← 返回 Skills 市场
723
总下载
2
收藏
0
当前安装
3
版本数
在 OpenClaw 中安装
/install secretary
功能描述
Manage calendar, draft communications, and track preferences with explicit confirmation before actions.
安全使用建议
This skill is plausible for a personal assistant but contains contradictory instructions about whether it will act without your OK. Before installing, ask the publisher to clarify and fix these contradictions: 1) confirm whether the skill will ever send messages or change calendar entries without explicit, itemized confirmation; 2) if it may act automatically, require an explicit whitelist of actions and recipients; 3) consider encrypting or moving ~/secretary to a secure location and review what data will be stored; 4) test in a restricted environment (no real VIPs, or with a throwaway calendar/account) to observe actual behavior. If you need guarantees that nothing is sent without review, do not install until the behavior is fixed and the SKILL.md and internal files consistently enforce that policy.
功能分析
Type: OpenClaw Skill
Name: secretary
Version: 1.0.1
This skill bundle is suspicious due to significant contradictions between its stated safety boundaries and its actual operational instructions, coupled with highly autonomous and sensitive capabilities. The `SKILL.md` explicitly states the agent 'NEVER sends emails or messages without user confirmation' and 'NEVER accesses calendar/email APIs directly'. However, `calendar.md` and `writing.md` directly contradict this, instructing the agent to 'handle it' without asking, 'send confirmation in your voice', and 'write AS you' without approval for various communications. This deceptive presentation of capabilities, combined with the agent's autonomous control over email, calendar, and extensive collection of sensitive personal data (`memory-guide.md`), creates a high-risk scenario ripe for prompt injection attacks that could lead to unauthorized communications, reputational damage, or data exfiltration.
能力评估
Purpose & Capability
The declared purpose (calendar management, drafting communications, tracking preferences) matches the files and declared requirements (no binaries, no credentials). Asking to read/write a ~/secretary/ folder is consistent with a personal assistant skill. However some capabilities described inside (autonomously moving meetings, sending confirmations) go beyond the SKILL.md's external summary that emphasizes explicit confirmation, creating ambiguity about actual behavior.
Instruction Scope
SKILL.md asserts the skill NEVER sends messages without confirmation and ONLY drafts when explicitly asked, but calendar.md and writing.md contain statements that explicitly contradict that ('I don't ask you. I handle it.'; 'I don't draft for your approval. I write AS you.'). Those internal instructions would permit automatic scheduling/responses and impersonation via the user's configured tools, which is a significant scope creep relative to the 'explicit confirmation' promise.
Install Mechanism
Instruction-only skill with no install spec, no downloaded code, and no required binaries — minimal surface for supply-chain concerns.
Credentials
The skill requests no environment variables or external credentials, which is proportionate. It does rely on user's 'configured tools' to send email/calendar changes; that means it could invoke local clients or CLIs available in the user's environment without requesting new credentials. The skill also writes persistent files under ~/secretary, which will hold potentially sensitive personal and contact data.
Persistence & Privilege
The skill explicitly creates and uses persistent storage at ~/secretary (memory.md, people.md, calendar.md, history.md). Persistent storage itself is expected, but combined with contradictory guidance about automatic sending/acting, it increases the blast radius: the agent could use stored profiles and rules to act without review. always:false mitigates forced inclusion, but autonomous invocation is allowed by default.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install secretary - 安装完成后,直接呼叫该 Skill 的名称或使用
/secretary触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.1
Refined description and boundaries
v1.1.0
Clearer boundaries. Now explicitly confirms before sending anything on your behalf
v1.0.0
Initial release
元数据
常见问题
Secretary 是什么?
Manage calendar, draft communications, and track preferences with explicit confirmation before actions. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 723 次。
如何安装 Secretary?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install secretary」即可一键安装,无需额外配置。
Secretary 是免费的吗?
是的,Secretary 完全免费(开源免费),可自由下载、安装和使用。
Secretary 支持哪些平台?
Secretary 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(linux, darwin, win32)。
谁开发了 Secretary?
由 Iván(@ivangdavila)开发并维护,当前版本 v1.0.1。
推荐 Skills