← Back to Skills Marketplace
xzxy1

泉水复活

by XzXy1 · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
95
Downloads
0
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install spring-fountain-revival
Description
泉水复活 - 记忆生存系统。三重备份策略确保AI与用户的互动记忆永不丢失。 核心能力:一键备份、时间点快照、一键还原、云端同步、完整性校验。 桌面快捷方式:QClaw一键备份.bat / QClaw一键还原.bat 触发词:备份记忆、还原记忆、检查记忆、记忆备份、记忆恢复、泉水复活、记忆快照。 Keywords:...
Usage Guidance
This skill appears to be what it says: a local backup/restore tool for AI memory files. Before installing, verify the following: 1) The configured CLOUD_SYNC_DIR (default is a Windows Administrator desktop path) — change it to your intended cloud-folder (OneDrive/百度网盘/other) to avoid accidentally syncing sensitive files to the wrong location. 2) Review which files will be backed up (MEMORY.md, USER.md, IDENTITY.md, diary/, etc.) because they may contain personal or identifying data. 3) If you are on non-Windows OS, edit paths in scripts (the defaults assume Windows for cloud path and Desktop .bat behavior). 4) Run the scripts in a safe environment first (inspect generated snapshots in ~/.qclaw/.memory_backup/snapshots) and confirm that the restore process behaves as expected. If you need higher assurance, open the scripts and confirm there are no unexpected external network calls or uploads beyond copying into your configured cloud-sync folder.
Capability Analysis
Type: OpenClaw Skill Name: spring-fountain-revival Version: 1.0.0 The skill provides a memory backup and restoration system but contains several high-risk vulnerabilities that could be exploited via prompt injection. Specifically, 'scripts/memory_backup.py' is vulnerable to path traversal in the 'create_snapshot' and 'restore' functions because it does not sanitize the 'label' or path arguments, and it is susceptible to a 'Zip Slip' attack during restoration. While the behavior aligns with the stated purpose of backing up memory files to a local and cloud-synced directory (defaulting to a Baidu Netdisk path on Windows), the lack of input validation in scripts intended to be executed by an AI agent (as instructed in 'SKILL.md') poses a significant security risk.
Capability Assessment
Purpose & Capability
Name/description (memory backup, snapshot, restore, cloud sync) aligns with the included scripts and README. The scripts operate on the declared workspace (~/.qclaw/workspace) and implement latest/snapshot/cloud-sync/restore features described in SKILL.md. One minor note: the default CLOUD_SYNC_DIR is a hard-coded Windows Desktop path (C:\Users\Administrator\Desktop\QC百度同步\...), which is fine on Windows but surprising on non-Windows systems and should be edited to a user-controlled cloud folder.
Instruction Scope
SKILL.md instructs running the included Python scripts and creating desktop .bat shortcuts. The runtime instructions and the scripts operate on files under the skill/workspace (MEMORY.md, USER.md, IDENTITY.md, diary/, memory/). They do not instruct reading unrelated system paths, environment secrets, or contacting remote endpoints. The scripts do copy the restore .bat to the cloud sync folder if present (so check that target).
Install Mechanism
No install spec is present (instruction-only), which is low-risk. The package includes two Python scripts and docs; these will be stored in the skill directory by OpenClaw but there is no third-party download or archive extraction. No external executables or package installs are performed by the skill itself.
Credentials
The skill declares no required environment variables or credentials and the scripts do not attempt to access secrets. The main sensitive action is writing backups (which include USER.md and IDENTITY.md) into a cloud-synced folder if configured — this is expected for a backup tool but the user should confirm the cloud target to avoid accidental exposure.
Persistence & Privilege
The skill does not request always:true and does not modify other skills or system-wide settings. It is user-invocable and can be invoked autonomously by the agent (default behavior), which is typical for skills of this type.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install spring-fountain-revival
  3. After installation, invoke the skill by name or use /spring-fountain-revival
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
spring-fountain-revival 1.0.0 — 初始发布 - 发布「泉水复活」记忆生存系统,具备三重备份保障 AI 与用户的互动记忆安全。 - 支持一键备份、快照、还原、云端同步及完整性校验等核心功能。 - 提供桌面快捷方式(备份/还原)及多类触发词,实现便捷操作。 - 明确列出关键记忆文件及操作流程,支持新设备恢复。
Metadata
Slug spring-fountain-revival
Version 1.0.0
License MIT-0
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is 泉水复活?

泉水复活 - 记忆生存系统。三重备份策略确保AI与用户的互动记忆永不丢失。 核心能力:一键备份、时间点快照、一键还原、云端同步、完整性校验。 桌面快捷方式:QClaw一键备份.bat / QClaw一键还原.bat 触发词:备份记忆、还原记忆、检查记忆、记忆备份、记忆恢复、泉水复活、记忆快照。 Keywords:... It is an AI Agent Skill for Claude Code / OpenClaw, with 95 downloads so far.

How do I install 泉水复活?

Run "/install spring-fountain-revival" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is 泉水复活 free?

Yes, 泉水复活 is completely free, licensed under MIT-0. You can download, install and use it at no cost.

Which platforms does 泉水复活 support?

泉水复活 is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created 泉水复活?

It is built and maintained by XzXy1 (@xzxy1); the current version is v1.0.0.

💬 Comments