huawei-cloud-skill-audit
Audit Huawei Cloud skills for quality, security, and compliance using a three-check pipeline: skillspector (AI security), gitleaks (credential leak), and runtime_security (CWE 高危运行模式). Generates structured reports with issue details and fix strategies. Triggers include: "审计技能","技能审计&q
as observed 2026-09-29T04:47:03.526Z- Identifier
huawei-cloud-skill-audit- Source
- ClawHub
- Version observed
- 1.0.9
- Source repository
- not published
- Repository observation
- No source repository listed
- First observed here
- 2026-08-28T22:06:42.351Z
- Observations recorded
- 7
- Installs (reported upstream)
- 0
- Weekly downloads (upstream)
- 141
- Declared license
- MIT-0
Observation history
Fields that differed: changelog latestVersion
| Field | Before | After |
|---|---|---|
changelog |
"- Added stricter path and execution safety: all commands must use the absolute skill installation path (AUDIT_DIR) to prevent script hijacking in untrusted directories.\n- Updated | "- Added new LLM Arbiter check module (`scripts/checks/llm_arbiter.py`) to enhance audit coverage.\n- Updated core scripts for protocol and runtime security analysis.\n- Revised an |
latestVersion |
"1.0.8" | "1.0.9" |
Fields that differed: changelog latestVersion summary
| Field | Before | After |
|---|---|---|
changelog |
"- Added CLI support with new scripts: scripts/cli/cli_entry.py and scripts/cli/cli_reporting.py.\n- Updated internal logic in scripts/checks/skillspector_builtin_check.py and scri | "- Added stricter path and execution safety: all commands must use the absolute skill installation path (AUDIT_DIR) to prevent script hijacking in untrusted directories.\n- Updated |
latestVersion |
"1.0.7" | "1.0.8" |
summary |
"Audit Huawei Cloud skills for quality, security, and compliance using a three-check pipeline: skillspector (AI security) and gitleaks (credential leak). Generates structured repor | "Audit Huawei Cloud skills for quality, security, and compliance using a three-check pipeline: skillspector (AI security), gitleaks (credential leak), and runtime_security (CWE 高危运 |
Fields that differed: changelog latestVersion
| Field | Before | After |
|---|---|---|
changelog |
"**Expanded to a three-check security pipeline with new runtime detection.**\n\n- Added a third check: runtime_security (36 CWE-based runtime patterns + 3 skill-quality rules).\n- | "- Added CLI support with new scripts: scripts/cli/cli_entry.py and scripts/cli/cli_reporting.py.\n- Updated internal logic in scripts/checks/skillspector_builtin_check.py and scri |
latestVersion |
"1.0.3" | "1.0.7" |
Fields that differed: license changelog description latestVersion summary
| Field | Before | After |
|---|---|---|
license |
null | "MIT-0" |
changelog |
"huawei-cloud-skill-audit v1.0.4\n\n- Updated documentation in SKILL.md to refine parameter details and clarify behavior of tool auto-install paths.\n- Example paths for overrides | "**Expanded to a three-check security pipeline with new runtime detection.**\n\n- Added a third check: runtime_security (36 CWE-based runtime patterns + 3 skill-quality rules).\n- |
description |
"Audit Huawei Cloud skills for quality, security, and compliance using a two-check pipeline:\nskillspector (AI security) and gitleaks (credential leak).\nGenerates structured repor | null |
latestVersion |
"1.0.4" | "1.0.3" |
summary |
"Audit Huawei Cloud skills for quality, security, and compliance using a two-check pipeline: skillspector (AI security) and gitleaks (credential leak). Generates structured reports | "Audit Huawei Cloud skills for quality, security, and compliance using a three-check pipeline: skillspector (AI security) and gitleaks (credential leak). Generates structured repor |
Fields that differed: changelog latestVersion
| Field | Before | After |
|---|---|---|
changelog |
"- Added a quality reporting module (`skill_quality_sdk.py`) to anonymously report audit execution details and outcomes for usage/statistics collection.\n- Updated entry script (`s | "huawei-cloud-skill-audit v1.0.4\n\n- Updated documentation in SKILL.md to refine parameter details and clarify behavior of tool auto-install paths.\n- Example paths for overrides |
latestVersion |
"1.0.3" | "1.0.4" |
Fields that differed: changelog latestVersion
| Field | Before | After |
|---|---|---|
changelog |
"Update from GitHub" | "- Added a quality reporting module (`skill_quality_sdk.py`) to anonymously report audit execution details and outcomes for usage/statistics collection.\n- Updated entry script (`s |
latestVersion |
"1.0.2" | "1.0.3" |
Correction
If you maintain this extension and believe anything above is inaccurate, request a correction. Corrections are published, and disputed entries are marked as disputed while under review.