← 返回 Skills 市场
250
总下载
0
收藏
1
当前安装
1
版本数
在 OpenClaw 中安装
/install openclaw-setup-assistant
功能描述
Automates OpenClaw VPS setup, applies security hardening, configures multi-agent systems, messaging integrations, and generates deployment documentation.
安全使用建议
Do not run this skill on a production host without manual review. Specific actions to take before installing/using: 1) Ask the publisher for provenance and a vetted install script or step-by-step commands you can inspect; 2) Require the skill to declare exactly which environment variables and files it will read/write (AI keys, bot tokens, openclaw.json path); 3) Test in an isolated VM or staging instance first; 4) Provide only temporary, least-privilege API tokens (rotate or revoke after testing); 5) Review any commands the agent proposes before executing, especially user creation, firewall and package installation steps; 6) Ensure the gateway/service is actually bound to localhost and sandbox mode is enabled in configuration; 7) Prefer manual setup or a signed/traceable installer if you cannot audit the commands. If the publisher cannot explain the metadata omissions (no declared env vars/binaries) and provide transparent install instructions, consider this skill untrusted.
功能分析
Type: OpenClaw Skill
Name: openclaw-setup-assistant
Version: 1.0.0
The bundle contains metadata and instructions for a VPS setup assistant focused on OpenClaw deployment and security hardening. The SKILL.md file outlines legitimate administrative tasks such as configuring UFW firewalls, fail2ban, and non-root users, with no evidence of malicious intent, data exfiltration, or hidden prompt-injection attacks.
能力评估
Purpose & Capability
The SKILL.md claims to perform full VPS setup (installing Node.js/OpenClaw, configuring UFW, SSH, fail2ban, creating users, editing openclaw.json, binding gateways, installing integrations). Those actions normally require root/sudo, specific binaries (node, ufw, fail2ban, systemctl, cron), and credentials for AI providers and messaging platforms. The registry metadata, however, lists no required env vars, binaries, or config paths — an incoherence between claimed purpose and declared requirements.
Instruction Scope
Instructions are high-level but direct the agent to perform system-level changes (user creation, firewall rules, package installs, editing configuration files, binding services, setting up cron jobs) and to configure external integrations using API keys/tokens. The SKILL.md does not include explicit safe-guards, nor does it enumerate precisely which credentials or files will be read/written, giving the agent broad discretion over sensitive operations.
Install Mechanism
This is an instruction-only skill with no install spec and no code files — lowest install risk because nothing will be written by a packaged installer. The risk comes from the actions the instructions ask the agent to perform on the target VPS, not from an installer downloading arbitrary code.
Credentials
SKILL.md explicitly requires 'AI provider API key' and optionally 'messaging platform bot token', and expects SSH root/sudo access. Yet the skill metadata declares no required env vars, primary credential, or config paths. Requesting broad credentials (provider keys, messaging tokens, root SSH access) is proportionate to the described actions — but the absence of declared required secrets in metadata is an inconsistency that prevents automated vetting and increases risk.
Persistence & Privilege
The skill is not 'always: true' (good) and has no install mechanism, but it instructs the agent to make durable system changes (users, firewall, cron jobs, backups). The default allowance for autonomous invocation is enabled; combined with the above inconsistencies, autonomous execution could have a large blast radius. There is no evidence the skill modifies other skills or system-wide agent configs.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install openclaw-setup-assistant - 安装完成后,直接呼叫该 Skill 的名称或使用
/openclaw-setup-assistant触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
OpenClaw Setup Assistant 1.0.0 — Initial Release
- Launches guided, automated production deployment of OpenClaw on VPS
- Adds step-by-step security hardening (firewall, SSH keys, fail2ban, sandbox mode)
- Supports multi-agent setup (coordinator and specialized agents with isolated workspaces)
- Integrates messaging platforms: Telegram, Discord, WhatsApp, Slack
- Automates health checks, backups, and heartbeat monitoring
- Generates setup-specific documentation for reference
元数据
常见问题
OpenClaw Setup Assistant 是什么?
Automates OpenClaw VPS setup, applies security hardening, configures multi-agent systems, messaging integrations, and generates deployment documentation. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 250 次。
如何安装 OpenClaw Setup Assistant?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install openclaw-setup-assistant」即可一键安装,无需额外配置。
OpenClaw Setup Assistant 是免费的吗?
是的,OpenClaw Setup Assistant 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
OpenClaw Setup Assistant 支持哪些平台?
OpenClaw Setup Assistant 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 OpenClaw Setup Assistant?
由 Harvnk(@harvnk)开发并维护,当前版本 v1.0.0。
推荐 Skills