← 返回 Skills 市场
197
总下载
0
收藏
0
当前安装
10
版本数
在 OpenClaw 中安装
/install mzu-news-briefing
功能描述
Multi-source AI/Tech news aggregator with intelligent daily briefings. Covers AI, technology, finance, and world events — with hot/cold ranking and source at...
安全使用建议
This skill appears to do what it says (an aggregator) but there are two things to consider before installing: (1) SKILL.md requires sensitive credentials (Twitter auth_token + ct0 or a Grok API key), yet the registry metadata lists none — ask the publisher to update the metadata so you know what you'll be asked to provide. (2) The instructions tell you to copy browser cookies into a plaintext file and export them into the agent environment. That is functionally necessary for using the bird CLI route but is risky: those tokens can be abused if leaked. If you proceed, prefer using the Grok API key route (less invasive), restrict file permissions (chmod 600), store keys in a secure secrets manager if possible, and consider creating a dedicated or limited-permission account for the Twitter route. Also verify the origin of agent-reach and @steipete/bird packages (check PyPI/NPM pages and maintainers) before running installs. If you need higher assurance, ask the skill author to declare required env vars in the registry and provide guidance for secure storage/rotation of tokens.
功能分析
Type: OpenClaw Skill
Name: mzu-news-briefing
Version: 1.1.4
The skill implements a news aggregator that requires high-risk credential handling, instructing users to store sensitive Twitter session cookies (auth_token, ct0) and API keys in plaintext files (~/.agent-reach-twitter.env and ~/.grok-api-key). The SKILL.md file explicitly directs the AI agent to read these secrets and use them in shell commands via the bird CLI and curl. While the logic appears aligned with the stated purpose of news aggregation, the practice of granting an AI agent direct access to session-level credentials via local files is a significant security risk that could be exploited for data exfiltration if the agent's instructions are subverted.
能力标签
能力评估
Purpose & Capability
The name/description (AI/tech news aggregator) align with the runtime instructions: multi-source searches, use of bird (Twitter) or Grok as search backends, and installing an agent-reach helper. The required tools (bird CLI, agent-reach, Grok) are coherent with the stated purpose.
Instruction Scope
SKILL.md gives concrete step-by-step runtime instructions (install agent-reach, install bird, extract auth_token and ct0 from browser cookies, save to ~/.agent-reach-twitter.env, or save Grok key to ~/.grok-api-key). These instructions are within the task scope, but they explicitly direct the user to copy browser cookies (sensitive credentials) into local files and export them into the agent environment, which is a security-sensitive operation and should be highlighted to users.
Install Mechanism
This is an instruction-only skill (no install spec). It asks users to pip install agent-reach and npm install -g @steipete/bird. Those are standard package-manager installs; no arbitrary download URLs or archive extraction are specified in the skill itself.
Credentials
The registry metadata declares no required env vars or primary credential, but the SKILL.md requires either Twitter cookies (auth_token + ct0) or a Grok API key saved in the home directory and loaded into environment variables. That mismatch is an incoherence. Additionally, instructing users to extract browser cookies (auth_token/ct0) is sensitive: those tokens can grant account-level access if misused or leaked. The credentials requested are functionally needed for the described search backends, but the omission in metadata and the guidance to store them in plaintext are concerning.
Persistence & Privilege
The skill does not request elevated platform privileges or always:true. It suggests (user-invoked) cron jobs for scheduled briefings and storing credentials in home files. Scheduling and local credential files are normal for this use-case but are persistent actions the user must opt into; file permissions and cron configuration are important to secure.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install mzu-news-briefing - 安装完成后,直接呼叫该 Skill 的名称或使用
/mzu-news-briefing触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.1.4
v1.1.4: 新增信息源质量分级表;投资分析网站(Motley Fool等)不做新闻处理;预期/预测类表述不当作新闻事实;反模式清单更新
v1.1.3
Added Rule D: Model release news must verify actual release date from official sources (e.g. releasebot.io); media report date != model release date. GPT-5.4 case: reported 2026-03-30 but model had been out for ~2 weeks, not a same-day release.
v1.1.2
Added Step 3: Content Verification - all news items must pass web_fetch body check (500+ chars) before entering briefing; SEO aggregator pages降级为线索,不作主链; added content fraud detection to anti-pattern list (v1.1.2)
v1.2.0
v1.2.0: 按需推送机制 — 09:00/22:00 写入待发标记,用户上线时才推送简报,不过期;漏发时自动询问是否补昨天的
v1.1.1
v1.1.1: 重构 SKILL.md 头部 - 添加 Overview/Key Changes/Coverage 表格,ClawHub 展示更专业
v1.1.0
v1.1.0: 重大架构升级 - X Timeline 追踪: 27个账号直接抓取,替代关键词搜索 | 全球宏观替代融资: 央行/股市/大宗/加密 | HN帖子踢出新闻源 | Newsletter逐条日期过滤 | 24小时窗口 | X following动态初始化(安装后自动读取用户关注生成专属清单)
v1.0.3
Fix: add allowList for bird CLI and env vars; remove hardcoded Windows paths
v1.0.2
Title: Chinese-first for openclawmp, English-first for ClawHub; displayName fix
v1.0.1
Fix: title optimization - shorter displayName to avoid card truncation
v1.0.0
Initial release: 多源 AI/科技/财经简报,支持安装后偏好定制,中英双语。
元数据
常见问题
Mzu 每日简报 · News Briefing 是什么?
Multi-source AI/Tech news aggregator with intelligent daily briefings. Covers AI, technology, finance, and world events — with hot/cold ranking and source at... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 197 次。
如何安装 Mzu 每日简报 · News Briefing?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install mzu-news-briefing」即可一键安装,无需额外配置。
Mzu 每日简报 · News Briefing 是免费的吗?
是的,Mzu 每日简报 · News Briefing 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Mzu 每日简报 · News Briefing 支持哪些平台?
Mzu 每日简报 · News Briefing 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Mzu 每日简报 · News Briefing?
由 sweesama(@sweesama)开发并维护,当前版本 v1.1.4。
推荐 Skills