# ZONES ## Zone 1: Title (10%) - "Skill 安全审计流程" - Subtitle: "Supply Chain Security Audit" ## Zone 2: Main Flow (60%) Five steps flowing left to right: ### Step 1: 发现 Skill - Icon: Sparkle/star with Skill box - Visual: Package with "NEW" label - Arrow flowing to next ### Step 2: 执行 inspect - Icon: Magnifying glass over code - Command: `clawhub inspect <slug> --files` - Visual: Terminal window doodle ### Step 3: 读取所有文件 ⚠️ - Icon: Open folder with documents - Highlight: ".md 和 .json 也要看!" - Warning: 攻击者常藏恶意指令在文档里 - Visual: Multiple file icons with suspicious eye ### Step 4: 人工二次确认 - Icon: Person with checklist - Visual: Human figure thinking/reviewing - Dotted line suggesting human judgment ### Step 5: 通过/拒绝 - Two paths: - ✓ 通过 (green) → Install - ✗ 拒绝 (red) → Delete ## Zone 3: Critical Warning Box (20%) - Red-bordered warning area - Text: "未通过安全审计的 Skill 不得使用" - Stop sign icon - Hand-drawn warning stripes ## Zone 4: Key Insight (10%) - Small note at bottom: - "攻击者知道人们只审查可执行脚本,所以把恶意指令藏在 .md 和 .json 里" # LABELS All text in Chinese: - 发现 Skill - 执行 inspect - 读取所有文件 - 人工二次确认 - 通过 / 拒绝 - 未通过安全审计的 Skill 不得使用 - .md 和 .json 也要看! - All command text as shown # COLORS - Background: Paper texture, cream - Flow arrows: Dark charcoal with hand-drawn arrowheads - Step boxes: Soft warm tones, each slightly different - Warning box: Red border with light red fill - Pass: Green accent (#27AE60) - Reject: Red accent (#E74C3C) - Icons: Simple black line art # STYLE Hand-drawn flowchart: - Boxes have organic, rounded corners - Arrows are curved and natural, not perfect straight lines - Steps connected like a storyboard - Icons are simple doodles - Warning box looks like a sticky note with red marker - Overall whiteboard sketch aesthetic - Some elements slightly askew for human feel - Mix of printed-style text and handwritten annotations
3/3/2026