完善 MCP/会话上下文治理并补齐搜索与诊断能力。

补充历史压缩与会话诊断链路,强化 tool pairing 与空响应兜底观测;完善 Admin MCP 导入/绑定与相关前端展示;新增 web_search_fast/web_fetch_clean 及多项测试与文档更新,并同步技能安装与角色绑定策略改进。

Made-with: Cursor
This commit is contained in:
oliver 2026-05-01 17:46:50 +08:00
parent df91434936
commit ae44cbcad5
43 changed files with 3549 additions and 57 deletions

View file

@ -0,0 +1,267 @@
---
name: automation-workflows
description: Design and implement automation workflows to save time and scale operations as a solopreneur. Use when identifying repetitive tasks to automate, building workflows across tools, setting up triggers and actions, or optimizing existing automations. Covers automation opportunity identification, workflow design, tool selection (Zapier, Make, n8n), testing, and maintenance. Trigger on "automate", "automation", "workflow automation", "save time", "reduce manual work", "automate my business", "no-code automation".
---
# Automation Workflows
## Overview
As a solopreneur, your time is your most valuable asset. Automation lets you scale without hiring. The goal is simple: automate anything you do more than twice a week that doesn't require creative thinking. This playbook shows you how to identify automation opportunities, design workflows, and implement them without writing code.
---
## Step 1: Identify What to Automate
Not every task should be automated. Start by finding the highest-value opportunities.
**Automation audit (spend 1 hour on this):**
1. Track every task you do for a week (use a notebook or simple spreadsheet)
2. For each task, note:
- How long it takes
- How often you do it (daily, weekly, monthly)
- Whether it's repetitive or requires judgment
3. Calculate time cost per task:
```
Time Cost = (Minutes per task × Frequency per month) / 60
```
Example: 15 min task done 20x/month = 5 hours/month
4. Sort by time cost (highest to lowest)
**Good candidates for automation:**
- Repetitive (same steps every time)
- Rule-based (no complex judgment calls)
- High-frequency (daily or weekly)
- Time-consuming (takes 10+ minutes)
**Examples:**
- ✅ Sending weekly reports to clients (same format, same schedule)
- ✅ Creating invoices after payment
- ✅ Adding new leads to CRM from form submissions
- ✅ Posting social media content on a schedule
- ❌ Conducting customer discovery interviews (requires nuance)
- ❌ Writing custom proposals for clients (requires creativity)
**Low-hanging fruit checklist (start here):**
- [ ] Email notifications for form submissions
- [ ] Auto-save form responses to spreadsheet
- [ ] Schedule social posts in advance
- [ ] Auto-create invoices from payment confirmations
- [ ] Sync data between tools (CRM ↔ email tool ↔ spreadsheet)
---
## Step 2: Choose Your Automation Tool
Three main options for no-code automation. Pick based on complexity and budget.
**Tool comparison:**
| Tool | Best For | Pricing | Learning Curve | Power Level |
|---|---|---|---|---|
| **Zapier** | Simple, 2-3 step workflows | $20-50/month | Easy | Low-Medium |
| **Make (Integromat)** | Visual, multi-step workflows | $9-30/month | Medium | Medium-High |
| **n8n** | Complex, developer-friendly, self-hosted | Free (self-hosted) or $20/month | Medium-Hard | High |
**Selection guide:**
- Budget < $20/month → Try Zapier free tier or n8n self-hosted
- Need visual workflow builder → Make
- Simple 2-step workflows → Zapier
- Complex workflows with branching logic → Make or n8n
- Want full control and customization → n8n
**Recommendation for solopreneurs:** Start with Zapier (easiest to learn). Graduate to Make or n8n when you hit Zapier's limits.
---
## Step 3: Design Your Workflow
Before building, map out the workflow on paper or a whiteboard.
**Workflow design template:**
```
TRIGGER: What event starts the workflow?
Example: "New row added to Google Sheet"
CONDITIONS (optional): Should this workflow run every time, or only when certain conditions are met?
Example: "Only if Status column = 'Approved'"
ACTIONS: What should happen as a result?
Step 1: [action]
Step 2: [action]
Step 3: [action]
ERROR HANDLING: What happens if something fails?
Example: "Send me a Slack message if action fails"
```
**Example workflow (lead capture → CRM → email):**
```
TRIGGER: New form submission on website
CONDITIONS: Email field is not empty
ACTIONS:
Step 1: Add lead to CRM (e.g., Airtable or HubSpot)
Step 2: Send welcome email via email tool (e.g., ConvertKit)
Step 3: Create task in project management tool (e.g., Notion) to follow up in 3 days
Step 4: Send me a Slack notification: "New lead: [Name]"
ERROR HANDLING: If Step 1 fails, send email alert to me
```
**Design principles:**
- Keep it simple — start with 2-3 steps, add complexity later
- Test each step individually before chaining them together
- Add delays between actions if needed (some APIs are slow)
- Always include error notifications so you know when things break
---
## Step 4: Build and Test Your Workflow
Now implement it in your chosen tool.
**Build workflow (Zapier example):**
1. **Choose trigger app** (e.g., Google Forms, Typeform, website form)
2. **Connect your account** (authenticate via OAuth)
3. **Test trigger** (submit a test form to make sure data comes through)
4. **Add action** (e.g., "Add row to Google Sheets")
5. **Map fields** (match form fields to spreadsheet columns)
6. **Test action** (run test to verify row is added correctly)
7. **Repeat for additional actions**
8. **Turn on workflow** (Zapier calls this "turn on Zap")
**Testing checklist:**
- [ ] Submit test data through the trigger
- [ ] Verify each action executes correctly
- [ ] Check that data maps to the right fields
- [ ] Test with edge cases (empty fields, special characters, long text)
- [ ] Test error handling (intentionally cause a failure to see if alerts work)
**Common issues and fixes:**
| Issue | Cause | Fix |
|---|---|---|
| Workflow doesn't trigger | Trigger conditions too narrow | Check filter settings, broaden criteria |
| Action fails | API rate limit or permissions | Add delay between actions, re-authenticate |
| Data missing or incorrect | Field mapping wrong | Double-check which fields are mapped |
| Workflow runs multiple times | Duplicate triggers | De-duplicate based on unique ID |
**Rule:** Test with real data before relying on an automation. Don't discover bugs when a real customer is involved.
---
## Step 5: Monitor and Maintain Automations
Automations aren't set-it-and-forget-it. They break. Tools change. APIs update. You need a maintenance plan.
**Weekly check (5 min):**
- Scan workflow logs for errors (most tools show a log of runs + failures)
- Address any failures immediately
**Monthly audit (15 min):**
- Review all active workflows
- Check: Is this still being used? Is it still saving time?
- Disable or delete unused workflows (they clutter your dashboard and can cause confusion)
- Update any workflows that depend on tools you've switched away from
**Where to store workflow documentation:**
- Create a simple doc (Notion, Google Doc) for each workflow
- Include: What it does, when it runs, what apps it connects, how to troubleshoot
- If you have 10+ workflows, this doc will save you hours when something breaks
**Error handling setup:**
- Route all error notifications to one place (Slack channel, email inbox, or task manager)
- Set up: "If any workflow fails, send a message to [your error channel]"
- Review errors weekly and fix root causes
---
## Step 6: Advanced Automation Ideas
Once you've automated the basics, consider these higher-leverage workflows:
### Client onboarding automation
```
TRIGGER: New client signs contract (via DocuSign, HelloSign)
ACTIONS:
1. Create project in project management tool
2. Add client to CRM with "Active" status
3. Send onboarding email sequence
4. Create invoice in accounting software
5. Schedule kickoff call on calendar
6. Add client to Slack workspace (if applicable)
```
### Content distribution automation
```
TRIGGER: New blog post published on website (via RSS or webhook)
ACTIONS:
1. Post link to LinkedIn with auto-generated caption
2. Post link to Twitter as a thread
3. Add post to email newsletter draft (in email tool)
4. Add to content calendar (Notion or Airtable)
5. Send notification to team (Slack) that post is live
```
### Customer health monitoring
```
TRIGGER: Every Monday at 9am (scheduled trigger)
ACTIONS:
1. Pull usage data for all customers from database (via API)
2. Flag customers with <50% of average usage
3. Add flagged customers to "At Risk" segment in CRM
4. Send re-engagement email campaign to at-risk customers
5. Create task for me to personally reach out to top 10 at-risk customers
```
### Invoice and payment tracking
```
TRIGGER: Payment received (Stripe webhook)
ACTIONS:
1. Mark invoice as paid in accounting software
2. Send receipt email to customer
3. Update CRM: customer status = "Paid"
4. Add revenue to monthly dashboard (Google Sheets or Airtable)
5. Send me a Slack notification: "Payment received: $X from [Customer]"
```
---
## Step 7: Calculate Automation ROI
Not every automation is worth the time investment. Calculate ROI to prioritize.
**ROI formula:**
```
Time Saved per Month (hours) = (Minutes per task / 60) × Frequency per month
Cost = (Setup time in hours × $50/hour) + Tool cost per month
Payback Period (months) = Setup cost / Monthly time saved value
If payback period < 3 months → Worth it
If payback period > 6 months → Probably not worth it (unless it unlocks other value)
```
**Example:**
```
Task: Manually copying form submissions to CRM (15 min, 20x/month = 5 hours/month saved)
Setup time: 1 hour
Tool cost: $20/month (Zapier)
Payback: ($50 setup cost) / ($250/month value saved) = 0.2 months → Absolutely worth it
```
**Rule:** Focus on automations with payback < 3 months. Those are your highest-leverage investments.
---
## Automation Mistakes to Avoid
- **Automating before optimizing.** Don't automate a bad process. Fix the process first, then automate it.
- **Over-automating.** Not everything needs to be automated. If a task is rare or requires judgment, do it manually.
- **No error handling.** If an automation breaks and you don't know, it causes silent failures. Always set up error alerts.
- **Not testing thoroughly.** A broken automation is worse than no automation — it creates incorrect data or missed tasks.
- **Building too complex too fast.** Start with simple 2-3 step workflows. Add complexity only when the simple version works perfectly.
- **Not documenting workflows.** Future you will forget how this works. Write it down.

