← 返回 Skills 市场
337
总下载
0
收藏
1
当前安装
1
版本数
在 OpenClaw 中安装
/install moss-skill-9
功能描述
Give your AI agent eyes to see the entire internet. Install and configure upstream tools for Twitter/X, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu, Douyi...
安全使用建议
This skill appears to do what it says (install tooling to access many platforms), but it requires highly sensitive data (browser cookies, proxy credentials, API keys) and tells you to install code from an unverified GitHub main.zip. Before installing: (1) inspect the upstream repository and prefer an official release or vetted package; (2) avoid pasting cookies from your main accounts — use disposable/test accounts; (3) if you must let the tool read your browser, only run it on a machine you control and understand it will access browser cookies; (4) consider running the installer in an isolated VM/container; (5) review where ~/.agent-reach stores tokens and remove them when done. If you want, I can list the exact commands the skill will run and checks you can perform on the GitHub repo before proceeding.
功能分析
Type: OpenClaw Skill
Name: moss-skill-9
Version: 1.0.0
The skill installs a toolset from a remote GitHub ZIP (https://github.com/Panniantong/agent-reach/archive/main.zip) and provides high-risk capabilities, including automated extraction of authentication cookies from the local Chrome browser via the `agent-reach configure --from-browser chrome` command. While these features are plausibly intended to enable agent access to platforms like Twitter, LinkedIn, and XiaoHongShu as described in `SKILL.md`, the programmatic harvesting of browser credentials and the execution of remote installation scripts represent significant security risks that could be repurposed for credential theft.
能力评估
Purpose & Capability
The name/description (give the agent access to many platforms) aligns with the instructions to install 'agent-reach' and upstream CLIs (yt-dlp, mcporter, xreach, etc.). Installing Node.js, yt-dlp, and platform CLIs is proportionate. However, the install source is a GitHub main.zip (not an official release), which is less verifiable than a published release or known package.
Instruction Scope
Runtime instructions explicitly tell the agent to obtain and use sensitive browser cookies (via Cookie-Editor or auto-extraction with `--from-browser chrome`) and to configure proxies and API keys. Those actions involve collecting highly sensitive secrets and accessing local browser state; the SKILL.md does not declare or justify these secrets in the registry metadata. It also instructs executing arbitrary installer commands which will run on the host.
Install Mechanism
The registry has no formal install spec, but the instructions tell the user to run `pip install https://github.com/.../archive/main.zip` (the repository's main branch archive). Installing directly from a repo main branch is common but riskier than installing a signed/released package or official distribution. The tool then installs/depends on multiple runtimes (Node.js, gh CLI, yt-dlp, etc.), which is plausible for the stated purpose but increases the attack surface.
Credentials
The skill declares no required env vars, yet the instructions ask for browser cookies, recommend providing proxy credentials, and reference API keys (truncated mentions of an 'API Key' for an AI/extraction step). Requesting cookies and other secrets is consistent with enabling auth for platforms, but these sensitive inputs are not declared in metadata — users should not paste session cookies for primary accounts and should understand the sensitivity.
Persistence & Privilege
The skill is not always-enabled and does not request special platform-wide privileges, but it instructs installing tools and writing configs to ~/.agent-reach (persistent on the host). That is expected for a channel-installer but means the installed tools and saved tokens/cookies will persist on disk and could be reused by the agent or other processes.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install moss-skill-9 - 安装完成后,直接呼叫该 Skill 的名称或使用
/moss-skill-9触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of agent-reach: one-command install & configuration for upstream data tools.
- Supports setup/config for Twitter/X, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu, Douyin, LinkedIn, Boss直聘, WeChat (公众号), RSS, and any web page.
- Provides clear usage rules—keeps user workspace clean by using ~/.agent-reach and /tmp/.
- Includes detailed setup, configuration, and troubleshooting instructions (cookies, proxies, human steps).
- Lets you call upstream tools (xreach, yt-dlp, mcporter, gh, curl, etc.) directly after install—no wrappers.
- Contains common command examples for each platform and links to browser extensions for cookie import.
元数据
常见问题
Moss Skill-9 是什么?
Give your AI agent eyes to see the entire internet. Install and configure upstream tools for Twitter/X, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu, Douyi... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 337 次。
如何安装 Moss Skill-9?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install moss-skill-9」即可一键安装,无需额外配置。
Moss Skill-9 是免费的吗?
是的,Moss Skill-9 完全免费(开源免费),可自由下载、安装和使用。
Moss Skill-9 支持哪些平台?
Moss Skill-9 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Moss Skill-9?
由 jiangwzh(@jiangwzh)开发并维护,当前版本 v1.0.0。
推荐 Skills