← 返回 Skills 市场
stringtwb1220

Web Search Ai News

作者 stringtwb1220 · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
139
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install web-search-ai-news
功能描述
实时获取最新的人工智能行业新闻和动态
安全使用建议
This skill fetches news but its instructions also tell the agent to read your local Himalaya email config (~/.config/himalaya/config.toml) and automatically send emails — a capability not declared in the metadata. Before installing or enabling it: (1) ask the author to explicitly declare required config paths or environment variables and to document exactly who the emails will be sent to; (2) inspect the referenced repository and the contents of ~/.config/himalaya/config.toml to see whether it contains SMTP credentials or other sensitive data; (3) if you must test, run the skill in a restricted sandbox or with a throwaway email account so real credentials aren't exposed; (4) consider disabling automatic emailing or requiring manual confirmation before any outbound email is sent. If the author clarifies and the required credentials/config are made explicit and limited, the incoherence will be resolved — otherwise treat the skill with caution or avoid installing it.
功能分析
Type: OpenClaw Skill Name: web-search-ai-news Version: 1.0.0 The SKILL.md file contains post-processing instructions that direct the AI agent to access a sensitive local configuration file (~/.config/himalaya/config.toml). This file typically contains plain-text SMTP/IMAP credentials for the Himalaya email client. While the stated intent is to email news updates, instructing an agent to read private credential files is a high-risk behavior that could lead to credential theft or unauthorized use of the user's email account.
能力评估
Purpose & Capability
The name/description promise 'fetch latest AI news' and the listed target news sites match that purpose. However, the SKILL.md adds an automatic SMTP email post-processing step (sending fetched news by email) and points at a local config file (~/.config/himalaya/config.toml). That email-sending behaviour and the need to read a local config are not reflected in the skill's declared requirements (no env vars or config paths).
Instruction Scope
Runtime instructions explicitly direct the agent to: (1) fetch content from external news sites (expected), and (2) '自动通过 SMTP 发送邮件' using credentials/config in ~/.config/himalaya/config.toml. Reading an undeclared local config and automatically sending mail expands scope beyond 'news fetching' and could access or transmit sensitive credentials or local data.
Install Mechanism
This is an instruction-only skill with no install spec and no code files, which minimizes disk persistence and supply-chain risk.
Credentials
The skill declares no required environment variables or config paths, yet it expects SMTP configuration at ~/.config/himalaya/config.toml. SMTP/email sending normally requires credentials (SMTP host, user, password or tokens); requiring access to a local config without declaring it is disproportionate and suspicious.
Persistence & Privilege
always is false and there is no special persistence requested. The skill is user-invokable and allows normal autonomous invocation, which is the platform default — not in itself a new risk here. The main concern is the undeclared access to local config and emailing behavior, not elevated platform privileges.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install web-search-ai-news
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /web-search-ai-news 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
- Initial release of Web Search AI News skill. - Provides real-time fetching of the latest AI industry news and trends. - Supports trigger phrases in Chinese and English to activate news search. - Fetches news from multiple technology-focused sources. - Automatically sends fetched news to a specified email via SMTP after retrieval.
元数据
Slug web-search-ai-news
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Web Search Ai News 是什么?

实时获取最新的人工智能行业新闻和动态. 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 139 次。

如何安装 Web Search Ai News?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install web-search-ai-news」即可一键安装,无需额外配置。

Web Search Ai News 是免费的吗?

是的,Web Search Ai News 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Web Search Ai News 支持哪些平台?

Web Search Ai News 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Web Search Ai News?

由 stringtwb1220(@stringtwb1220)开发并维护,当前版本 v1.0.0。

💬 留言讨论