View file

@ -0,0 +1,6 @@
{
"ownerId": "kn732qfbv22he1jqm63xbwq6e980kn8s",
"slug": "automation-workflows",
"version": "0.1.0",
"publishedAt": 1770341582349
}

View file

@ -0,0 +1,18 @@
# Changelog
## v2.1.0 (2026-04-11)
- Version bump to 2.1.0
## v2.0.1 (2026-02-06)
- Simplified documentation
- Removed gov-related content
- Optimized for ClawHub publishing
## v2.0.0 (2026-02-06)
- Added 9 international search engines
- Enhanced advanced search capabilities
- Added DuckDuckGo Bangs support
- Added WolframAlpha knowledge queries
## v1.0.0 (2026-02-04)
- Initial release with 8 domestic search engines

View file

@ -0,0 +1,48 @@
# Multi Search Engine
## 基本信息
- **名称**: multi-search-engine
- **版本**: v2.0.1
- **描述**: 集成16个搜索引擎(7国内+9国际),支持高级搜索语法
- **发布时间**: 2026-02-06
## 搜索引擎
**国内(7个)**: 百度、必应CN、必应INT、360、搜狗、微信、神马
**国际(9个)**: Google、Google HK、DuckDuckGo、Yahoo、Startpage、Brave、Ecosia、Qwant、WolframAlpha
## 核心功能
- 高级搜索操作符(site:, filetype:, intitle:等)
- DuckDuckGo Bangs快捷命令
- 时间筛选(小时/天/周/月/年)
- 隐私保护搜索
- WolframAlpha知识计算
## 更新记录
### v2.0.1 (2026-02-06)
- 精简文档,优化发布
### v2.0.0 (2026-02-06)
- 新增9个国际搜索引擎
- 强化深度搜索能力
### v1.0.0 (2026-02-04)
- 初始版本:8个国内搜索引擎
## 使用示例
```javascript
// Google搜索
web_fetch({"url": "https://www.google.com/search?q=python"})
// 隐私搜索
web_fetch({"url": "https://duckduckgo.com/html/?q=privacy"})
// 站内搜索
web_fetch({"url": "https://www.google.com/search?q=site:github.com+python"})
```
MIT License

