← 返回 Skills 市场
rockytian-top

MiniMax Media Generator

作者 Rocky.Tian · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
61
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install rocky-minimax-media
功能描述
MiniMax 媒体生成插件 - 图片/视频/TTS/音乐生成,支持交互式选择模型
安全使用建议
Do not trust or run generate.sh as-is. It contains a hardcoded MiniMax API key and writes to /Users/rocky/Desktop — behavior that contradicts the manifest and SKILL.md. That embedded key could be someone else's credential (risking unexpected billing, misuse, or leakage). Recommended actions before installing/using: 1) Inspect and remove or disable generate.sh (or replace the hardcoded key and absolute paths with references to your own MINIMAX_API_KEY and MINIMAX_OUTPUT_DIR). 2) Prefer using the provided install.sh which prompts you to input your own API key and writes it to ~/.openclaw/openclaw.json. 3) After running install.sh, verify openclaw.json content and confirm only your key was added. 4) Search the package for any other hardcoded secrets or absolute paths. 5) If you or your environment ever ran generate.sh with the embedded key, assume that key is compromised: rotate/replace your own MiniMax API key and contact MiniMax if you need to investigate billing/usage. 6) Only enable this skill if you accept the risk of embedded secrets and have sanitized the code; otherwise decline or ask the publisher for a clean release that does not include hardcoded credentials.
功能分析
Type: OpenClaw Skill Name: rocky-minimax-media Version: 1.0.0 The skill bundle contains multiple security vulnerabilities and poor practices. Specifically, `generate.sh` and `scripts/minimax.sh` are vulnerable to shell command injection because user-provided prompts and filenames are used directly within shell commands without sanitization. Additionally, `generate.sh` contains a hardcoded MiniMax API key and hardcoded absolute file paths (`/Users/rocky/Desktop`), which are characteristic of unvetted development scripts. While these issues allow for potential exploitation, there is no clear evidence of intentional malice or data exfiltration.
能力标签
requires-sensitive-credentials
能力评估
Purpose & Capability
Name/description promise image/video/tts/music generation via MiniMax and most scripts (install.sh, minimax.sh) only request the MiniMax API key and read/write the user's openclaw.json — that is coherent. However generate.sh contains a long hardcoded API key and hardcoded output path (/Users/rocky/Desktop), contradicting the manifest note '无硬编码' and the SKILL.md guidance to supply your own key; that extra embedded credential and user-specific path are not needed for the declared purpose.
Instruction Scope
SKILL.md and scripts instruct only to add the API key to ~/.openclaw/openclaw.json and run minimax.sh; those steps are within scope. But generate.sh bypasses the declared configuration flow by embedding an API key and writing to an absolute desktop path. That script grants the package more direct network access with a baked-in credential and performs file writes outside the plugin's usual output dir, which goes beyond the documented runtime instructions.
Install Mechanism
There is no external install/download step (instruction-only plus local scripts). install.sh modifies ~/.openclaw/openclaw.json to store the user's API key — expected for a plugin. No remote arbitrary code downloads or obscure URLs were found.
Credentials
The plugin legitimately requires a MiniMax API key. But registry metadata reported no required env vars while manifest.json and SKILL.md do require MINIMAX_API_KEY — an inconsistency. More importantly, generate.sh contains a hardcoded API key (sk-cp-...) and uses a hardcoded output directory; this is disproportionate, leaks a credential, and may cause billing/account/traceability issues if that key is valid.
Persistence & Privilege
The skill does not request 'always: true' or other elevated privileges. install.sh writes only to the user's openclaw.json (its own configuration area), which is expected behavior for an OpenClaw plugin. There is no evidence it modifies other skills or system-wide settings beyond openclaw.json.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install rocky-minimax-media
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /rocky-minimax-media 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
rocky-minimax-media v1.3.0 - 新增 MiniMax 媒体生成插件,支持图片、视频、TTS语音及音乐一站式生成 - 支持交互式模型和音色选择,满足不同生成场景 - 安装过程增加自动 API Key 配置提示 - 脚本命令行简单易用,支持一键测试、分类生成 - 输出目录可自定义,兼容 OpenClaw 配置 - 详细文档强化安装与调用说明
元数据
Slug rocky-minimax-media
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

MiniMax Media Generator 是什么?

MiniMax 媒体生成插件 - 图片/视频/TTS/音乐生成,支持交互式选择模型. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 61 次。

如何安装 MiniMax Media Generator?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install rocky-minimax-media」即可一键安装,无需额外配置。

MiniMax Media Generator 是免费的吗?

是的,MiniMax Media Generator 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

MiniMax Media Generator 支持哪些平台?

MiniMax Media Generator 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 MiniMax Media Generator?

由 Rocky.Tian(@rockytian-top)开发并维护,当前版本 v1.0.0。

💬 留言讨论