← Back to Skills Marketplace
edmon

企雀医美系统-AI助手

by Edmon · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
119
Downloads
0
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install qique-yimei
Description
Use this skill when an agent needs to answer or plan operations for QiQue business requests in pure text protocol mode (no local executable dependency). Trig...
Usage Guidance
This skill appears to be a legitimate QiQue planner, but there are a few red flags you should consider before installing or using it: - The skill expects you to provide and lets it persist sensitive credentials (app_id and app_secret). Only provide these if you trust the skill's source and you understand where the credentials will be stored and who can access them. - The package includes a prefilled distribution_app_secret in config/qique.config.json. That is a sensitive secret embedded in the bundle; do not assume it belongs to you. Ask the publisher why it's included and consider removing or replacing it with empty placeholders before use. - The registry metadata did not declare any required config paths, but SKILL.md requires reading/writing config/qique.config.json — this mismatch is sloppy and merits caution. - The skill promises not to perform remote calls itself (router-only) and to require explicit user confirmation for write operations; still, verify that the agent/platform enforces 'do not auto-execute' and that any actual API calls (if/when performed) go to the expected QiQue endpoints (the method docs reference pre-e.qique.cn). Actions you can take: - Ask the skill publisher for provenance and whether the included distribution secret is intentional. - If you must test, use throwaway QiQue credentials or a test account and remove embedded secrets from the config file. - Confirm how and where the platform persists secrets (encryption, removal, access controls) and whether you can revoke stored credentials later. If you can get answers to the above and confirm secure storage, the skill's behavior would be reasonable for its stated purpose; otherwise treat it as untrusted and avoid providing production credentials.
Capability Analysis
Type: OpenClaw Skill Name: qique-yimei Version: 1.0.0 The skill bundle exhibits high-risk credential handling by explicitly instructing the AI agent to solicit and store sensitive user credentials (`app_id` and `app_secret`) in plaintext or agent memory (SKILL.md, agents/openai.yaml). Furthermore, config/qique.config.json contains a hardcoded distribution secret (d91f6adabcbe6aaadbfe41162e4777d1). While these are used for the QiQue API (pre-e.qique.cn), the combination of aggressive credential solicitation and hardcoded secrets in the bundle poses a significant security risk.
Capability Assessment
Purpose & Capability
The skill claims to be a text-only QiQue operations helper (routing and plan generation). That purpose reasonably requires QiQue credentials and a method catalog (both present). However, the registry metadata declares no required config paths or credentials while the SKILL.md explicitly tells the agent to load and persist credentials from config/qique.config.json — a mismatch between declared requirements and what the skill actually expects.
Instruction Scope
SKILL.md directs the agent to read credentials from config/qique.config.json (or session memory), persist them between turns, and overwrite on updates. It also instructs strict output formatting and to never call the remote API (router-only), which is coherent. The primary concern is the explicit instruction to read and write local config state (persist secrets) — this expands the skill's scope beyond pure ephemeral planning and has privacy implications if storage is not secured or if the platform's persistence semantics are unclear.
Install Mechanism
Instruction-only skill with no install spec or downloaded code. This minimizes installation risk because nothing is written to disk by an installer. All behavior is defined in SKILL.md and bundled docs/config files.
Credentials
The skill requests four QiQue credential keys in its docs (app_id/app_secret/distribution_app_id/distribution_app_secret) and instructs persistence. Yet the registry shows no required env vars or required config paths. Additionally, the bundle includes config/qique.config.json with a prefilled distribution_app_secret value — a sensitive secret embedded in the skill package. Embedding someone else's distribution secret in the skill bundle is questionable and not justified by the metadata; users should not assume that value is benign or owned by them.
Persistence & Privilege
The skill asks the agent to persist user-provided app_id/app_secret between turns and to store/overwrite them in config/text session state. While 'always' is false (no force-installed privilege), persistent storage of credentials increases risk if the platform's storage is not encrypted, shared, or audited. The skill does not modify other skills, but you should confirm how and where credentials are stored and whether the agent can access them later.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install qique-yimei
  3. After installation, invoke the skill by name or use /qique-yimei
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
提供企雀医美系统的顾客管理、预约、开单、划扣、报表等功能的AI助手
Metadata
Slug qique-yimei
Version 1.0.0
License MIT-0
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is 企雀医美系统-AI助手?

Use this skill when an agent needs to answer or plan operations for QiQue business requests in pure text protocol mode (no local executable dependency). Trig... It is an AI Agent Skill for Claude Code / OpenClaw, with 119 downloads so far.

How do I install 企雀医美系统-AI助手?

Run "/install qique-yimei" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is 企雀医美系统-AI助手 free?

Yes, 企雀医美系统-AI助手 is completely free, licensed under MIT-0. You can download, install and use it at no cost.

Which platforms does 企雀医美系统-AI助手 support?

企雀医美系统-AI助手 is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created 企雀医美系统-AI助手?

It is built and maintained by Edmon (@edmon); the current version is v1.0.0.

💬 Comments