发现和使用优秀的技能扩展
AI 代理的安全扫描器和输入清理器。可检测提示注入、命令注入、服务器端请求伪造(SSRF)、凭证泄露和路径遍历攻击。在以下情况使用:(1)从 ClawHub 安装新技能时;(2)处理外部输入(如电子邮件、日历事件、Trello 卡片或 API 响应)时;(3)在获取 URL 前进行验证时;(4)对工作区进行安全审计时。保护代理免受不可信数据源中的恶意内容的侵害。
Security scanner and input sanitizer for AI agents. Detects prompt injection, command injection, SSRF, credential exfiltration, and path traversal attacks. Use when (1) installing new skills from ClawHub, (2) processing external input like emails, calendar events, Trello cards, or API responses, (3) validating URLs before fetching, (4) running security audits on your workspace. Protects agents from malicious content in untrusted data sources.