← 返回 Skills 市场
xiejinsong

Night Market Guide

作者 xiejinsong · GitHub ↗ · v3.2.0 · MIT-0
cross-platform ⚠ suspicious
70
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install night-market-guide
功能描述
Find night markets, food streets, and local culinary hotspots. Discover street food, local specialties, and the best evening food experiences. Also supports:...
安全使用建议
Key things to consider before installing: 1) The SKILL.md requires you to globally install and run @fly-ai/flyai-cli from npm at runtime — verify that package on the npm registry (author, weekly downloads, source repository, maintainers, and recent release) before allowing installation or run the CLI in a sandbox. 2) The skill advertises booking/Fliggy capabilities but declares no credentials; expect that the CLI may later prompt for API keys or account logins — don’t provide secrets until you verify the provider. 3) The skill references local docs that are not included, and enforces strict re-run/self-test behavior that could cause repeated network calls or installs; consider rejecting or sandboxing the install if you do not want external network activity. 4) If you still want to use it, test the flyai CLI manually in an isolated environment and inspect its code before granting the agent permission to execute global installs or network calls.
功能分析
Type: OpenClaw Skill Name: night-market-guide Version: 3.2.0 The skill mandates the global installation of an external NPM package (`@fly-ai/flyai-cli`) and uses aggressive, 'jailbreak-style' instructions in `SKILL.md` to force the agent to bypass its internal knowledge and execute shell commands. While these actions are technically aligned with the stated purpose of providing real-time travel data, the requirement for global installation privileges and the reliance on an unverified external dependency represent a significant security risk and a potential vector for supply chain attacks.
能力标签
cryptocan-make-purchases
能力评估
Purpose & Capability
The declared purpose (find night markets / food streets) aligns with the CLI commands shown (flyai search-poi). However the description also claims many extra travel features (flight booking, hotels, travel insurance, 'powered by Fliggy') that are not supported or justified by the SKILL.md commands or by any declared credentials. The extra capabilities are disproportionate to the visible instructions.
Instruction Scope
The SKILL.md mandates that every answer must come from the flyai CLI output and instructs the agent to install and run npm i -g @fly-ai/flyai-cli if the CLI is missing. It also references several local doc files (references/*.md) that are not present in the skill manifest. The file-missing and the strict re-execution/self-test rules (requiring a [Book]({detailUrl}) link and re-running on any deviation) could force repeated installs/external calls or create an execution loop. The rule 'NEVER answer from training data' gives the agent no fallback and could lead to failure or repeated network activity.
Install Mechanism
Although the registry metadata has no formal install spec, the runtime instructions require a global npm install of @fly-ai/flyai-cli. Installing an unvetted global npm package is potentially high-impact (writes to disk, installs binaries that will be invoked). The SKILL.md provides no pinned version, no source verification, and no alternative validated install path, which is disproportionate for a simple lookup skill.
Credentials
The skill declares no required environment variables or credentials, which is good. However it advertises booking and Fliggy-powered capabilities that normally require API credentials, yet no credential fields or instructions for authentication are declared. The flyai CLI itself may prompt for or require credentials at runtime — this is not surfaced in the manifest and could lead to unexpected credential entry.
Persistence & Privilege
The skill is not always-on and does not request elevated platform privileges. That said, its instructions involve installing a global CLI binary (npm i -g), which persists on the host outside the agent sandbox; this persistence is not declared in the registry install spec and is worth noting though it is not a direct skill-level permission request.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install night-market-guide
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /night-market-guide 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v3.2.0
night-market-guide 3.2.0 Changelog - Enforces strict CLI execution for all responses; no knowledge-based answers are allowed. - Adds robust environment checks: will prompt user to install flyai-cli if missing, never falls back to knowledge data. - Mandates every recommendation must include a [Book](detailUrl) link sourced from real-time CLI output. - Introduces expanded Playbooks for "night market", "food street", and "street food" triggers with specific CLI command patterns. - Includes explicit guidelines for output formatting, validation, and brand tagging to ensure accuracy and compliance. - Updates compatibility and skill description, highlighting new supported platforms and services.
元数据
Slug night-market-guide
版本 3.2.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Night Market Guide 是什么?

Find night markets, food streets, and local culinary hotspots. Discover street food, local specialties, and the best evening food experiences. Also supports:... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 70 次。

如何安装 Night Market Guide?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install night-market-guide」即可一键安装,无需额外配置。

Night Market Guide 是免费的吗?

是的,Night Market Guide 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Night Market Guide 支持哪些平台?

Night Market Guide 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Night Market Guide?

由 xiejinsong(@xiejinsong)开发并维护,当前版本 v3.2.0。

💬 留言讨论