - Analyzes user input for harmful content, risky commands, and security threats before invoking LLM

      237Downloads
      0Installs
      1Stars
      1Versions
      Security & Compliance3,689AI & Machine Learning3,159Legal & Compliance1,710

      Security Analysis

      medium confidence
      Suspicious0.08 risk

      The skill's stated purpose (a safety guard for LLM inputs) is plausible, but packaging and metadata inconsistencies plus some undocumented file/config access raise concerns and warrant manual review before installing or supplying credentials.

      Mar 15, 20262 files3 concerns
      Purpose & Capabilitynote

      The skill claims to analyze input for harmful content and references LLM provider API keys (OpenAI, Anthropic, xAI, Google). Those requirements are proportionate to a safety-guard skill. However, the skill is instruction-only (no code provided) yet shows CLI usage examples for a 'safety-guard' binary that is not included — unclear how runtime behavior is supplied, which reduces confidence in capability claims.

      Instruction Scopenote

      SKILL.md describes fetching content from URLs, local files, and YouTube and references optional external services (FIRECRAWL, APIFY). Those actions are plausible for content-extraction and safety checks, but the file also references a user config path (~/.safety-guard/config.json) that isn't declared in the registry metadata. Because the skill can instruct fetching external resources and reading/writing a local config, you should verify exactly what code will run and what data will be read or transmitted before use.

      Install Mechanismconcern

      Registry metadata at the top-level reported 'No install spec', yet SKILL.md includes embedded metadata that lists a pip install step for PyYAML and requires python3. Additionally, the included _meta.json file does not match the registry metadata (different slug/owner/version). These inconsistencies suggest packaging or provenance problems — either the skill is incomplete (instruction-only but references an external CLI not supplied) or files were copied/mislabelled. That mismatch increases risk because you can't verify what will be installed/run.

      Credentialsok

      The skill does not declare any required environment variables and only suggests standard LLM provider API keys and optional API tokens for content-extraction services. Those are proportionate for a safety-guard that needs to call LLMs and optional crawlers. No unrelated credentials (cloud keys, SSH keys, etc.) are requested.

      Persistence & Privilegeok

      The skill is not always-enabled, is user-invocable, and does not request persistent privileges in the metadata. It mentions an optional local config path (~/.safety-guard/config.json) which would be typical for a CLI tool, but the presence of that path in SKILL.md without being declared is a packaging inconsistency to verify.

      Guidance

      Do not install or provide API keys yet. Steps to take before trusting this skill: 1) Inspect the referenced GitHub repo and confirm the CLI or Python code actually exists and matches this SKILL.md. 2) Verify author/owner identity (the registry metadata and _meta.json disagree on slug/owner/version). 3) If you plan to use it, run it in a sandboxed environment (no real API keys) and monitor network calls to see what endpoints it contacts. 4) Confirm what files it will read/write (it mentions ~/.safety-guard/config.json) and that it won’t exfiltrate sensitive data. 5) Prefer least-privilege API keys (scoped, revocable) and rotate them after testing. If you can't find source code that implements the CLI behavior described, treat the skill as incomplete/untrustworthy.

      Latest Release

      v1.0.2

      - Improved documentation and usage instructions in SKILL.md - Added details about supported models, API keys, and configuration options - Clarified optional flags and fallback services for enhanced usability and flexibility

      More by @john-niu-07

      karpathy-llm-wiki

      @john-ver · 6 stars

      OpenClaw Safety Guard

      1 stars

      OpenClaw Safety Guard

      0 stars

      see-video

      @john-ver · 0 stars

      下载电影/电视剧/综艺的剧照/海报

      @zj-john · 0 stars

      Scoped Memory Manager

      @john-20-ux · 0 stars

      Published by @john-niu-07 on ClawHub

      Zappush© 2026 Zappush
      HomeGuaranteeSupport

      Something feels unusual? We want to help: [email protected]