โ† Back to Skills Marketplace
ybridge

Super Lobster

by YBridge ยท GitHub โ†— ยท v1.0.0 ยท MIT-0
cross-platform โš  suspicious
84
Downloads
0
Stars
0
Active Installs
1
Versions
Install in OpenClaw
/install wong-super-lobster
Description
๐Ÿฆž Super Lobster | ่ถ…็บง้พ™่™พ - ๆกฅๅ“ฅ็š„็งไบบ AI ๅŠฉ็† ๆ•ดๅˆไบ†้ฃžไนฆๆ–‡ๆกฃ็ฎก็†ใ€ไผš่ฎฎ็บช่ฆๆ•ด็†ใ€ๆฏๆ—ฅๅพ…ๅŠžๆŽจ้€ใ€ๅทฅไฝœๆจกๅ—ๅˆ†็ฑป็ญ‰ๆ ธๅฟƒๆŠ€่ƒฝใ€‚ ่ƒฝๅคŸ่‡ชๅŠจ่ฏปๅ–ไผš่ฎฎ็บช่ฆใ€ๆŒ‰ๅทฅไฝœๆจกๅ—ๅˆ†็ฑปๆ•ด็†ๅพ…ๅŠžไบ‹้กนใ€ๅˆ›ๅปบ้ฃžไนฆๆ–‡ๆกฃๅนถๆŽจ้€ใ€‚ ๆ ธๅฟƒ่ƒฝๅŠ›๏ผš - ๐Ÿ“„ ้ฃžไนฆๆ–‡ๆกฃๅˆ›ๅปบ๏ผˆๆ”ฏๆŒ 100+ blocks ๅคงๆ–‡ๆกฃ๏ผ‰ - ๐Ÿ“‹ ไผš่ฎฎ็บช...
Usage Guidance
Do not run or install this skill as-is. The code includes embedded Feishu credentials (APP_SECRET/APP_ID/USER_OPEN_ID) that should never be committed to a public or shared repo. Before using this skill: 1) Ask the author to remove hard-coded secrets and to accept credentials via environment variables or a secure platform secret manager; 2) Rotate any exposed credentials immediately (treat the included APP_SECRET as compromised); 3) Verify the repository's origin and the author's identity (there is a github link in metadataโ€”confirm it exists and matches the published package); 4) Review and restrict the Feishu app permissions to the minimum necessary (docx write, permission manage, message send are powerful); 5) Run the code in an isolated/test environment and inspect other scripts (read_meeting_notes.mjs, classify_by_module.mjs) before granting it access to real data; 6) If you need automated deployment, require the skill to document exactly which environment variables it expects and avoid any embedded credentials. These steps will reduce the risk of credential exposure or unintended data access.
Capability Analysis
Type: OpenClaw Skill Name: wong-super-lobster Version: 1.0.0 The skill bundle contains hardcoded sensitive credentials, specifically a Feishu 'APP_SECRET' and 'USER_OPEN_ID' within 'scripts/create_daily_todo.mjs' and 'clawhub.json'. The script is designed to automatically grant 'edit' permissions to the hardcoded 'USER_OPEN_ID' for any documents it creates. While this appears to be a poorly secured private tool rather than intentional malware, the exposure of API secrets and hardcoded access control mechanisms represent significant security vulnerabilities.
Capability Assessment
โ„น Purpose & Capability
The name/description (Feishu document creation, meeting-note parsing, todo push, permission management) align with the included files and the Node script, which uses the Lark/Feishu SDK and lists appropriate Feishu permissions (docx write, permission manage, message send). The skill does not request unrelated system-level binaries or capabilities.
โœ“ Instruction Scope
SKILL.md instructions are limited to cloning the skill, adding an agent entry to ~/.openclaw/openclaw.json, optionally adding cron/heartbeat entries, reading Feishu meeting notes, creating documents and setting permissions. The instructions do instruct the user to write into their OpenClaw config and workspace directories (e.g., ~/.openclaw), which is expected for an agent skill.
โ„น Install Mechanism
There is no automated install spec (instruction-only) so nothing is downloaded or executed automatically by the platform. The code requires Node (>=25) and the Lark SDK when run, but users must install dependencies themselves. This lowers some supply-chain risk, but the presence of runnable script files means the repository will execute code on installation if the user runs them.
โš  Credentials
The package contains hard-coded Feishu credentials and IDs instead of declaring them as required environment variables. scripts/create_daily_todo.mjs includes APP_ID and APP_SECRET values and USER_OPEN_ID; clawhub.json also contains feishu.appId and userOpenId. These are sensitive and should not be embedded in distributed code. The skill metadata declares Feishu permissions consistent with its stated purpose, but embedding credentials in the repo is disproportionate and risky.
โœ“ Persistence & Privilege
The skill is not force-included (always: false) and is user-invocable. It does not request special platform privileges beyond being registered as an agent for a channel (as documented). It writes/reads files within its own workspace and asks users to add entries to their OpenClaw configโ€”this is normal and scoped to the skill.
How to Use
  1. Make sure OpenClaw is installed (local or Docker)
  2. Run the install command in chat: /install wong-super-lobster
  3. After installation, invoke the skill by name or use /wong-super-lobster
  4. Provide required inputs per the skill's parameter spec and get structured output
Version History
v1.0.0
Super Lobster v1.0.0 - Initial Release - ๅ…จ้ข้‡ๆž„ไธบ้ฃžไนฆ้ซ˜ๆ•ˆๅทฅไฝœๅŠฉๆ‰‹๏ผŒ่š็„ฆๆ–‡ๆกฃ็ฎก็†ใ€ไผš่ฎฎ็บช่ฆๆ•ด็†ใ€ๆฏๆ—ฅๅพ…ๅŠžๆŽจ้€ไธŽ่‡ชๅŠจๅˆ†็ฑปใ€‚ - ๆ–ฐๅขžๆ”ฏๆŒ็™พๅ—้ฃžไนฆๆ–‡ๆกฃ่‡ชๅŠจ็”Ÿๆˆใ€ๅพ…ๅŠžไธŽไผš่ฎฎ็บช่ฆๆ™บ่ƒฝๆŠ“ๅ–ใ€ๅˆ†็ฑปไธŽ่‡ชๅŠจๆŽจ้€ใ€‚ - ๅขžๅผบ้ฃžไนฆๆƒ้™็ฎก็†ใ€ๅฎšๆ—ถไปปๅŠกๅ’Œๅคšๆจกๆฟๆ”ฏๆŒใ€‚ - ็งป้™คๅŽŸๆœ‰้€š็”จ็ฝ‘็ปœ็ˆฌๅ–ไธŽ่„šๆœฌๅทฅๅ…ท๏ผŒๅ…จ้ขๅˆ‡ๆขไธบ้ฃžไนฆๅœบๆ™ฏไธŽ็”ŸไบงๅŠ›่‡ชๅŠจๅŒ–ใ€‚ - ่กฅๅ……่ฏฆๅฎž API ๅ‚ๆ•ฐ็”จๆณ•ใ€ๆจกๆฟไธŽๆœ€ไฝณๅฎž่ทตๆ–‡ๆกฃใ€‚
Metadata
Slug wong-super-lobster
Version 1.0.0
License MIT-0
All-time Installs 0
Active Installs 0
Total Versions 1
Frequently Asked Questions

