Yao Doctor Skill
SkillSecurityAudit local and OpenClaw skill libraries for privacy theft, credential theft, stealthy exfiltration, unsafe execution chains, deceptive instructions, and persistence behavior, then generate a visual HTML security report. Use when Codex needs to security-review one skill or a full skill library before install, enablement, or execution. Do not use for generic cleanup, usage estimation, or app-level security review outside skill packages.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Yao Doctor Skill skill
What this skill tells your AI
The instructions your AI receives, as published by yaojingang/yao-open-skills in skills/yao-doctor-skill/SKILL.md and read by ahel’s review.
Boundary
Own this recurring job: security-review skill packages as untrusted code and untrusted instructions, separate broad capability risk from actual unsafe behavior, and produce evidence-backed recommendations before the skills are installed or executed.
Do not route here for:
- generic code security reviews outside skill folders
- skill cleanup, archival, deduplication, or stale-usage analysis
- privacy policy writing without scanning files
- creating a brand-new skill with no security audit need
Default Workflow
- Run
scripts/run_yao_doctor_skill.py [root] [more-roots]. If no roots are provided, auto-discover the current workspace, OpenClaw skill roots, Codex and Claude local skill roots, Codex plugin-cache skills, supported local workbench configuration surfaces, and project-level workbench surfaces such as repoAGENTS.md,CLAUDE.md, or selected.claude/.codexfiles. - Scan every discovered skill directory containing
SKILL.md, plus recognized workbench surfaces such as local Codex and Claude configuration bundles and project-local agent configuration areas. - For each skill, score two separate layers:
- capability risk: what the skill can access or execute
- unsafe behavior: what the skill appears to do with sensitive data or hidden actions
- Reuse the incremental cache when possible, and surface per-target diffs plus evidence type and confidence in the final report.
- Generate
_yao_doctor_skill_reports/<timestamp>/report.html,report.json, andreport.md. Also update the stable entry:- full scans ->
_yao_doctor_skill_reports/full-library-latest/report.html - changed-only scans ->
_yao_doctor_skill_reports/changed-only-latest/report.html
- full scans ->
- Summarize the highest-severity findings first, with exact paths, lines, evidence type, confidence, and the reason a finding is merely risky, suspicious, unsafe, or critical.
Security Principles
- Do not equate broad permissions with automatic compromise.
- Treat a skill as unsafe only when there is evidence of privacy theft, credential theft, stealthy exfiltration, deceptive behavior, remote execution, or persistence abuse.
- Distinguish capability from intent. A skill may be powerful without being malicious.
- Escalate hard when a sensitive source and an external sink appear in the same execution path or file.
- Favor precise path-level evidence over generic suspicion.
- Stay read-only unless the user explicitly authorizes destructive or quarantine actions.
Outputs
Primary artifact:
- visual HTML security report with the fixed section order:
- overview
- data analysis
- definitions
- module guide
- skill modules
- footer credit
Current interactive contract:
- sticky top navigation
- Chinese default with English toggle
- linked type filters between data analysis and module list
- module cards with audit opinion, findings, and capability evidence
- stable latest report entry for in-app browsing and reuse
Per skill, include:
- absolute path
- declared skill name and one-line summary
- capability risk score and level
- unsafe behavior score and level
- final disposition:
safe,risky,suspicious,unsafe, orcritical - top capabilities discovered
- concrete findings with file path, line, category, severity, rationale, and recommended action
Resources
- Security Principles
- Detection Taxonomy
- Report Blueprint
- Report UI Contract
- Solution Architecture
scripts/scan_security_skills.pyscripts/render_security_report.pyscripts/run_yao_doctor_skill.pyscripts/validate_report_ui_contract.pyevals/trigger_cases.json
Signals
- GitHub stars
- 1k
- Forks
- 147
- Last commit
- Aug 2026
ahel review
K6info
bundled executables the agent is told to runK1info
remote-installer-piped-to-shell (in scripts/build_public_example_report.py)K1info
remote-installer-piped-to-shell (in docs/example-report/report.html)K1info
remote-installer-piped-to-shell (in docs/example-report/report.json)K1info
remote-installer-piped-to-shell (in evals/pressure_suite/doc-only-threat-notes/references/red-team-notes.md)K2info
exfiltration (in evals/pressure_suite/doc-only-threat-notes/references/red-team-notes.md)
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Item type
- skill
- Key
yao-doctor-skill- Source
- github.com/yaojingang/yao-open-skills