← 返回 Skills 市场
xzxy1

泉水复活

作者 XzXy1 · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
95
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install spring-fountain-revival
功能描述
泉水复活 - 记忆生存系统。三重备份策略确保AI与用户的互动记忆永不丢失。 核心能力:一键备份、时间点快照、一键还原、云端同步、完整性校验。 桌面快捷方式:QClaw一键备份.bat / QClaw一键还原.bat 触发词:备份记忆、还原记忆、检查记忆、记忆备份、记忆恢复、泉水复活、记忆快照。 Keywords:...
安全使用建议
This skill appears to be what it says: a local backup/restore tool for AI memory files. Before installing, verify the following: 1) The configured CLOUD_SYNC_DIR (default is a Windows Administrator desktop path) — change it to your intended cloud-folder (OneDrive/百度网盘/other) to avoid accidentally syncing sensitive files to the wrong location. 2) Review which files will be backed up (MEMORY.md, USER.md, IDENTITY.md, diary/, etc.) because they may contain personal or identifying data. 3) If you are on non-Windows OS, edit paths in scripts (the defaults assume Windows for cloud path and Desktop .bat behavior). 4) Run the scripts in a safe environment first (inspect generated snapshots in ~/.qclaw/.memory_backup/snapshots) and confirm that the restore process behaves as expected. If you need higher assurance, open the scripts and confirm there are no unexpected external network calls or uploads beyond copying into your configured cloud-sync folder.
功能分析
Type: OpenClaw Skill Name: spring-fountain-revival Version: 1.0.0 The skill provides a memory backup and restoration system but contains several high-risk vulnerabilities that could be exploited via prompt injection. Specifically, 'scripts/memory_backup.py' is vulnerable to path traversal in the 'create_snapshot' and 'restore' functions because it does not sanitize the 'label' or path arguments, and it is susceptible to a 'Zip Slip' attack during restoration. While the behavior aligns with the stated purpose of backing up memory files to a local and cloud-synced directory (defaulting to a Baidu Netdisk path on Windows), the lack of input validation in scripts intended to be executed by an AI agent (as instructed in 'SKILL.md') poses a significant security risk.
能力评估
Purpose & Capability
Name/description (memory backup, snapshot, restore, cloud sync) aligns with the included scripts and README. The scripts operate on the declared workspace (~/.qclaw/workspace) and implement latest/snapshot/cloud-sync/restore features described in SKILL.md. One minor note: the default CLOUD_SYNC_DIR is a hard-coded Windows Desktop path (C:\Users\Administrator\Desktop\QC百度同步\...), which is fine on Windows but surprising on non-Windows systems and should be edited to a user-controlled cloud folder.
Instruction Scope
SKILL.md instructs running the included Python scripts and creating desktop .bat shortcuts. The runtime instructions and the scripts operate on files under the skill/workspace (MEMORY.md, USER.md, IDENTITY.md, diary/, memory/). They do not instruct reading unrelated system paths, environment secrets, or contacting remote endpoints. The scripts do copy the restore .bat to the cloud sync folder if present (so check that target).
Install Mechanism
No install spec is present (instruction-only), which is low-risk. The package includes two Python scripts and docs; these will be stored in the skill directory by OpenClaw but there is no third-party download or archive extraction. No external executables or package installs are performed by the skill itself.
Credentials
The skill declares no required environment variables or credentials and the scripts do not attempt to access secrets. The main sensitive action is writing backups (which include USER.md and IDENTITY.md) into a cloud-synced folder if configured — this is expected for a backup tool but the user should confirm the cloud target to avoid accidental exposure.
Persistence & Privilege
The skill does not request always:true and does not modify other skills or system-wide settings. It is user-invocable and can be invoked autonomously by the agent (default behavior), which is typical for skills of this type.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install spring-fountain-revival
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /spring-fountain-revival 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
spring-fountain-revival 1.0.0 — 初始发布 - 发布「泉水复活」记忆生存系统,具备三重备份保障 AI 与用户的互动记忆安全。 - 支持一键备份、快照、还原、云端同步及完整性校验等核心功能。 - 提供桌面快捷方式(备份/还原)及多类触发词,实现便捷操作。 - 明确列出关键记忆文件及操作流程,支持新设备恢复。
元数据
Slug spring-fountain-revival
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

泉水复活 是什么?

泉水复活 - 记忆生存系统。三重备份策略确保AI与用户的互动记忆永不丢失。 核心能力:一键备份、时间点快照、一键还原、云端同步、完整性校验。 桌面快捷方式:QClaw一键备份.bat / QClaw一键还原.bat 触发词:备份记忆、还原记忆、检查记忆、记忆备份、记忆恢复、泉水复活、记忆快照。 Keywords:... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 95 次。

如何安装 泉水复活?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install spring-fountain-revival」即可一键安装,无需额外配置。

泉水复活 是免费的吗?

是的,泉水复活 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

泉水复活 支持哪些平台?

泉水复活 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 泉水复活?

由 XzXy1(@xzxy1)开发并维护,当前版本 v1.0.0。

💬 留言讨论