๋ณธ๋ฌธ์œผ๋กœ ๊ฑด๋„ˆ๋›ฐ๊ธฐ
ๅฐ้พ™่™พๅฐ้พ™่™พAI
๐Ÿค–

page-behavior-audit

Deep behavioral audit with hashed policy (CSP-compliant, no plaintext badwords)

ไธ‹่ฝฝ1.0k
ๆ˜Ÿๆ ‡0
็‰ˆๆœฌ1.0.7
ๅฎ‰ๅ…จๅˆ่ง„
ๅฎ‰ๅ…จ้€š่ฟ‡

ๆŠ€่ƒฝ่ฏดๆ˜Ž


name: page-behavior-audit description: Deep behavioral audit with hashed policy (CSP-compliant, no plaintext badwords) homepage: https://github.com/openclaw/page-behavior-audit metadata: { "openclaw": { "emoji": "๐Ÿ”", "type": "skill", "version": "1.0.3", "modelInvocable": false, "requiredEnv": [ { "name": "WECOM_WEBHOOK_URL", "description": "WeCom webhook URL for critical alerts", "sensitive": true, }, { "name": "OPENCLAW_AUDIT_DIR", "description": "Directory for audit logs, screenshots, and HAR files", "default": "${HOME}/.openclaw/audit", }, ], "trigger": { "type": "webhook", "path": "/api/audit/scan", "method": "POST" }, "timeout": 15000, }, }

page-behavior-audit

Deep behavioral page auditing with content safety policy enforcement.

Features

  • ๐Ÿ” Browser automation with redirect tracking
  • ๐Ÿ›ก๏ธ Content policy checking (hashed badwords)
  • ๐ŸŽฏ Response monitoring (SSRF/XXE detection)
  • ๐Ÿ“ธ Full-page screenshots
  • ๐Ÿ“Š HAR export
  • ๐Ÿšจ WeCom alerts for critical findings

Prerequisites

Set required environment variables:

export WECOM_WEBHOOK_URL="https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=YOUR_KEY"
export OPENCLAW_AUDIT_DIR="${HOME}/.openclaw/audit"  # optional

Usage

Via Webhook

curl -X POST http://localhost:8080/api/audit/scan \
  -H "Content-Type: application/json" \
  -d '{"url": "https://example.com", "include_har": true}'

Via CLI

openclaw skill run page-behavior-audit --url https://example.com

Configuration

Input schema:

  • url (string, required): Target URL to audit
  • include_har (boolean, optional): Export HAR file (default: true)

Output:

  • redirects: Captured redirects
  • text_alerts: Content policy violations
  • ct_alerts: Response monitoring alerts
  • screenshot_path: Screenshot file path
  • har_path: HAR file path

Security

  • SHA256-hashed badword policies
  • Ed25519 signature verification
  • CSP-compliant (no plaintext sensitive words)
  • Sandbox-isolated browser execution

Alert Rules

CRITICAL severity:

  • XML served from non-.xml endpoints (SSRF/XXE risk)
  • Image endpoints returning XML (XXE evasion)

Alerts are sent to WeCom webhook when critical issues are detected.

ๅฆ‚ไฝ•ไฝฟ็”จใ€Œpage-behavior-auditใ€๏ผŸ

  1. ๆ‰“ๅผ€ๅฐ้พ™่™พAI๏ผˆWeb ๆˆ– iOS App๏ผ‰
  2. ็‚นๅ‡ปไธŠๆ–นใ€Œ็ซ‹ๅณไฝฟ็”จใ€ๆŒ‰้’ฎ๏ผŒๆˆ–ๅœจๅฏน่ฏๆก†ไธญ่พ“ๅ…ฅไปปๅŠกๆ่ฟฐ
  3. ๅฐ้พ™่™พAI ไผš่‡ชๅŠจๅŒน้…ๅนถ่ฐƒ็”จใ€Œpage-behavior-auditใ€ๆŠ€่ƒฝๅฎŒๆˆไปปๅŠก
  4. ็ป“ๆžœๅณๆ—ถๅ‘ˆ็Žฐ๏ผŒๆ”ฏๆŒ็ปง็ปญๅฏน่ฏไผ˜ๅŒ–

็›ธๅ…ณๆŠ€่ƒฝ