OpenClaw/clawhub-security-signals
收藏资源简介:
ClawHub安全信号是一个经过清理、采用MIT许可证的安全信号数据集,用于公共OpenClaw代理技能。它捕获了代理技能注册表如何大规模评估信任、来源、捆绑代码和扫描器证据。该数据集基于论文《ClawHub安全信号:当VirusTotal、静态分析和SkillSpector存在分歧时》提出,包含了67,453个最新公共ClawHub技能版本,其中SKILL.md内容被编辑,捆绑文件经过清理(如果存在),以及ClawScan注册表裁决,并支持来自VirusTotal、静态启发式分析和NVIDIA SkillSpector的扫描器证据。数据集的核心研究信号是扫描器之间的分歧:VirusTotal、静态分析和SkillSpector很少标记相同的技能,且它们的分歧由攻击面结构化。因此,代理技能安全需要分层治理,而非单一扫描器的允许/阻止决策。
ClawHub Security Signals is a sanitized, MIT-licensed security-signals dataset for public OpenClaw agent skills. It captures how an agent-skill registry evaluates trust, provenance, bundled code, and scanner evidence at scale. This dataset was presented in the paper ClawHub Security Signals: When VirusTotal, Static Analysis, and SkillSpector Disagree. It includes 67,453 latest public ClawHub skill versions with redacted SKILL.md content, sanitized bundled files where present, ClawScan registry verdicts, and supporting scanner evidence from VirusTotal, static heuristic analysis, and NVIDIA SkillSpector. The core research signal is scanner disagreement: VirusTotal, static analysis, and SkillSpector rarely flag the same skills, and their disagreement is structured by attack surface. Agent-skill security therefore needs layered governance rather than a single-scanner allow/block decision.




