← 返回 Skills 市场
Top Attractions
作者
dingtom336-gif
· GitHub ↗
· v3.2.0
· MIT-0
62
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install top-attractions
功能描述
Discover the most popular and highest-rated attractions in any city. Shows top-tier POIs with ticket prices, opening hours, and booking links. Also supports:...
安全使用建议
This skill is suspicious but not obviously malicious. Before installing or enabling it: 1) Verify the source of the '@fly-ai/flyai-cli' package on npm (inspect the package code, maintainer, and recent releases). 2) Ask the skill author for a homepage or vendor contact and clarification about the Fliggy claim and how bookings/authentication work. 3) If you must try it, run the CLI install and skill in a sandboxed environment (container or VM) and review any files it writes (e.g., .flyai-execution-log.json). 4) Consider disabling autonomous invocation unless you trust the CLI package and want the agent to run networked commands without prompting.
功能分析
Type: OpenClaw Skill
Name: top-attractions
Version: 3.2.0
The skill bundle instructs the AI agent to automatically perform a global installation of an external NPM package (`@fly-ai/flyai-cli`) if it is missing, which is a high-privilege system modification. Additionally, `references/runbook.md` directs the agent to log user queries and execution metadata to a local hidden file (`.flyai-execution-log.json`). While these behaviors are plausibly linked to the stated travel-search functionality, the automated software installation and local data persistence represent significant security and privacy risks.
能力评估
Purpose & Capability
The description claims 'Powered by Fliggy (Alibaba Group)' and broad support (flights, hotels, insurance, etc.), but the instructions only call a third-party CLI 'flyai' and show POI search commands. There is no homepage or vendor info, and no declared credentials for Fliggy. The Fliggy branding vs 'flyai' CLI is a mismatch and the broader claimed capabilities are not justified by the provided commands.
Instruction Scope
Runtime instructions strictly require running the flyai CLI and forbids using training data. They do not instruct reading arbitrary system files, but the runbook suggests creating/writing .flyai-execution-log.json containing the raw user_query and CLI call logs, which could persist sensitive user input. The instructions also insist on re-executing until every result includes a [Book]({detailUrl}) link — this enforces repeated network/CLI calls.
Install Mechanism
The skill has no registry install spec but instructs the agent to run 'npm i -g @fly-ai/flyai-cli'. Installing a global npm package is a moderate-risk operation (downloads and executes third-party code). The package name is not a well-known vendor in the manifest, and no checksum or verified release source is provided — verify the npm package and its code before installing.
Credentials
The skill declares no required credentials or env vars, yet promises booking links and other transactional features. It may rely entirely on the external CLI for auth, but that is unspecified. The lack of declared credentials is not necessarily malicious, but combined with unknown CLI provenance and Fliggy branding inconsistency it warrants caution.
Persistence & Privilege
always:false and no system-wide privileges are requested. However, the runbook explicitly suggests appending logs to .flyai-execution-log.json in the working directory, which gives the skill write persistence in the user's environment and may store user-provided queries. This is limited but should be considered before granting autonomous invocation.
如何使用
- 确保已安装 OpenClaw(本地或 Docker 部署)
- 在对话框中输入安装命令:
/install top-attractions - 安装完成后,直接呼叫该 Skill 的名称或使用
/top-attractions触发 - 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v3.2.0
top-attractions v3.2.0 Changelog
- Major rewrite of SKILL.md to emphasize CLI-only execution and strict usage of the flyai command.
- Added detailed critical execution rules: never answer with training data, always install/verify flyai-cli, must show booking links.
- Clarified English and Chinese language handling according to user query.
- Expanded playbooks and scenario triggers for broader coverage (top rated, category, kid-friendly, etc.).
- Introduced strict output validation and formatting requirements, including markdown comparison tables and booking links.
- Updated compatibility notes and reference file usage.
元数据
常见问题
Top Attractions 是什么?
Discover the most popular and highest-rated attractions in any city. Shows top-tier POIs with ticket prices, opening hours, and booking links. Also supports:... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 62 次。
如何安装 Top Attractions?
在 OpenClaw 或 Claude Code 对话框中运行命令「/install top-attractions」即可一键安装,无需额外配置。
Top Attractions 是免费的吗?
是的,Top Attractions 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。
Top Attractions 支持哪些平台?
Top Attractions 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。
谁开发了 Top Attractions?
由 dingtom336-gif(@dingtom336-gif)开发并维护,当前版本 v3.2.0。
推荐 Skills