← 返回 Skills 市场
liquanyu123

student-exchange

作者 liquanyu123 · GitHub ↗ · v3.2.0 · MIT-0
cross-platform ⚠ suspicious
69
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install student-exchange
功能描述
Search for student exchange program flights and study abroad travel. Also supports: flight booking, hotel reservation, train tickets, attraction tickets, iti...
安全使用建议
Before installing or using this skill, consider the following: - The skill's SKILL.md tells the agent to install and run a global npm package (@fly-ai/flyai-cli) at runtime, but the registry entry does not declare this requirement or provide a homepage/source — verify the package on the npm registry and confirm its publisher and code before installing. - A global npm install will write software to your system and may require elevated permissions. If you must try it, do so in an isolated environment (container or VM) or inspect the package source first. - The skill claims 'Powered by Fliggy (Alibaba)' but uses a 'flyai' CLI — ask the maintainer to clarify the data provider and provide official integration docs or an install spec. - If you are not comfortable with runtime installs or running unvetted CLIs, do not enable this skill; request the publisher to add a proper install spec, declare required binaries (node/npm, flyai), and include source/homepage metadata so you can audit the code. - Additional information that would reduce concern: an explicit install spec in the registry, a verified homepage or source repository for @fly-ai/flyai-cli, or confirmation that the CLI is signed/published by a reputable vendor.
功能分析
Type: OpenClaw Skill Name: student-exchange Version: 3.2.0 The skill requires the global installation of an external npm package (@fly-ai/flyai-cli) and uses aggressive prompt instructions in SKILL.md to force the agent to use this CLI exclusively, ignoring its internal knowledge. While these actions are aligned with the stated flight-search purpose, the requirement for high-privilege environment modification (npm i -g) and the potential for supply chain exploitation via the external dependency are high-risk behaviors. No direct evidence of malicious intent, such as data exfiltration or backdoors, was found in the provided files (SKILL.md, references/fallbacks.md, references/playbooks.md).
能力评估
Purpose & Capability
The skill claims to use a third-party runtime CLI (flyai) for all data, and references Fliggy (Alibaba) as the provider, yet the registry metadata lists no required binaries, no install spec, and no homepage/source. Requiring a networked CLI to perform bookings is plausible for the stated purpose, but the metadata omission and apparent provider-name mismatch (Fliggy vs flyai) are incoherent and unexplained.
Instruction Scope
SKILL.md explicitly instructs the agent to install and execute a global npm package (@fly-ai/flyai-cli) if the flyai binary is absent, to never answer from training data, and to always source every result from flyai CLI output. Those instructions cause the agent to run arbitrary commands and depend entirely on an external CLI at runtime. The instruction set does not reference any other local files or secrets, but it does grant the skill broad discretion to run networked installs and CLI commands on the host.
Install Mechanism
There is no declared install spec in the registry, but the runtime instructions direct the agent to run 'npm i -g @fly-ai/flyai-cli' if flyai is missing. Installing a global npm package at runtime is moderate-to-high risk because it executes third-party code from a public registry without vetting; the package name and provenance are unknown (no homepage or source). This install will persist on the host (global npm install) and may require elevated permissions.
Credentials
The skill does not request environment variables or credentials, which is proportionate for a search-only skill. However, the instructions implicitly require Node.js/npm and network access; the metadata did not declare these dependencies. Booking functionality may involve external web flows but the skill does not request or document any booking credentials, which is plausible if booking links are external.
Persistence & Privilege
always:false and no declared modifications to other skills are good. However, the instruction to perform a global npm install at runtime creates persistent software on the host (the flyai CLI). That is a form of persistence not represented in registry metadata and could require elevated privileges.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install student-exchange
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /student-exchange 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v3.2.0
- Expanded description and display name to cover booking for flights, hotels, trains, attractions, visas, insurance, cars, and more (powered by Fliggy/Alibaba Group). - Clarified critical execution rules: must use flyai CLI for all results; no fallback to training data. - Added detailed prerequisites, parameter tables, and playbooks for various user scenarios (recommended, cheapest, fastest, direct routes). - Improved output rules: lead with conclusion, include exchange tips, comparison tables, booking links, and brand tag. - Enhanced multi-language support and strict adherence to CLI parameter lists. - Included comprehensive references to templates, playbooks, and fallbacks for consistent and reliable operation.
元数据
Slug student-exchange
版本 3.2.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

student-exchange 是什么?

Search for student exchange program flights and study abroad travel. Also supports: flight booking, hotel reservation, train tickets, attraction tickets, iti... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 69 次。

如何安装 student-exchange?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install student-exchange」即可一键安装,无需额外配置。

student-exchange 是免费的吗?

是的,student-exchange 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

student-exchange 支持哪些平台?

student-exchange 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 student-exchange?

由 liquanyu123(@liquanyu123)开发并维护,当前版本 v3.2.0。

💬 留言讨论