What is Super Lobster?

๐Ÿฆž Super Lobster | ่ถ…็บง้พ™่™พ - ๆกฅๅ“ฅ็š„็งไบบ AI ๅŠฉ็† ๆ•ดๅˆไบ†้ฃžไนฆๆ–‡ๆกฃ็ฎก็†ใ€ไผš่ฎฎ็บช่ฆๆ•ด็†ใ€ๆฏๆ—ฅๅพ…ๅŠžๆŽจ้€ใ€ๅทฅไฝœๆจกๅ—ๅˆ†็ฑป็ญ‰ๆ ธๅฟƒๆŠ€่ƒฝใ€‚ ่ƒฝๅคŸ่‡ชๅŠจ่ฏปๅ–ไผš่ฎฎ็บช่ฆใ€ๆŒ‰ๅทฅไฝœๆจกๅ—ๅˆ†็ฑปๆ•ด็†ๅพ…ๅŠžไบ‹้กนใ€ๅˆ›ๅปบ้ฃžไนฆๆ–‡ๆกฃๅนถๆŽจ้€ใ€‚ ๆ ธๅฟƒ่ƒฝๅŠ›๏ผš - ๐Ÿ“„ ้ฃžไนฆๆ–‡ๆกฃๅˆ›ๅปบ๏ผˆๆ”ฏๆŒ 100+ blocks ๅคงๆ–‡ๆกฃ๏ผ‰ - ๐Ÿ“‹ ไผš่ฎฎ็บช... It is an AI Agent Skill for Claude Code / OpenClaw, with 84 downloads so far.

How do I install Super Lobster?

Run "/install wong-super-lobster" in the OpenClaw or Claude Code chat to install it in one step โ€” no extra setup required.

Is Super Lobster free?

Yes, Super Lobster is completely free, licensed under MIT-0. You can download, install and use it at no cost.

Which platforms does Super Lobster support?

Super Lobster is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).

Who created Super Lobster?

It is built and maintained by YBridge (@ybridge); the current version is v1.0.0.

๐Ÿ’ฌ Comments