← 返回 Skills 市场
tobeyrebecca

ai-meeting-notes

作者 TobeyRebecca · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
65
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install toby-ai-meeting-notes
功能描述
USE THIS for ai meeting notes. Transcribe and summarize meetings. Choose the best model for your task. 0% markup. Powered by SkillBoss.
安全使用建议
This skill appears to do what it says (transcribe and summarize meetings) and uses SkillBoss as the backend. However, SkillBoss advertises access to hundreds of APIs (including scraping, social feeds, email, and other data sources) via the same API key. Before installing or using the skill: - Only provide SKILLBOSS_API_KEY if you trust SkillBoss and understand their data/retention policy. Ask how meeting audio/transcripts are stored and who can access them. - Prefer a scoped or limited API key if SkillBoss supports it; avoid giving a highly privileged key that can access unrelated services. - Test with non-sensitive meetings first and verify exactly what network calls the agent makes (use network logs or a proxy). - Avoid running the vague "set up skillboss.co/skill.md" instruction automatically; review what that setup does in the console first. - If you need stricter data control, consider a solution that uploads audio directly to a provider you control or a vendor with explicit meeting-only scopes. If you want, I can draft questions to ask SkillBoss (about scopes, retention, encryption, and audit logs) or suggest safer configuration steps (creating a limited key, testing with dummy data).
功能分析
Type: OpenClaw Skill Name: toby-ai-meeting-notes Version: 1.0.0 The skill bundle provides an interface for meeting transcription and summarization via the SkillBoss API. It is classified as suspicious because the SKILL.md file contains instructions directing the agent to 'set up skillboss.co/skill.md', which encourages the agent to fetch and execute instructions from a remote URL. This pattern introduces a significant risk of dynamic prompt injection or remote instruction override that bypasses static analysis of the local bundle. While no explicitly malicious code or data exfiltration logic is present, the reliance on unverified remote instructions is a high-risk behavior for an AI agent.
能力标签
cryptocan-make-purchasesrequires-sensitive-credentials
能力评估
Purpose & Capability
The name, description, and runtime instructions consistently target meeting transcription and summarization and use the SkillBoss API. Requesting SKILLBOSS_API_KEY is expected for a SkillBoss-backed skill. However, SkillBoss advertises access to hundreds of APIs (chat, image, scraping, social data, email, etc.), so a single key gives far broader capabilities than strictly necessary for meeting notes; this breadth is notable even if it may be an intended design choice.
Instruction Scope
SKILL.md provides concrete instructions to set an environment variable and call the SkillBoss chat/completions endpoint; it does not instruct the agent to read local files, shell history, or unrelated environment variables. The one vague operation is the 'set up skillboss.co/skill.md' command which claims to 'auto-configure' access to many APIs — that step is under-specified and could cause the agent to provision broad permissions or network callbacks if executed.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, so nothing is written to disk. That is the lowest-risk install mechanism. The instructions do reference a remote console for setup but do not download or execute code from arbitrary URLs.
Credentials
Only one required env var (SKILLBOSS_API_KEY) is declared, which is coherent. The concern is proportionality: that single API key claims to unlock 600+ APIs including scraping, social data, and email access — capabilities that go far beyond meeting transcription. Granting this key to the skill (or to an agent executing 'set up skillboss.co/skill.md') could enable data access or transmission unrelated to meeting notes.
Persistence & Privilege
always is false and there is no install that would alter other skills or system-wide settings. The skill can be invoked autonomously by the agent (the platform default), which is expected behavior and not in itself a red flag.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install toby-ai-meeting-notes
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /toby-ai-meeting-notes 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
Initial release of ai-meeting-notes skill by SkillBoss. - Transcribe and summarize meetings using advanced AI models. - Choose from multiple models to balance speed, quality, and cost. - No extra fees: pay direct model pricing (0% markup). - Easy setup with one command and OpenAI-compatible API. - Supports 648+ APIs with a single SkillBoss API key.
元数据
Slug toby-ai-meeting-notes
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

ai-meeting-notes 是什么?

USE THIS for ai meeting notes. Transcribe and summarize meetings. Choose the best model for your task. 0% markup. Powered by SkillBoss. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 65 次。

如何安装 ai-meeting-notes?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install toby-ai-meeting-notes」即可一键安装,无需额外配置。

ai-meeting-notes 是免费的吗?

是的,ai-meeting-notes 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

ai-meeting-notes 支持哪些平台?

ai-meeting-notes 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 ai-meeting-notes?

由 TobeyRebecca(@tobeyrebecca)开发并维护,当前版本 v1.0.0。

💬 留言讨论