← 返回 Skills 市场
msruruguay

MidOS MCP — Knowledge OS for AI Agents

作者 msruruguay · GitHub ↗ · v1.0.0
cross-platform ⚠ suspicious
404
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install midos-mcp
功能描述
MidOS — The MCP Knowledge OS. 134 tools for knowledge management, multi-agent orchestration, search, planning, and memory. 670K+ vectors, 46K+ chunks, EUREKA...
安全使用建议
This skill appears to be a remote Knowledge OS and many usages are reasonable (search, memory, planning). But before installing: 1) Ask the publisher how authentication works — why are no API keys or tokens declared? Confirm whether midos.dev requires an API key, and how credentials are transmitted and stored. 2) Clarify what maker_run_bash / maker_read_file / maker_write_file actually do and where they execute (on your machine, on MidOS servers, or on third-party workers). If they can run local shell or read local files, do not enable autonomous invocation and restrict the skill to manual use only. 3) Prefer self-hosting (they provide a repo) if you will send sensitive data. 4) Avoid providing webhook/Discord tokens to the skill until you understand where notifications originate. 5) If you must use the hosted service, limit the agent’s permissions, monitor network calls, and review privacy/terms for data retention and sharing.
功能分析
Type: OpenClaw Skill Name: midos-mcp Version: 1.0.0 The skill bundle is suspicious due to the inclusion of highly privileged execution tools: `maker_run_bash`, `maker_read_file`, and `maker_write_file` as described in `SKILL.md`. These tools grant the AI agent the ability to execute arbitrary shell commands, read any file, and write any file on the host system. While there is no explicit malicious instruction or prompt injection attempt within the provided `SKILL.md` itself, these capabilities represent a critical vulnerability, enabling potential remote code execution and data exfiltration if the agent is compromised (e.g., via a malicious user prompt).
能力评估
Purpose & Capability
The skill describes a Knowledge OS and search/memory/plan tools which fit its name, but it also advertises 'Execution' tools (maker_run_bash, maker_read_file, maker_write_file, git, HTTP fetch). Those capabilities are powerful and potentially outside a pure "knowledge search" role; the SKILL.md does not explain where those executions run (remote service vs local agent) nor why no credentials are required to access them. Requiring remote execution/file-op capabilities without clarifying scope or auth is disproportionate to the plain knowledge-search description.
Instruction Scope
The instructions focus on JSON-RPC calls to https://midos.dev/mcp and provide examples for search, memory, and plan operations which are in-scope. However the doc also includes heartbeat guidance and references execution and notifier tools; the instructions do not show any authentication, nor do they limit or clarify usage of file/shell execution tools. That ambiguity could allow broad actions if the agent or service interprets tool names as able to run arbitrary commands or access files.
Install Mechanism
Instruction-only skill with no install spec and no code files — lowest install risk. No downloads or packages are pulled by the skill itself.
Credentials
The skill declares no required environment variables or primary credential even though it points at a remote API (midos.dev) and lists webhook/Discord notifiers and execution tools that normally need authentication or tokens. The absence of declared credentials is inconsistent with expected needs for a remote platform that can perform actions or notify external services.
Persistence & Privilege
always is false and the skill is user-invocable; it does not request persistent platform privileges. Note: autonomous invocation (model-invocation enabled by default) is allowed — combined with the execution toolset this raises the blast radius if you enable the skill to act autonomously, but autonomous invocation itself is the platform default.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install midos-mcp
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /midos-mcp 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release: 134 tools, 670K+ vectors, hybrid search, persistent memory, multi-agent planning
元数据
Slug midos-mcp
版本 1.0.0
许可证
累计安装 0
当前安装数 0
历史版本数 1
常见问题

MidOS MCP — Knowledge OS for AI Agents 是什么?

MidOS — The MCP Knowledge OS. 134 tools for knowledge management, multi-agent orchestration, search, planning, and memory. 670K+ vectors, 46K+ chunks, EUREKA... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 404 次。

如何安装 MidOS MCP — Knowledge OS for AI Agents?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install midos-mcp」即可一键安装,无需额外配置。

MidOS MCP — Knowledge OS for AI Agents 是免费的吗?

是的,MidOS MCP — Knowledge OS for AI Agents 完全免费(开源免费),可自由下载、安装和使用。

MidOS MCP — Knowledge OS for AI Agents 支持哪些平台?

MidOS MCP — Knowledge OS for AI Agents 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 MidOS MCP — Knowledge OS for AI Agents?

由 msruruguay(@msruruguay)开发并维护,当前版本 v1.0.0。

💬 留言讨论