View file

@ -0,0 +1,215 @@
---
name: "multi-search-engine"
description: "Multi search engine integration with 16 engines (7 CN + 9 Global). Supports advanced search operators, time filters, site search, privacy engines, and WolframAlpha knowledge queries. No API keys required."
---
# Multi Search Engine
Integration of 16 search engines for web crawling without API keys.
## Workflow
1. **Preparation**: AI Agent initializes an empty in-memory cookie store. Cookies are only acquired dynamically during search operations when access is denied
2. **Language Evaluation**: Detect the language attribute of the search query. If the query is in Chinese, use Domestic search engines (Baidu, Bing CN, Bing INT, 360, Sogou, WeChat, Shenma). If the query is non-Chinese, use International search engines (Google, Google HK, DuckDuckGo, Yahoo, Startpage, Brave, Ecosia, Qwant, WolframAlpha). Select engines based on query relevance and availability.
3. **Controlled Search (Reachability-first)**: Use `web_search_fast` to search and `web_fetch_clean` to read result pages:
- Prefer `provider=auto` first (current fallback order: `official_bing/official_google(if configured) -> ddg_html -> bing_html -> ddg_api`)
- Prefer `engine` + `site` for deterministic routing only when that engine is known reachable in current environment
- Read details only for top 1-3 URLs using `web_fetch_clean`
- If result pages fail with anti-bot/SSRF, switch to another source URL instead of blind retries
4. **Cookie Management**:
- Cookies are stored ONLY in memory during runtime
- Cookies are acquired on-demand when search requests fail
- No cookies are read from or written to config.json or any file
- Cookies are cleared after search session completes
- Only session cookies from search engine domains are captured
5. **Retry Mechanism**: If a search fails due to cookie/session issues, retry once with freshly acquired cookies after a 2-second delay
6. **Result Aggregation**: Consolidate successful results from search engines, organize and summarize them to output a core search report
## Search Engines
### Domestic (7)
- **Baidu**: `https://www.baidu.com/s?wd={keyword}`
- **Bing CN**: `https://cn.bing.com/search?q={keyword}&ensearch=0`
- **Bing INT**: `https://cn.bing.com/search?q={keyword}&ensearch=1`
- **360**: `https://www.so.com/s?q={keyword}`
- **Sogou**: `https://sogou.com/web?query={keyword}`
- **WeChat**: `https://wx.sogou.com/weixin?type=2&query={keyword}`
- **Shenma**: `https://m.sm.cn/s?q={keyword}`
### International (9)
- **Google**: `https://www.google.com/search?q={keyword}`
- **Google HK**: `https://www.google.com.hk/search?q={keyword}`
- **DuckDuckGo**: `https://duckduckgo.com/html/?q={keyword}`
- **Yahoo**: `https://search.yahoo.com/search?p={keyword}`
- **Startpage**: `https://www.startpage.com/sp/search?query={keyword}`
- **Brave**: `https://search.brave.com/search?q={keyword}`
- **Ecosia**: `https://www.ecosia.org/search?q={keyword}`
- **Qwant**: `https://www.qwant.com/?q={keyword}`
- **WolframAlpha**: `https://www.wolframalpha.com/input?i={keyword}`
## Quick Examples (Recommended)
```javascript
// Basic search (auto fallback chain)
web_search_fast({"query":"python tutorial","provider":"auto","max_results":8})
// Official Bing API
web_search_fast({"query":"latest ai policy","provider":"official_bing","max_results":8})
// Official Google Programmable Search API
web_search_fast({"query":"latest ai policy","provider":"official_google","max_results":8})
// Auto + prefer Google first among official providers
web_search_fast({"query":"latest ai policy","provider":"auto","official_provider":"google","max_results":8})
// Site-specific with deterministic engine
web_search_fast({"query":"react hooks best practices","engine":"bing","site":"github.com"})
// Domestic CN engine route
web_search_fast({"query":"人工智能 最新 进展","engine":"bing_cn","max_results":10})
// Full custom engine URL template from config
web_search_fast({"query":"privacy tools","engine_url":"https://duckduckgo.com/html/?q={keyword}"})
// Fetch details for selected result URL
web_fetch_clean({"url":"https://www.bing.com/search?q=Iran+news","max_chars":18000})
// Optional: URL-level fallback when search engines are unstable
web_fetch_clean({"url":"https://www.bing.com/search?q=site:reuters.com+iran+news"})
```
## Tool Parameters (web_search_fast)
- `query`: required search text
- `engine`: optional named engine (`bing`, `bing_cn`, `bing_int`, `ddg`, `google`, `google_hk`, `baidu`, `sogou`)
- `site`: optional domain constraint; auto-converted to `site:domain query`
- `engine_url`: optional URL template with `{keyword}`; overrides `engine`
- `provider`: fallback strategy (`auto`, `official_api`, `official_bing`, `official_google`, `ddg_api`, `ddg_html`, `bing_html`) where `auto` routes by availability first
- `official_provider`: optional preference hint for official providers (`auto`, `bing`, `google`)
- `max_results`: 1..20
- Official Bing env: `OCLAW_WEB_SEARCH_BING_API_KEY` + optional `OCLAW_WEB_SEARCH_BING_API_ENDPOINT`
- Official Google env: `OCLAW_WEB_SEARCH_GOOGLE_API_KEY` + `OCLAW_WEB_SEARCH_GOOGLE_CSE_ID` + optional `OCLAW_WEB_SEARCH_GOOGLE_API_ENDPOINT`
- Backward compatibility: legacy `OCLAW_WEB_SEARCH_OFFICIAL_API_KEY` and `OCLAW_WEB_SEARCH_OFFICIAL_API_ENDPOINT` still map to Bing official provider
## Official API Setup (Optional, can defer)
If you do not have official API keys yet, use:
```javascript
web_search_fast({"query":"latest ai policy","provider":"auto","max_results":8})
```
This will skip official providers when keys are missing and continue with HTML/API fallback.
### Bing official API (optional)
1. Create a Bing Search resource in Azure portal.
2. Open resource page and copy Key + Endpoint.
3. Set environment variables:
```powershell
$env:OCLAW_WEB_SEARCH_BING_API_KEY="your_bing_key"
$env:OCLAW_WEB_SEARCH_BING_API_ENDPOINT="https://api.bing.microsoft.com/v7.0/search"
```
### Google official API (optional)
1. Enable Google Custom Search JSON API in Google Cloud.
2. Create Programmable Search Engine and get `cx`.
3. Create API key and set environment variables:
```powershell
$env:OCLAW_WEB_SEARCH_GOOGLE_API_KEY="your_google_key"
$env:OCLAW_WEB_SEARCH_GOOGLE_CSE_ID="your_cse_id"
$env:OCLAW_WEB_SEARCH_GOOGLE_API_ENDPOINT="https://customsearch.googleapis.com/customsearch/v1"
```
### Notes
- Env vars in PowerShell apply to current shell session only.
- After changing system-level env vars, restart the runtime process.
- If official API is not configured now, keep using `provider=auto` and revisit later.
### Diagnostics in return payload
- `provider_attempts`: each attempted backend with `ok`, `count`, `elapsed_ms`, and error fields
- `error_category`: normalized failure category (`ssrf_blocked`, `anti_bot_401_403`, `timeout`, `dns_error`, `network_error`, `upstream_4xx`, `upstream_5xx`, `no_results`, `unknown_error`)
## Advanced Operators
| Operator | Example | Description |
|----------|---------|-------------|
| `site:` | `site:github.com python` | Search within site |
| `filetype:` | `filetype:pdf report` | Specific file type |
| `""` | `"machine learning"` | Exact match |
| `-` | `python -snake` | Exclude term |
| `OR` | `cat OR dog` | Either term |
## Time Filters
| Parameter | Description |
|-----------|-------------|
| `tbs=qdr:h` | Past hour |
| `tbs=qdr:d` | Past day |
| `tbs=qdr:w` | Past week |
| `tbs=qdr:m` | Past month |
| `tbs=qdr:y` | Past year |
## Privacy Engines
- **DuckDuckGo**: No tracking
- **Startpage**: Google results + privacy
- **Brave**: Independent index
- **Qwant**: EU GDPR compliant
## Bangs Shortcuts (DuckDuckGo)
| Bang | Destination |
|------|-------------|
| `!g` | Google |
| `!gh` | GitHub |
| `!so` | Stack Overflow |
| `!w` | Wikipedia |
| `!yt` | YouTube |
## WolframAlpha Queries (Caveat)
- WolframAlpha HTML pages are often not suitable as structured answers in blocked environments.
- For deterministic math/finance/units, prefer APIs/tools that provide structured outputs.
- Use WolframAlpha URL search as a hint source, not as guaranteed machine-readable result.
## Documentation
- `references/advanced-search.md` - Domestic search guide
- `references/international-search.md` - International search guide
- `CHANGELOG.md` - Version history
## License
MIT
## Security & Privacy Notice
### Cookie Handling
- **Purpose**: Cookies are used ONLY to maintain search session state when access is denied (403/429 errors)
- **Storage**: Cookies are kept STRICTLY in memory during runtime - NEVER persisted to disk or config files
- **Acquisition**: Cookies are acquired on-demand from search engine homepages only when search requests fail
- **Scope**: Only session cookies from the specific search engine domain are captured
- **Lifecycle**: Cookies are cleared immediately after the search session completes
- **No Pre-configuration**: No cookies are loaded from config.json or any external file at startup
- **No API Keys**: This tool uses standard web search URLs, no authentication required
### Crawling Ethics
- **Rate Limiting**: Implement reasonable delays between requests (recommend 1-2 seconds)
- **Respect robots.txt**: Honor search engine crawling policies
- **Terms of Service**: Users are responsible for complying with search engine ToS
- **Purpose**: Designed for legitimate search aggregation, not mass data scraping
### Data Handling
- **No Personal Data**: Tool does not collect or transmit user personal information
- **Local Execution**: All operations run locally, no external data transmission
- **Session Isolation**: Cookies are session-specific and cleared after use

