← 返回 Skills 市场
opencli
作者
chensu1234
· GitHub ↗
· v1.0.0
· MIT-0
156
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install opencli-hub
功能描述
Universal CLI for browser automation and website command-line access, supporting commands for Bilibili, Twitter, Reddit, GitHub, and more with automation fea...
安全使用建议
This skill behaves like a thin wrapper around a separate, preinstalled 'opencli' binary and expects access to your Chrome session and to install external CLIs on demand. Before installing or enabling it: (1) verify the provenance of the opencli binary (source URL, maintainers, and checksums); (2) avoid granting access to your browser profile/cookies unless you fully trust the binary—consider using an isolated browser profile or VM; (3) refuse or inspect any automatic installer runs (know what URLs/executables will be fetched); (4) demand explicit install instructions or source code/homepage from the publisher; and (5) if you need the functionality but want lower risk, run opencli inside a sandboxed container with no access to your main Chrome profile. Providing the skill's source, release URLs, and checksum would raise confidence; lacking that, treat it with caution.
功能分析
Type: OpenClaw Skill
Name: opencli-hub
Version: 1.0.0
The skill bundle provides a CLI interface ('opencli') for browser automation and interaction with authenticated web accounts (Twitter, Bilibili, Reddit), which inherently involves high-risk access to user session data. Significant red flags include a hardcoded local path ('/Users/c/.openclaw/opencli') in SKILL.md and the claim that the tool 'automatically' installs external CLI binaries (e.g., Docker, GitHub CLI), which presents a potential supply chain or remote code execution risk. While no explicit exfiltration logic is visible in the provided markdown, the combination of broad system access and automated binary installation is highly risky.
能力评估
Purpose & Capability
The stated purpose (CLI for browser automation and site-specific commands) aligns with the instructions, but the SKILL.md asserts an installed binary path (/Users/c/.openclaw/opencli) and a daemon without providing an install spec or any provenance. That is an inconsistency: an instruction-only skill claims an installed artifact it does not itself provide.
Instruction Scope
Runtime instructions refer to 'cookie/intercept mode' and require Chrome to be logged in to access user-specific pages. That implies the agent will need to read or connect to the user's browser session (cookies, profile, or debugging port). The doc also says opencli will 'automatically try to install' missing external CLIs — giving the agent permission to execute installers or download tools. Both raise data-exfiltration and arbitrary-execution risks not constrained by the SKILL.md.
Install Mechanism
There is no install spec in the skill (instruction-only), so the skill itself writes nothing. However, the instructions rely on a preinstalled binary and describe auto-install behavior for external CLIs; those runtime installs (performed by the opencli binary or by the agent invoking installers) are outside the skill package and could fetch arbitrary code. The skill provides no trusted URLs, checksums, or guidance on what gets installed.
Credentials
The skill declares no required env vars or creds, yet its functionality depends on access to logged-in browser state (cookies/session). Access to Chrome profile data or enabling a remote debugging port is sensitive and not declared. The automatic installation of other CLIs could also demand elevated privileges or network access that the skill does not enumerate.
Persistence & Privilege
always:false and model invocation are normal. The SKILL.md references a daemon and an installed path, implying a background component and persistent installation, but the skill package has no install or persistence declarations. This mismatch is suspicious but not proof of malicious intent.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install opencli-hub - 安装完成后,直接呼叫该 Skill 的名称或使用
/opencli-hub触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release: Universal CLI Hub for 70+ websites with browser automation support
元数据
常见问题
opencli 是什么?
Universal CLI for browser automation and website command-line access, supporting commands for Bilibili, Twitter, Reddit, GitHub, and more with automation fea... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 156 次。
如何安装 opencli?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install opencli-hub」即可一键安装,无需额外配置。
opencli 是免费的吗?
是的,opencli 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
opencli 支持哪些平台?
opencli 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 opencli?
由 chensu1234(@chensu1234)开发并维护,当前版本 v1.0.0。
推荐 Skills