Loading...
Loading...
Compare original and translation side by side
~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md/legal-builder-hub:skill-installer/legal-builder-hub:skill-installer/legal-builder-hub:skill-installer/legal-builder-hub:skill-installerSKILL.mdcommands/*.mdagents/*.mdhooks/hooks.jsonCLAUDE.md~/.claude/plugins/config/claude-for-legal/<plugin>/CLAUDE.mdSKILL.mdcommands/*.mdagents/*.mdhooks/hooks.jsonCLAUDE.md~/.claude/plugins/config/claude-for-legal/<plugin>/CLAUDE.mdskills-qahooks/hooks.json.mcp.jsonallowed-toolstoolsBashWebFetchWebSearchdescriptionskill-installerauto-updaterCLAUDE.mdsettings.jsonhooks.json.gitignore~/.claude/plugins/config/...~/.claude/plugins/config/claude-for-legal/<plugin>/~/.ssh/~/.aws/~/.config/gh/?data=?token=?payload=This is a heuristic scan by an AI, not a security audit. A skill that passes this scan can still be malicious — injections can be worded in ways this check does not recognize, and a skill that passes every pattern here can still misbehave in subtler ways. Read the raw SKILL.md yourself. In enterprise deployments, only install from allowlisted registries and publishers.
skills-qahooks/hooks.json.mcp.jsonallowed-toolstoolsBashWebFetchWebSearchdescriptionskill-installerauto-updaterCLAUDE.mdsettings.jsonhooks.json.gitignore~/.claude/plugins/config/...~/.claude/plugins/config/claude-for-legal/<plugin>/~/.ssh/~/.aws/~/.config/gh/?data=?token=?payload=这是AI执行的启发式扫描,而非安全审计。通过扫描的技能仍可能存在恶意——注入内容可能采用本检查未识别的措辞,通过所有模式检查的技能仍可能以更隐蔽的方式异常行为。请自行阅读原始SKILL.md内容。在企业部署中,仅从白名单注册中心和发布者处安装技能。
CLAUDE.mdCLAUDE.md/legal-builder-hub:skills-qa/legal-builder-hub:skill-installer~/.claude/plugins/config/claude-for-legal/legal-builder-hub/allowlist.yaml/legal-builder-hub:skills-qaallowlist.yamlpermissiverestrictivepermissiverestrictiveAllowlist: ⛔ Source is not on your allowlist. Your mode is— install would be BLOCKED until an administrator addsrestrictiveto[publisher]inpublishers. The QA below will run, but you cannot install this skill without an admin action.allowlist.yaml
/legal-builder-hub:skills-qa/legal-builder-hub:skill-installer~/.claude/plugins/config/claude-for-legal/legal-builder-hub/allowlist.yaml/legal-builder-hub:skills-qaallowlist.yamlpermissiverestrictivepermissiverestrictive白名单:⛔ 源不在你的白名单中。你的模式为——安装会被阻止,直到管理员将restrictive添加到[发布者]的allowlist.yaml中。以下QA会继续运行,但未经管理员操作,你无法安装此技能。publishers
hooks/hooks.json.mcp.jsonallowed-toolstools~/.claude/CLAUDE.mdhooks/.gitignorehooks/hooks.json.mcp.jsonallowed-toolstools~/.claude/CLAUDE.mdhooks/.gitignorereferences/SKILL.mdlast_verifiedfreshness_windowfreshness_categoryverified_againstskill-installer/references/freshness.mdverified_againstlast_verifiedfreshness_windowreferences/last_verifiedfreshness_category: stablestablereferences/references/last_verifiedfreshness_windowfreshness_categoryverified_againstskill-installer/references/freshness.mdverified_againstlast_verifiedfreshness_windowreferences/last_verifiedfreshness_category: stablestablereferences/namedescriptiontriggernamedescriptiontriggercommercial-legalcommercial-legalcommercial-legalcommercial-legalLegal failure mode check:
□ Legal advice vs. legal support: [Addressed / Partially addressed / Not addressed]
□ Privilege implications: [Addressed / N/A — output not work product / Not addressed]
□ Accountability gap: [Addressed / Partially addressed / Not addressed]法律失效模式检查:
□ 法律建议vs法律支持: [已解决/部分解决/未解决]
□ 保密特权影响: [已解决/不适用——输出非工作成果/未解决]
□ 问责缺口: [已解决/部分解决/未解决]I will not help you install this. Here is what I found: [list each finding with file, line, quoted text, and the harm pattern it matches]. I will not present an install prompt, a "type yes to proceed" gate, or a redacted alternative for this skill. Your options: (1) report the skill to the community registry or publisher, (2) ask me to look for a safe alternative that does the legitimate part of what you needed, (3) route to your supervising attorney or security team — I can draft that handoff if you tell me who should receive it.
我不会帮你安装此技能。以下是发现的问题:[列出每个发现,包含文件、行号、引用文本,以及匹配的危害模式]。我不会为此技能提供安装提示、“输入yes继续”闸门,或替代方案。你的选项:(1) 向社区注册中心或发布者举报该技能,(2) 让我寻找能满足你合法需求的安全替代技能,(3) 转交给你的主管律师或安全团队——如果你告诉我接收人,我可以起草交接内容。
undefinedundefined
---
---## Outputs## Outputs