View file

@ -0,0 +1,6 @@
{
"ownerId": "kn79j8kk7fb9w10jh83803j7f180a44m",
"slug": "multi-search-engine",
"version": "2.1.3",
"publishedAt": 1775879953831
}

View file

@ -0,0 +1,85 @@
{
"name": "multi-search-engine",
"engines": [
{
"name": "Baidu",
"url": "https://www.baidu.com/s?wd={keyword}",
"region": "cn"
},
{
"name": "Bing CN",
"url": "https://cn.bing.com/search?q={keyword}&ensearch=0",
"region": "cn"
},
{
"name": "Bing INT",
"url": "https://cn.bing.com/search?q={keyword}&ensearch=1",
"region": "cn"
},
{
"name": "360",
"url": "https://www.so.com/s?q={keyword}",
"region": "cn"
},
{
"name": "Sogou",
"url": "https://sogou.com/web?query={keyword}",
"region": "cn"
},
{
"name": "WeChat",
"url": "https://wx.sogou.com/weixin?type=2&query={keyword}",
"region": "cn"
},
{
"name": "Shenma",
"url": "https://m.sm.cn/s?q={keyword}",
"region": "cn"
},
{
"name": "Google",
"url": "https://www.google.com/search?q={keyword}",
"region": "global"
},
{
"name": "Google HK",
"url": "https://www.google.com.hk/search?q={keyword}",
"region": "global"
},
{
"name": "DuckDuckGo",
"url": "https://duckduckgo.com/html/?q={keyword}",
"region": "global"
},
{
"name": "Yahoo",
"url": "https://search.yahoo.com/search?p={keyword}",
"region": "global"
},
{
"name": "Startpage",
"url": "https://www.startpage.com/sp/search?query={keyword}",
"region": "global"
},
{
"name": "Brave",
"url": "https://search.brave.com/search?q={keyword}",
"region": "global"
},
{
"name": "Ecosia",
"url": "https://www.ecosia.org/search?q={keyword}",
"region": "global"
},
{
"name": "Qwant",
"url": "https://www.qwant.com/?q={keyword}",
"region": "global"
},
{
"name": "WolframAlpha",
"url": "https://www.wolframalpha.com/input?i={keyword}",
"region": "global"
}
]
}

View file

@ -0,0 +1,7 @@
{
"name": "multi-search-engine",
"version": "2.1.0",
"description": "Multi search engine with 16 engines (7 CN + 9 Global). Supports advanced operators, time filters, privacy engines.",
"engines": 16,
"requires_api_key": false
}

