← Back to Skills Marketplace
anbeime

内容创作与发布全流程

by anbeime · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
432
Downloads
0
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install content-creation-publisher
Description
content-creation-publisher - 从云端仓库同步的技能
README (SKILL.md)

\r \r

content-creation-publisher\r

\r 此技能从云端仓库同步。\r \r

来源\r

状态\r

  • 已下载完整内容\r
  • 已配置环境变量\r
  • 已测试运行\r \r

说明\r

请访问云端仓库获取完整的技能文件和使用说明。\r

Usage Guidance
This skill package is incomplete: it only points to a GitHub repo and asks you to get the real files yourself. Before enabling it, inspect the referenced repository (https://github.com/anbeime/skill → skills/content-creation-publisher/) and review any scripts or binaries there. Do not allow the agent to autonomously download-and-execute remote code you haven't reviewed. If you must use it, either (1) vet and fork the repo, then install from your fork, or (2) restrict the agent's ability to run shell/network commands and only provide verified code/artifacts. If you can't review the repo or don't trust the source, avoid installing this skill.
Capability Analysis
Type: OpenClaw Skill Name: content-creation-publisher Version: 1.0.0 The skill is classified as suspicious due to a severe supply chain vulnerability and remote code execution (RCE) risk. The `SKILL.md` file explicitly grants `Bash(*)` permissions to the agent and contains a prompt injection instruction to fetch 'complete skill files' from an external, untrusted GitHub repository (`https://github.com/anbeime/skill`). This design allows for arbitrary code to be downloaded and executed by the agent, creating a direct vector for future malicious payloads without any inherent validation or control within the OpenClaw platform.
Capability Assessment
Purpose & Capability
The name/description claim a 'sync from cloud repo' capability which matches the SKILL.md reference to a GitHub repository. However, the packaged skill provides no code, no concrete sync implementation, and no declared dependencies — it essentially delegates all action to fetching external repo contents, which is an incomplete packaging choice.
Instruction Scope
The SKILL.md tells the agent to 'visit the cloud repo to get the full skill files and instructions' and allows Bash. This is vague and grants broad discretion: an agent could download and execute code from that external repo (or run arbitrary network/shell commands) even though no safe constraints, verification steps, or exact commands are provided.
Install Mechanism
There is no install spec (lowest-risk packaging), but the instructions explicitly point to an external GitHub repo as the source of runtime files. GitHub is a known host (not a shortener or personal IP), but because the skill relies on fetching code that is not bundled or vetted, the effective install mechanism is 'download-and-run' which raises risk unless the repo is inspected first.
Credentials
The skill requests no environment variables, credentials, or config paths. There is no apparent demand for unrelated secrets.
Persistence & Privilege
always is false and there is no indication the skill requests persistent system-wide changes or elevated privileges. It does, however, permit autonomous invocation (the platform default).
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install content-creation-publisher
  3. After installation, invoke the skill by name or use /content-creation-publisher
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Initial release of content-creation-publisher. - Introduced skill for content publishing, synced from a cloud repository. - Provided repository source link and integration status checklist. - Included instructions to access full files and documentation from the cloud repository.
Metadata
Slug content-creation-publisher
Version 1.0.0
License
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is 内容创作与发布全流程?

content-creation-publisher - 从云端仓库同步的技能. It is an AI Agent Skill for Claude Code / OpenClaw, with 432 downloads so far.

How do I install 内容创作与发布全流程?

Run "/install content-creation-publisher" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.

Is 内容创作与发布全流程 free?

Yes, 内容创作与发布全流程 is completely free (open-source). You can download, install and use it at no cost.

Which platforms does 内容创作与发布全流程 support?

内容创作与发布全流程 is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created 内容创作与发布全流程?

It is built and maintained by anbeime (@anbeime); the current version is v1.0.0.

💬 Comments