安全扫描
OpenClaw
安全
high confidence该技能的请求和运行时指令与 Solidity 开发助手一致:不要求凭据,无安装操作,步骤始终围绕声明用途。
评估建议
This skill is coherent and low-risk: it provides step-by-step guidance for writing and testing Solidity contracts and does not request secrets or install code. Before using it, verify the publisher (metadata shows inconsistent owner strings), and be aware that the agent may attempt to run local tooling (Hardhat/Foundry/Slither) if available — the skill will not itself install those tools. Never provide private keys, mnemonics, or RPC credentials to the agent; review any generated deployment comm...详细分析 ▾
✓ 用途与能力
Name, description, and instructions align: the skill is an instruction-only Solidity development helper that focuses on secure patterns, tests, and validation. It does not request unrelated binaries, credentials, or system paths.
✓ 指令范围
SKILL.md directives (clarify requirements, use OpenZeppelin, implement access control, write tests, run compile/test/static checks) stay within the stated purpose. The instructions do mention running tools (forge, hardhat, slither) but do not ask the agent to read unrelated files, exfiltrate secrets, or perform operations outside normal dev/test/build workflows.
✓ 安装机制
No install spec and no code files — instruction-only skill. This is the lowest-risk install posture; the skill will rely on existing tooling in the agent environment rather than downloading or extracting code.
✓ 凭证需求
No required environment variables, credentials, or config paths are declared. Safety rules explicitly prohibit embedding private keys or RPC secrets. The lack of requested secrets is proportionate to the stated functionality.
✓ 持久化与权限
always:false and no config-path writes are declared. The skill does not request permanent presence or elevated privileges beyond normal autonomous invocation (the platform default).
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/24
初始发布摘要:为 Solidity 智能合约的开发、测试与验证提供安全、结构化的工作流。 - 采用安全优先的最佳实践与显式安全模式(访问控制、可暂停、重入保护)。 - 支持 ERC-20、ERC-721、ERC-1155 及自定义合约类型,并选用经过验证的库。 - 内置测试脚手架与验证步骤,兼容 Hardhat 或 Foundry。 - 主网部署需用户显式批准,并强制执行最佳安全规则。 - 为每个合约生成源码、测试、构建/验证命令及安全说明。
● Pending
安装命令
点击复制官方npx clawhub@latest install axodus-solidity-dev
镜像加速npx clawhub@latest install axodus-solidity-dev --registry https://cn.longxiaskill.com