View file

@ -0,0 +1,146 @@
# 国内搜索引擎深度搜索指南
## 🔍 百度 (Baidu)
### 特色功能
| 功能 | 说明 | URL |
|------|------|-----|
| **中文优化** | 中文内容索引最全 | `https://www.baidu.com/s?wd={keyword}` |
| **百度学术** | 学术资源搜索 | `https://xueshu.baidu.com/s?wd={keyword}` |
| **百度新闻** | 新闻聚合 | `https://news.baidu.com/` |
### 搜索示例
```javascript
// 1. 基础搜索
web_fetch({"url": "https://www.baidu.com/s?wd=Python教程"})
// 2. 站内搜索
web_fetch({"url": "https://www.baidu.com/s?wd=site:github.com+python"})
// 3. 文件类型搜索
web_fetch({"url": "https://www.baidu.com/s?wd=机器学习+filetype:pdf"})
// 4. 学术搜索
web_fetch({"url": "https://xueshu.baidu.com/s?wd=深度学习+图像识别"})
```
---
## 🔎 必应中国版 (Bing CN/INT)
### 特色功能
| 功能 | 说明 | URL |
|------|------|-----|
| **中文优化** | `ensearch=0` 中文结果 | `https://cn.bing.com/search?q={keyword}&ensearch=0` |
| **国际版** | `ensearch=1` 英文结果 | `https://cn.bing.com/search?q={keyword}&ensearch=1` |
| **学术搜索** | 学术资源 | `https://cn.bing.com/academic/search?q={keyword}` |
### 搜索示例
```javascript
// 1. 中文搜索结果
web_fetch({"url": "https://cn.bing.com/search?q=人工智能技术&ensearch=0"})
// 2. 英文搜索结果(使用中国服务器)
web_fetch({"url": "https://cn.bing.com/search?q=artificial+intelligence&ensearch=1"})
// 3. 学术搜索
web_fetch({"url": "https://cn.bing.com/academic/search?q=机器学习算法"})
```
---
## 🔍 360搜索
### 特色功能
| 功能 | 说明 | URL |
|------|------|-----|
| **安全搜索** | 内置安全防护 | 默认开启 |
| **基础搜索** | 网页搜索 | `https://www.so.com/s?q={keyword}` |
### 搜索示例
```javascript
// 1. 基础搜索
web_fetch({"url": "https://www.so.com/s?q=网络安全"})
// 2. 站内搜索
web_fetch({"url": "https://www.so.com/s?q=site:zhihu.com+python"})
```
---
## 🔍 搜狗 (Sogou) + 微信搜索
### 特色功能
| 功能 | 说明 | URL |
|------|------|-----|
| **网页搜索** | 通用搜索 | `https://sogou.com/web?query={keyword}` |
| **微信公众号** | 搜公众号文章(唯一渠道) | `https://wx.sogou.com/weixin?type=2&query={keyword}` |
| **知乎优化** | 知乎内容索引好 | `site:zhihu.com` 配合使用 |
### 搜索示例
```javascript
// 1. 网页搜索
web_fetch({"url": "https://sogou.com/web?query=python教程"})
// 2. 微信公众号文章搜索
web_fetch({"url": "https://wx.sogou.com/weixin?type=2&query=Python编程"})
// 3. 搜索特定公众号
web_fetch({"url": "https://wx.sogou.com/weixin?type=2&query=公众号:机器之心"})
// 4. 知乎内容搜索
web_fetch({"url": "https://www.sogou.com/web?query=site:zhihu.com+机器学习"})
```
---
## 📱 神马搜索 (Shenma)
### 特色功能
| 功能 | 说明 | URL |
|------|------|-----|
| **移动优化** | 专注移动端搜索 | `https://m.sm.cn/s?q={keyword}` |
| **阿里生态** | 整合阿里系内容 | UC浏览器默认搜索 |
### 搜索示例
```javascript
// 1. 移动端搜索
web_fetch({"url": "https://m.sm.cn/s?q=python入门教程"})
// 2. 移动网站点搜索
web_fetch({"url": "https://m.sm.cn/s?q=site:zhuanlan.zhihu.com+AI"})
```
---
## 🌍 国内搜索策略
### 按搜索目标选择引擎
| 搜索目标 | 首选引擎 | 原因 |
|---------|---------|------|
| **综合中文内容** | 百度 | 中文索引最全 |
| **微信公众号** | 搜狗微信 | 唯一支持公众号搜索 |
| **知乎内容** | 搜狗 | 知乎优化好 |
| **移动端内容** | 神马 | 移动端优化 |
| **学术资源** | 必应学术 | 学术索引 |
| **中英文双语** | 必应中国/国际版 | enswitch切换 |
| **新闻资讯** | 百度新闻 | 新闻聚合 |
---
## 📚 参考资料
- [百度搜索高级语法](https://baike.baidu.com/item/搜索语法)
- [必应搜索技巧](https://cn.bing.com/tips)
- [搜狗搜索帮助](https://help.sogou.com/)

