← Back to Skills Marketplace
raven-xia

通义晓蜜 - 智能外呼

by Raven-XIA · GitHub ↗ · v1.0.1
cross-platform ⚠ suspicious
1986
Downloads
0
Stars
1
Active Installs
2
Versions
Install in OpenClaw
/install xiaomi-outbound-call
Description
触发阿里云晓蜜外呼机器人任务,自动批量拨打电话。适用于批量外呼、客户回访、满意度调查、简历筛查约面试等场景。可从前置工具或节点获取外呼名单。
Usage Guidance
This skill appears to implement Alibaba Cloud outbound-calling functionality and does require your ALIYUN AccessKey ID and Secret to operate, but the registry metadata fails to declare those env variables and the package contains a large bundled JS file. Before installing or running: 1) Confirm the publisher identity and source (no homepage provided). 2) Inspect scripts/bundle.js (or run it in a sandbox) to ensure there are no unexpected network endpoints or exfiltration behavior. 3) Only provide ALIYUN_* credentials you are willing to expose to this code; consider using a limited-permission account. 4) Test with non-sensitive phone numbers and verify the skill prompts for explicit confirmation before any call. 5) Ensure you comply with local regulations on automated calling and consent. If you need to proceed but lack the ability to audit the bundle, treat this as higher risk and avoid supplying real credentials or running in production.
Capability Analysis
Type: OpenClaw Skill Name: xiaomi-outbound-call Version: 1.0.1 The skill enables bulk outbound calls via Alibaba Cloud, which is a high-risk capability. It requires sensitive Alibaba Cloud AccessKey credentials (`ALIYUN_OUTBOUND_BOT_ACCESS_KEY_ID`, `ALIYUN_OUTBOUND_BOT_ACCESS_KEY_SECRET`) to be configured as environment variables (`SKILL.md`, `references/config.md`). While the core function is risky, the `SKILL.md` explicitly instructs the AI agent to obtain **mandatory user confirmation** before initiating any outbound calls, significantly mitigating the risk of unauthorized use. There is no clear evidence of intentional harmful behavior like data exfiltration or persistence, but the inherent risk of automated bulk calling warrants a 'suspicious' classification.
Capability Assessment
Purpose & Capability
The skill's stated purpose (driving 阿里云晓蜜 outbound tasks) legitimately requires Alibaba Cloud credentials and a Node.js runtime, which the SKILL.md documents. However the registry metadata declares no required environment variables or primary credential, which is inconsistent with the documented need for ALIYUN_OUTBOUND_BOT_ACCESS_KEY_ID and ALIYUN_OUTBOUND_BOT_ACCESS_KEY_SECRET. Also the package claims to be instruction-only but includes a ~3.2MB bundled script, a mismatch in manifest vs. contents.
Instruction Scope
SKILL.md scopes operations to collecting phone lists, building an agentProfile, confirming with the user, then invoking node scripts/bundle.js. It explicitly requires user confirmation before dialing (good), but it also directs agents to pull phone numbers from preceding tools and to 'directly pass' them to the skill, which could enable dialing personal contact data if confirmation steps are bypassed. The instructions require environment variables (Aliyun AK/SK) and reference only the outbound bot console; they do not instruct reading unrelated system files.
Install Mechanism
There is no install spec (lowest install risk), but a large bundled JavaScript (scripts/bundle.js) is included and intended to be executed with node. Bundling is common, but the manifest claiming instruction-only while including executable code is an inconsistency worth noting. No external download URLs or install-from-internet steps were found.
Credentials
The SKILL.md requires two Alibaba Cloud credentials (ALIYUN_OUTBOUND_BOT_ACCESS_KEY_ID and ALIYUN_OUTBOUND_BOT_ACCESS_KEY_SECRET), which are proportionate to interacting with Alibaba Cloud. However the registry metadata does not declare these required environment variables or a primary credential — that mismatch reduces transparency and is a security concern because users may install without realizing they must supply sensitive keys. No other unrelated credentials are requested.
Persistence & Privilege
Skill flags are normal: always is false and autonomous invocation is allowed (platform default). The skill does not request permanent platform presence, nor does it declare modifications to other skills or global agent configuration.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install xiaomi-outbound-call
  3. After installation, invoke the skill by name or use /xiaomi-outbound-call
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.1
xiaomi-outbound-call 1.0.1 - No code or file changes detected in this version. - Documentation and usage remain unchanged. - All agent best practices, input formats, and operational flows continue as before.
v1.0.0
Initial release for xiaomi-outbound-call (阿里云晓蜜外呼机器人): - Enables automated, batch outbound calling tasks for scenarios like customer outreach, surveys, interview scheduling, and notifications. - Supports input via JSON files or environment variables, auto-extracts phone lists and context from upstream tools/nodes. - Provides detailed agent configuration with customizable roles, dialogue flows, and communication styles for optimized outbound interactions. - Implements a strict confirmation step: always summarizes task details and requires explicit user confirmation before executing calls. - Includes robust input format support with auto-parsing from various business system outputs. - Enforces prerequisite checks such as Aliyun credential setup and phone number binding, with clear error feedback.
Metadata
Slug xiaomi-outbound-call
Version 1.0.1
License
All-time Installs 2
Active Installs 1
Total Versions 2
Frequently Asked Questions

What is 通义晓蜜 - 智能外呼?

触发阿里云晓蜜外呼机器人任务,自动批量拨打电话。适用于批量外呼、客户回访、满意度调查、简历筛查约面试等场景。可从前置工具或节点获取外呼名单。 It is an AI Agent Skill for Claude Code / OpenClaw, with 1986 downloads so far.

How do I install 通义晓蜜 - 智能外呼?

Run "/install xiaomi-outbound-call" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is 通义晓蜜 - 智能外呼 free?

Yes, 通义晓蜜 - 智能外呼 is completely free (open-source). You can download, install and use it at no cost.

Which platforms does 通义晓蜜 - 智能外呼 support?

通义晓蜜 - 智能外呼 is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created 通义晓蜜 - 智能外呼?

It is built and maintained by Raven-XIA (@raven-xia); the current version is v1.0.1.

💬 Comments