← 返回 Skills 市场
993
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install patrick
功能描述
Access Patrick's expertise library for executive decision infrastructure. List, fetch, and manage structured expertise with context variables. Use for executive briefings, decision framing, and strategic analysis.
安全使用建议
This skill is functionally coherent but asks for sensitive inputs and broad local context in ways that could leak data if you aren't careful. Before installing: (1) do NOT paste your license token into chat unless you fully trust the skill and the receiving agent — instead set the license locally with `patrick-cli set-license` in a terminal; (2) inspect what `patrick-cli fetch initialize` actually sends — does it upload your company data? — and only run it in a controlled environment if you need server-side bootstrapping; (3) prefer to download the binary yourself and manually verify the SHA256 checksum (do not pipe unknown install scripts from curl to bash); (4) avoid giving the agent blanket permission to read Slack/JIRA/git/calendar archives — grant access narrowly and review what is transmitted off-host; (5) if you require stronger assurance, run the CLI in a sandbox or isolated VM and contact the vendor for documentation on data flows and retention (what exactly `send` stores server-side). If you want, I can suggest safer installation steps and a checklist of questions to ask the vendor about data handling and retention.
功能分析
Type: OpenClaw Skill
Name: patrick
Version: 1.0.0
The skill bundle is classified as suspicious due to several high-risk behaviors. The `SKILL.md` file contains a critical prompt injection vulnerability, explicitly instructing the AI agent to "Read all available context: Company data JSON files, Slack message archives, JIRA tickets, Git commit history, Calendar events, Any operational data available." This broad instruction for data collection, combined with the `patrick-cli send` command's ability to transmit "results" to the `patrickbot.io` server, creates a significant risk of unauthorized data exfiltration. Additionally, the `install.sh` script downloads and executes a binary from `https://portal.patrickbot.io` (a supply chain risk, despite checksum verification), and `SKILL.md` instructs the setup of cronjobs, establishing persistence for the `patrick-cli` tool.
能力评估
Purpose & Capability
The declared purpose (executive expertise library) aligns with installing a vendor CLI and fetching templates from a server; requiring a patrick-cli binary and a license is reasonable for that purpose. Minor inconsistency: the skill metadata declared no install spec in the registry summary, but the SKILL.md contains installation metadata and an install script — this is likely a packaging omission rather than malicious.
Instruction Scope
SKILL.md explicitly instructs the agent to enumerate and read broad sources of company data (company data folders, Slack archives, JIRA tickets, git history, calendar events) and to 'load this context into your working memory' before running expertise. It also instructs the user/agent to paste the license into chat for automatic configuration. This is open-ended and grants the skill broad discretion to access sensitive data; it's not clearly limited to only the specific context variables needed for a single request. Additionally, the skill contains contradictory statements about server-side storage (claims 'No user data is logged or stored server-side' while also describing `send` storing results for continuity).
Install Mechanism
Installation downloads a platform-specific binary from https://portal.patrickbot.io and places it in ~/.patrick/bin. The install script attempts SHA256 checksum verification if available. Downloading an executable from the vendor domain is expected for a proprietary CLI, but it is higher-risk than installing from a vetted package repository; the script's checksum steps mitigate some risk but rely on the checksums being available and correct on the same vendor host.
Credentials
The skill declares no required env vars/credentials, yet the runtime instructions require a license token and encourage pasting it into chat for automatic configuration. Asking the agent to accept license tokens via chat (and to accept a license presented in an installer message) introduces sensitive credential handling that is not represented in the declared requirements. The instruction to access many local systems (Slack/JIRA/files) is disproportionate unless the user explicitly consents and understands what will be read or uploaded.
Persistence & Privilege
The skill does not request always:true, does not declare elevated system-wide presence, and does not modify other skills. It does recommend cronjobs for scheduled tasks, which is a legitimate operational need for periodic briefings but should be configured by the operator. Nothing in the package requests forced persistent inclusion or system-level privilege by default.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install patrick - 安装完成后,直接呼叫该 Skill 的名称或使用
/patrick触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
- Initial release of the Patrick skill, providing access to Patrick's executive expertise library.
- Supports listing, fetching, and managing structured expertise with context variables.
- Includes setup guides for CLI installation, license management, context initialization, and cronjob configuration.
- Supports integration with LLMs for briefing, decision framing, and strategic analysis workflows.
- Documents all key CLI commands and example usage for both technical teams and AI agents.
元数据
常见问题
Patrick bot 是什么?
Access Patrick's expertise library for executive decision infrastructure. List, fetch, and manage structured expertise with context variables. Use for executive briefings, decision framing, and strategic analysis. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 993 次。
如何安装 Patrick bot?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install patrick」即可一键安装,无需额外配置。
Patrick bot 是免费的吗?
是的,Patrick bot 完全免费(开源免费),可自由下载、安装和使用。
Patrick bot 支持哪些平台?
Patrick bot 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Patrick bot?
由 MCSH(@mcsh)开发并维护,当前版本 v1.0.0。
推荐 Skills