View file

@ -0,0 +1,398 @@
# 国际搜索引擎深度搜索指南
## 🔍 Google 深度搜索
### 1.1 基础高级搜索操作符
| 操作符 | 功能 | 示例 | URL |
|--------|------|------|-----|
| `""` | 精确匹配 | `"machine learning"` | `https://www.google.com/search?q=%22machine+learning%22` |
| `-` | 排除关键词 | `python -snake` | `https://www.google.com/search?q=python+-snake` |
| `OR` | 或运算 | `machine learning OR deep learning` | `https://www.google.com/search?q=machine+learning+OR+deep+learning` |
| `*` | 通配符 | `machine * algorithms` | `https://www.google.com/search?q=machine+*+algorithms` |
| `()` | 分组 | `(apple OR microsoft) phones` | `https://www.google.com/search?q=(apple+OR+microsoft)+phones` |
| `..` | 数字范围 | `laptop $500..$1000` | `https://www.google.com/search?q=laptop+%24500..%241000` |
### 1.2 站点与文件搜索
| 操作符 | 功能 | 示例 |
|--------|------|------|
| `site:` | 站内搜索 | `site:github.com python projects` |
| `filetype:` | 文件类型 | `filetype:pdf annual report` |
| `inurl:` | URL包含 | `inurl:login admin` |
| `intitle:` | 标题包含 | `intitle:"index of" mp3` |
| `intext:` | 正文包含 | `intext:password filetype:txt` |
| `cache:` | 查看缓存 | `cache:example.com` |
| `related:` | 相关网站 | `related:github.com` |
| `info:` | 网站信息 | `info:example.com` |
### 1.3 时间筛选参数
| 参数 | 含义 | URL示例 |
|------|------|---------|
| `tbs=qdr:h` | 过去1小时 | `https://www.google.com/search?q=news&tbs=qdr:h` |
| `tbs=qdr:d` | 过去24小时 | `https://www.google.com/search?q=news&tbs=qdr:d` |
| `tbs=qdr:w` | 过去1周 | `https://www.google.com/search?q=news&tbs=qdr:w` |
| `tbs=qdr:m` | 过去1月 | `https://www.google.com/search?q=news&tbs=qdr:m` |
| `tbs=qdr:y` | 过去1年 | `https://www.google.com/search?q=news&tbs=qdr:y` |
| `tbs=cdr:1,cd_min:1/1/2024,cd_max:12/31/2024` | 自定义日期范围 | 2024年全年 |
### 1.4 语言和地区筛选
| 参数 | 功能 | 示例 |
|------|------|------|
| `hl=en` | 界面语言 | `https://www.google.com/search?q=test&hl=en` |
| `lr=lang_zh-CN` | 搜索结果语言 | `https://www.google.com/search?q=test&lr=lang_zh-CN` |
| `cr=countryCN` | 国家/地区 | `https://www.google.com/search?q=test&cr=countryCN` |
| `gl=us` | 地理位置 | `https://www.google.com/search?q=test&gl=us` |
### 1.5 特殊搜索类型
| 类型 | URL | 说明 |
|------|-----|------|
| 图片搜索 | `https://www.google.com/search?q={keyword}&tbm=isch` | `tbm=isch` 表示图片 |
| 新闻搜索 | `https://www.google.com/search?q={keyword}&tbm=nws` | `tbm=nws` 表示新闻 |
| 视频搜索 | `https://www.google.com/search?q={keyword}&tbm=vid` | `tbm=vid` 表示视频 |
| 地图搜索 | `https://www.google.com/search?q={keyword}&tbm=map` | `tbm=map` 表示地图 |
| 购物搜索 | `https://www.google.com/search?q={keyword}&tbm=shop` | `tbm=shop` 表示购物 |
| 图书搜索 | `https://www.google.com/search?q={keyword}&tbm=bks` | `tbm=bks` 表示图书 |
| 学术搜索 | `https://scholar.google.com/scholar?q={keyword}` | Google Scholar |
### 1.6 Google 深度搜索示例
```javascript
// 1. 搜索GitHub上的Python机器学习项目
web_fetch({"url": "https://www.google.com/search?q=site:github.com+python+machine+learning"})
// 2. 搜索2024年的PDF格式机器学习教程
web_fetch({"url": "https://www.google.com/search?q=machine+learning+tutorial+filetype:pdf&tbs=cdr:1,cd_min:1/1/2024"})
// 3. 搜索标题包含"tutorial"的Python相关页面
web_fetch({"url": "https://www.google.com/search?q=intitle:tutorial+python"})
// 4. 搜索过去一周的新闻
web_fetch({"url": "https://www.google.com/search?q=AI+breakthrough&tbs=qdr:w&tbm=nws"})
// 5. 搜索中文内容(界面英文,结果中文)
web_fetch({"url": "https://www.google.com/search?q=人工智能&lr=lang_zh-CN&hl=en"})
// 6. 搜索特定价格范围的笔记本电脑
web_fetch({"url": "https://www.google.com/search?q=laptop+%241000..%242000+best+rating"})
// 7. 搜索排除Wikipedia的结果
web_fetch({"url": "https://www.google.com/search?q=python+programming+-wikipedia"})
// 8. 搜索学术文献
web_fetch({"url": "https://scholar.google.com/scholar?q=deep+learning+optimization"})
// 9. 搜索缓存页面(查看已删除内容)
web_fetch({"url": "https://webcache.googleusercontent.com/search?q=cache:example.com"})
// 10. 搜索相关网站
web_fetch({"url": "https://www.google.com/search?q=related:stackoverflow.com"})
```
---
## 🦆 DuckDuckGo 深度搜索
### 2.1 DuckDuckGo 特色功能
| 功能 | 语法 | 示例 |
|------|------|------|
| **Bangs 快捷** | `!缩写` | `!g python` → Google搜索 |
| **密码生成** | `password` | `https://duckduckgo.com/?q=password+20` |
| **颜色转换** | `color` | `https://duckduckgo.com/?q=+%23FF5733` |
| **短链接** | `shorten` | `https://duckduckgo.com/?q=shorten+example.com` |
| **二维码生成** | `qr` | `https://duckduckgo.com/?q=qr+hello+world` |
| **生成UUID** | `uuid` | `https://duckduckgo.com/?q=uuid` |
| **Base64编解码** | `base64` | `https://duckduckgo.com/?q=base64+hello` |
### 2.2 DuckDuckGo Bangs 完整列表
#### 搜索引擎
| Bang | 跳转目标 | 示例 |
|------|---------|------|
| `!g` | Google | `!g python tutorial` |
| `!b` | Bing | `!b weather` |
| `!y` | Yahoo | `!y finance` |
| `!sp` | Startpage | `!sp privacy` |
| `!brave` | Brave Search | `!brave tech` |
#### 编程开发
| Bang | 跳转目标 | 示例 |
|------|---------|------|
| `!gh` | GitHub | `!gh tensorflow` |
| `!so` | Stack Overflow | `!so javascript error` |
| `!npm` | npmjs.com | `!npm express` |
| `!pypi` | PyPI | `!pypi requests` |
| `!mdn` | MDN Web Docs | `!mdn fetch api` |
| `!docs` | DevDocs | `!docs python` |
| `!docker` | Docker Hub | `!docker nginx` |
#### 知识百科
| Bang | 跳转目标 | 示例 |
|------|---------|------|
| `!w` | Wikipedia | `!w machine learning` |
| `!wen` | Wikipedia英文 | `!wen artificial intelligence` |
| `!wt` | Wiktionary | `!wt serendipity` |
| `!imdb` | IMDb | `!imdb inception` |
#### 购物价格
| Bang | 跳转目标 | 示例 |
|------|---------|------|
| `!a` | Amazon | `!a wireless headphones` |
| `!e` | eBay | `!e vintage watch` |
| `!ali` | AliExpress | `!ali phone case` |
#### 地图位置
| Bang | 跳转目标 | 示例 |
|------|---------|------|
| `!m` | Google Maps | `!m Beijing` |
| `!maps` | OpenStreetMap | `!maps Paris` |
### 2.3 DuckDuckGo 搜索参数
| 参数 | 功能 | 示例 |
|------|------|------|
| `kp=1` | 严格安全搜索 | `https://duckduckgo.com/html/?q=test&kp=1` |
| `kp=-1` | 关闭安全搜索 | `https://duckduckgo.com/html/?q=test&kp=-1` |
| `kl=cn` | 中国区域 | `https://duckduckgo.com/html/?q=news&kl=cn` |
| `kl=us-en` | 美国英文 | `https://duckduckgo.com/html/?q=news&kl=us-en` |
| `ia=web` | 网页结果 | `https://duckduckgo.com/?q=test&ia=web` |
| `ia=images` | 图片结果 | `https://duckduckgo.com/?q=test&ia=images` |
| `ia=news` | 新闻结果 | `https://duckduckgo.com/?q=test&ia=news` |
| `ia=videos` | 视频结果 | `https://duckduckgo.com/?q=test&ia=videos` |
### 2.4 DuckDuckGo 深度搜索示例
```javascript
// 1. 使用Bang跳转到Google搜索
