← 返回 Skills 市场
bushushu2333

三体:文明的抉择

作者 bushushu2333 · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
120
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install santi-text-game
功能描述
恐怖惊魂夜 - 互动式恐怖悬疑剧本杀游戏。玩家将在雪山旅馆中经历一场惊心动魄的生存冒险,通过调查线索、做出选择来推动剧情发展。支持多结局、角色扮演、线索系统。适用于互动小说、剧本杀、文字冒险游戏等场景。
安全使用建议
Do not install this skill on a machine with sensitive data or live credentials yet. Specific concerns: (1) The package includes many unrelated scripts and integration code (Feishu, Gmail, publishing) and files containing API keys/credentials (gmail-credentials.json, service-account.json, cookies.json, API keys pasted in MEMORY.md). (2) AGENTS.md and other workspace docs direct the assistant to read long-term memory and user files without asking — this is scope creep from a simple game. (3) The SKILL.md/references include prompt-injection-like system instructions and potential obfuscation. Actions to take before proceeding: - Ask the publisher for provenance (source/homepage/owner) and why so many unrelated files are bundled. Do not proceed if owner is unknown/untrusted. - Inspect the repository for secrets: search for 'API_KEY', 'SECRET', 'password', '.env', 'service-account.json', 'gmail-credentials.json', 'cookies.json' and remove or rotate any exposed credentials. - Run the skill in an isolated sandbox/VM with no access to your real workspace, network-restricted if possible. - If you only want the game, extract SKILL.md and the references/ game files into a clean directory and remove unrelated files; verify no scripts will be executed. - If you plan to allow autonomous actions, require explicit, minimal env vars and a clear install script from a trusted source; never grant broad file-system access. If you want, I can list the exact files that contain apparent credentials and the lines to inspect/rotate.
功能分析
Type: OpenClaw Skill Name: santi-text-game Version: 1.0.0 The skill bundle is classified as suspicious due to the extensive presence of hardcoded sensitive credentials, including API keys and secrets for Feishu, Volcengine, Maton, Perplexity, and WeChat, found in files such as `doubao_seed2pro_service.py`, `MEMORY.md`, `TOOLS.md`, and `tools/feishu_send.py`. The bundle also includes high-privilege capabilities such as full desktop automation via pyautogui (`skills/desktop-control/__init__.py`) and the creation of persistent system services on macOS via launchd (`feishu-openclaw/setup-service.mjs`). While these features appear to be part of a legitimate personal automation environment for a specific user, the lack of credential sanitization and the inclusion of persistence mechanisms represent significant security vulnerabilities.
能力评估
Purpose & Capability
The skill's name/description are for a text-adventure game, yet the package includes hundreds of unrelated files (Feishu connectors, Gmail creds, service account JSON, publishing scripts, many other skills). Declaring 'instruction-only' with no required env vars is inconsistent with the repository contents. The presence of social/publishing integrations and stored credentials does not belong to a simple single-game skill.
Instruction Scope
The SKILL.md itself limits runtime actions to reading game reference files, but other workspace docs (AGENTS.md, SOUL.md, MEMORY.md, TOOLS.md, HEARTBEAT.md) instruct the agent to read long-term memory, user files, and to perform external actions without asking. Those instructions expand scope far beyond a standalone game and enable access to sensitive workspace data.
Install Mechanism
No install spec is declared (instruction-only), which usually lowers risk. However, this repository nonetheless contains many executable scripts and service files; absence of an install spec combined with many code files is inconsistent but does not itself execute code on install.
Credentials
The skill declares no required env vars, but multiple files contain credentials or references to secrets (gmail-credentials.json, service-account.json, FEISHU app id/secret, pasted API keys in MEMORY.md and TOOLS.md, cookies.json). A text-adventure game does not need these — their presence is disproportionate and suggests potential for credential exposure or misuse.
Persistence & Privilege
always:false (normal). However, AGENTS.md and other docs instruct the agent to autonomously read and update workspace memory files and to perform heartbeats and external actions. While autonomous invocation is the platform default, these embedded agent behaviors increase blast radius if the skill is enabled — combine with other red flags.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install santi-text-game
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /santi-text-game 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
三体互动文字冒险游戏 v1.0
元数据
Slug santi-text-game
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

三体:文明的抉择 是什么?

恐怖惊魂夜 - 互动式恐怖悬疑剧本杀游戏。玩家将在雪山旅馆中经历一场惊心动魄的生存冒险,通过调查线索、做出选择来推动剧情发展。支持多结局、角色扮演、线索系统。适用于互动小说、剧本杀、文字冒险游戏等场景。 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 120 次。

如何安装 三体:文明的抉择?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install santi-text-game」即可一键安装,无需额外配置。

三体:文明的抉择 是免费的吗?

是的,三体:文明的抉择 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

三体:文明的抉择 支持哪些平台?

三体:文明的抉择 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 三体:文明的抉择?

由 bushushu2333(@bushushu2333)开发并维护,当前版本 v1.0.0。

💬 留言讨论