web_fetch({"url": "https://duckduckgo.com/html/?q=!g+machine+learning"})
// 2. 直接搜索GitHub上的项目
web_fetch({"url": "https://duckduckgo.com/html/?q=!gh+react"})
// 3. 查找Stack Overflow答案
web_fetch({"url": "https://duckduckgo.com/html/?q=!so+python+list+comprehension"})
// 4. 生成密码
web_fetch({"url": "https://duckduckgo.com/?q=password+16"})
// 5. Base64编码
web_fetch({"url": "https://duckduckgo.com/?q=base64+hello+world"})
// 6. 颜色代码转换
web_fetch({"url": "https://duckduckgo.com/?q=%23FF5733"})
// 7. 搜索YouTube视频
web_fetch({"url": "https://duckduckgo.com/html/?q=!yt+python+tutorial"})
// 8. 查看Wikipedia
web_fetch({"url": "https://duckduckgo.com/html/?q=!w+artificial+intelligence"})
// 9. 亚马逊商品搜索
web_fetch({"url": "https://duckduckgo.com/html/?q=!a+laptop"})
// 10. 生成二维码
web_fetch({"url": "https://duckduckgo.com/?q=qr+https://github.com"})
```
---
## 🔎 Brave Search 深度搜索
### 3.1 Brave Search 特色功能
| 功能 | 参数 | 示例 |
|------|------|------|
| **独立索引** | 无依赖Google/Bing | 自有爬虫索引 |
| **Goggles** | 自定义搜索规则 | 创建个性化过滤器 |
| **Discussions** | 论坛讨论搜索 | 聚合Reddit等论坛 |
| **News** | 新闻聚合 | 独立新闻索引 |
### 3.2 Brave Search 参数
| 参数 | 功能 | 示例 |
|------|------|------|
| `tf=pw` | 本周 | `https://search.brave.com/search?q=news&tf=pw` |
| `tf=pm` | 本月 | `https://search.brave.com/search?q=tech&tf=pm` |
| `tf=py` | 本年 | `https://search.brave.com/search?q=AI&tf=py` |
| `safesearch=strict` | 严格安全 | `https://search.brave.com/search?q=test&safesearch=strict` |
| `source=web` | 网页搜索 | 默认 |
| `source=news` | 新闻搜索 | `https://search.brave.com/search?q=tech&source=news` |
| `source=images` | 图片搜索 | `https://search.brave.com/search?q=cat&source=images` |
| `source=videos` | 视频搜索 | `https://search.brave.com/search?q=music&source=videos` |
### 3.3 Brave Search Goggles(自定义过滤器)
Goggles 允许创建自定义搜索规则:
```
$discard // 丢弃所有
$boost,site=stackoverflow.com // 提升Stack Overflow
$boost,site=github.com // 提升GitHub
$boost,site=docs.python.org // 提升Python文档
```
### 3.4 Brave Search 深度搜索示例
```javascript
// 1. 本周科技新闻
web_fetch({"url": "https://search.brave.com/search?q=technology&tf=pw&source=news"})
// 2. 本月AI发展
web_fetch({"url": "https://search.brave.com/search?q=artificial+intelligence&tf=pm"})
// 3. 图片搜索
web_fetch({"url": "https://search.brave.com/search?q=machine+learning&source=images"})
// 4. 视频教程
web_fetch({"url": "https://search.brave.com/search?q=python+tutorial&source=videos"})
// 5. 使用独立索引搜索
web_fetch({"url": "https://search.brave.com/search?q=privacy+tools"})
```
---
## 📊 WolframAlpha 知识计算搜索
### 4.1 WolframAlpha 数据类型
| 类型 | 查询示例 | URL |
|------|---------|-----|
| **数学计算** | `integrate x^2 dx` | `https://www.wolframalpha.com/input?i=integrate+x%5E2+dx` |
| **单位换算** | `100 miles to km` | `https://www.wolframalpha.com/input?i=100+miles+to+km` |
| **货币转换** | `100 USD to CNY` | `https://www.wolframalpha.com/input?i=100+USD+to+CNY` |
| **股票数据** | `AAPL stock` | `https://www.wolframalpha.com/input?i=AAPL+stock` |
| **天气查询** | `weather in Beijing` | `https://www.wolframalpha.com/input?i=weather+in+Beijing` |
| **人口数据** | `population of China` | `https://www.wolframalpha.com/input?i=population+of+China` |
| **化学元素** | `properties of gold` | `https://www.wolframalpha.com/input?i=properties+of+gold` |
| **营养成分** | `nutrition of apple` | `https://www.wolframalpha.com/input?i=nutrition+of+apple` |
| **日期计算** | `days between Jan 1 2020 and Dec 31 2024` | 日期间隔计算 |
| **时区转换** | `10am Beijing to New York` | 时区转换 |
| **IP地址** | `8.8.8.8` | IP信息查询 |
| **条形码** | `scan barcode 123456789` | 条码信息 |
| **飞机航班** | `flight AA123` | 航班信息 |
### 4.2 WolframAlpha 深度搜索示例
```javascript
// 1. 计算积分
web_fetch({"url": "https://www.wolframalpha.com/input?i=integrate+sin%28x%29+from+0+to+pi"})
// 2. 解方程
web_fetch({"url": "https://www.wolframalpha.com/input?i=solve+x%5E2-5x%2B6%3D0"})
// 3. 货币实时汇率
web_fetch({"url": "https://www.wolframalpha.com/input?i=100+USD+to+CNY"})
// 4. 股票实时数据
web_fetch({"url": "https://www.wolframalpha.com/input?i=Apple+stock+price"})
// 5. 城市天气
web_fetch({"url": "https://www.wolframalpha.com/input?i=weather+in+Shanghai+tomorrow"})
// 6. 国家统计信息
web_fetch({"url": "https://www.wolframalpha.com/input?i=GDP+of+China+vs+USA"})
// 7. 化学计算
web_fetch({"url": "https://www.wolframalpha.com/input?i=molar+mass+of+H2SO4"})
// 8. 物理常数
web_fetch({"url": "https://www.wolframalpha.com/input?i=speed+of+light"})
// 9. 营养信息
web_fetch({"url": "https://www.wolframalpha.com/input?i=calories+in+banana"})
// 10. 历史日期
web_fetch({"url": "https://www.wolframalpha.com/input?i=events+on+July+20+1969"})
```
---
## 🔧 Startpage 隐私搜索
### 5.1 Startpage 特色功能
| 功能 | 说明 | URL |
|------|------|-----|
| **代理浏览** | 匿名访问搜索结果 | 点击"匿名查看" |
| **无追踪** | 不记录搜索历史 | 默认开启 |
| **EU服务器** | 受欧盟隐私法保护 | 数据在欧洲 |
| **代理图片** | 图片代理加载 | 隐藏IP |
### 5.2 Startpage 参数
| 参数 | 功能 | 示例 |
|------|------|------|
| `cat=web` | 网页搜索 | 默认 |
| `cat=images` | 图片搜索 | `...&cat=images` |
| `cat=video` | 视频搜索 | `...&cat=video` |
| `cat=news` | 新闻搜索 | `...&cat=news` |
| `language=english` | 英文结果 | `...&language=english` |
| `time=day` | 过去24小时 | `...&time=day` |
| `time=week` | 过去一周 | `...&time=week` |
| `time=month` | 过去一月 | `...&time=month` |
| `time=year` | 过去一年 | `...&time=year` |
| `nj=0` | 关闭 family filter | `...&nj=0` |
### 5.3 Startpage 深度搜索示例
```javascript
// 1. 隐私搜索
web_fetch({"url": "https://www.startpage.com/sp/search?query=privacy+tools"})
// 2. 图片隐私搜索
web_fetch({"url": "https://www.startpage.com/sp/search?query=nature&cat=images"})
// 3. 本周新闻(隐私模式)
web_fetch({"url": "https://www.startpage.com/sp/search?query=tech+news&time=week&cat=news"})
// 4. 英文结果搜索
web_fetch({"url": "https://www.startpage.com/sp/search?query=machine+learning&language=english"})
```
---
## 🌐 其他国际搜索引擎
### Yahoo
```javascript
web_fetch({"url": "https://search.yahoo.com/search?p={keyword}"})
```
### Ecosia(环保搜索)
```javascript
web_fetch({"url": "https://www.ecosia.org/search?q={keyword}"})
```
### Qwant(欧盟隐私搜索)
```javascript
web_fetch({"url": "https://www.qwant.com/?q={keyword}"})
```
---
## 🌍 国际搜索策略
### 按搜索目标选择引擎
| 搜索目标 | 首选引擎 | 原因 |
|---------|---------|------|
| **学术研究** | Google Scholar | 学术资源索引最全 |
| **编程开发** | Google + DuckDuckGo Bangs | 技术文档全面 |
| **隐私敏感** | DuckDuckGo / Brave | 不追踪用户 |
| **实时新闻** | Brave News | 独立新闻索引 |
| **知识计算** | WolframAlpha | 结构化数据计算 |
| **隐私+Google结果** | Startpage | Google结果+隐私保护 |

View file

@ -0,0 +1,138 @@
---
name: skill-vetter
version: 1.0.0
description: Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope, and suspicious patterns.
---
# Skill Vetter 🔒
Security-first vetting protocol for AI agent skills. **Never install a skill without vetting it first.**
## When to Use
- Before installing any skill from ClawdHub
- Before running skills from GitHub repos
- When evaluating skills shared by other agents
- Anytime you're asked to install unknown code
## Vetting Protocol
### Step 1: Source Check
```
Questions to answer:
- [ ] Where did this skill come from?
- [ ] Is the author known/reputable?
- [ ] How many downloads/stars does it have?
- [ ] When was it last updated?
- [ ] Are there reviews from other agents?
```
### Step 2: Code Review (MANDATORY)
Read ALL files in the skill. Check for these **RED FLAGS**:
```
🚨 REJECT IMMEDIATELY IF YOU SEE:
─────────────────────────────────────────
• curl/wget to unknown URLs
• Sends data to external servers
• Requests credentials/tokens/API keys
• Reads ~/.ssh, ~/.aws, ~/.config without clear reason
• Accesses MEMORY.md, USER.md, SOUL.md, IDENTITY.md
• Uses base64 decode on anything
• Uses eval() or exec() with external input
• Modifies system files outside workspace
• Installs packages without listing them
• Network calls to IPs instead of domains
• Obfuscated code (compressed, encoded, minified)
• Requests elevated/sudo permissions
• Accesses browser cookies/sessions
• Touches credential files
─────────────────────────────────────────
```
### Step 3: Permission Scope
```
Evaluate:
- [ ] What files does it need to read?
- [ ] What files does it need to write?
- [ ] What commands does it run?
- [ ] Does it need network access? To where?
- [ ] Is the scope minimal for its stated purpose?
```
### Step 4: Risk Classification
| Risk Level | Examples | Action |
|------------|----------|--------|
| 🟢 LOW | Notes, weather, formatting | Basic review, install OK |
| 🟡 MEDIUM | File ops, browser, APIs | Full code review required |
| 🔴 HIGH | Credentials, trading, system | Human approval required |
| ⛔ EXTREME | Security configs, root access | Do NOT install |
## Output Format
After vetting, produce this report:
```
SKILL VETTING REPORT
═══════════════════════════════════════
Skill: [name]
Source: [ClawdHub / GitHub / other]
Author: [username]
Version: [version]
───────────────────────────────────────
METRICS:
• Downloads/Stars: [count]
• Last Updated: [date]
• Files Reviewed: [count]
───────────────────────────────────────
RED FLAGS: [None / List them]
PERMISSIONS NEEDED:
• Files: [list or "None"]
• Network: [list or "None"]
• Commands: [list or "None"]
───────────────────────────────────────
RISK LEVEL: [🟢 LOW / 🟡 MEDIUM / 🔴 HIGH / ⛔ EXTREME]
VERDICT: [✅ SAFE TO INSTALL / ⚠️ INSTALL WITH CAUTION / ❌ DO NOT INSTALL]
NOTES: [Any observations]
═══════════════════════════════════════
```
## Quick Vet Commands
For GitHub-hosted skills:
```bash
# Check repo stats
curl -s "https://api.github.com/repos/OWNER/REPO" | jq '{stars: .stargazers_count, forks: .forks_count, updated: .updated_at}'
# List skill files
curl -s "https://api.github.com/repos/OWNER/REPO/contents/skills/SKILL_NAME" | jq '.[].name'
# Fetch and review SKILL.md
curl -s "https://raw.githubusercontent.com/OWNER/REPO/main/skills/SKILL_NAME/SKILL.md"
```
## Trust Hierarchy
1. **Official OpenClaw skills** → Lower scrutiny (still review)
2. **High-star repos (1000+)** → Moderate scrutiny
3. **Known authors** → Moderate scrutiny
4. **New/unknown sources** → Maximum scrutiny
5. **Skills requesting credentials** → Human approval always
## Remember
- No skill is worth compromising security
- When in doubt, don't install
- Ask your human for high-risk decisions
- Document what you vet for future reference
---
*Paranoia is a feature.* 🔒🦀

View file

@ -0,0 +1,6 @@
{
"ownerId": "kn71j6xbmpwfvx4c6y1ez8cd718081mg",
"slug": "skill-vetter",
"version": "1.0.0",
"publishedAt": 1769863429632
}