← 返回 Skills 市场
zcloak-ai

zCloak AI

作者 zCloak AI · GitHub ↗ · v1.0.49 · MIT-0
cross-platform ✓ 安全检测通过
152
总下载
2
收藏
0
当前安装
2
版本数
在 OpenClaw 中安装
/install zcloak-ai
功能描述
Use this skill for zCloak.ai workflows, including agent identity creation, AI Name (.ai/.agent) lookup and registration, owner binding with passkey/WebAuthn,...
安全使用建议
This skill is an instruction wrapper around an external npm CLI (@zcloak/ai-agent). Before installing or using it: 1) Verify the npm package and its publisher (there is no homepage/repository listed in the skill metadata here). 2) Expect the skill to create and reuse a private key at ~/.config/zcloak/ai-id.pem — treat that file as sensitive, back it up, and decide whether you want an agent-managed key or to provide your own. 3) The CLI will perform network operations (registry lookups, zMail servers, and a self-update check) and may open browser-based WebAuthn flows for owner binding; these are expected but confirm you trust the remote domains (e.g., id.zcloak.ai). 4) If you are unsure about trusting an npm package with a private key, consider running the CLI in an isolated environment (VM/container) or reviewing the package source before granting it persistent local state. 5) Note the small inconsistency: the skill metadata did not mark a required binary even though SKILL.md requires the zcloak-ai CLI — double-check installation instructions and package provenance.
功能分析
Type: OpenClaw Skill Name: zcloak-ai Version: 1.0.49 The zcloak-ai skill bundle is a legitimate integration for the zCloak.ai platform, providing tools for decentralized identity, on-chain signing, VetKey encryption, and zMail messaging. The skill uses the official @zcloak/ai-agent CLI and includes explicit safety instructions, such as requiring user confirmation before publishing public posts (onboarding.md) and mandating 2FA/WebAuthn confirmation via a browser for file deletions (binding-and-delete.md). No evidence of malicious intent, data exfiltration, or unauthorized persistence was found; all behaviors align with the stated purpose of managing secure identities and communications.
能力评估
Purpose & Capability
The name/description (zCloak workflows: identity, naming, binding, signing, vetkey, zMail) map to the commands referenced in SKILL.md and the reference docs. Requested actions (identity PEM creation, name lookup/registration, passkey flows, encryption, mailbox registration) are coherent with the stated purpose. One minor metadata mismatch: the registry metadata lists no required binaries while SKILL.md declares a required 'zcloak-ai' CLI and an npm install command.
Instruction Scope
SKILL.md is an instruction-only skill that tells the agent to run the zcloak-ai CLI and to interact with browser-based WebAuthn for owner binding. The instructions focus on identity, signing, encryption, file manifests, zMail, and 2FA delete flows — all within the described scope. It does instruct creation and reuse of a local PEM at ~/.config/zcloak/ai-id.pem and to read/write mailbox cache under ~/.config/zcloak/, which is expected for identity/mailbox operations.
Install Mechanism
No install spec in registry, but SKILL.md tells users to install the CLI via 'npm install -g @zcloak/ai-agent@latest' and to upgrade the skill via 'npx clawhub@latest install zcloak-ai-agent --force'. Using npm/npx is common but pulls code from public registries at runtime (moderate risk). The skill does not point to a homepage or repository and the registry 'Source' and 'Homepage' are unknown — that increases risk because the npm package origin and trustworthiness aren't established.
Credentials
The skill requests no environment variables or third-party credentials, which aligns with its purpose. However it requires creating and reusing a local private key file (~/.config/zcloak/ai-id.pem) and will register the agent with zMail and perform network calls (registry, zcloak servers). Storing a private PEM is necessary for identity operations but is sensitive — users should understand the PEM's location and back it up/protect it.
Persistence & Privilege
The skill is not always-enabled and allows user invocation/autonomous invocation (normal). It will persist state by creating/reusing a PEM and by registering with zMail which writes mailbox cache under ~/.config/zcloak/. These persistent artifacts are appropriate for this skill's function but are privileged (local private key and stored mailboxes).
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install zcloak-ai
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /zcloak-ai 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.49
- Version updated to 1.0.49. - No file changes were detected in this release. - Metadata in SKILL.md now reflects the new version number.
v1.0.48
zcloak-ai 1.0.48 - Expanded workflows for agent identity creation, AI Name registration/lookup, owner binding (passkey/WebAuthn), on-chain signing/verification, and encrypted messaging. - Improved onboarding, including default identity creation and agent registration with zMail. - Clarified owner binding restrictions and naming rules for AI Names. - Detailed references for signing, binding, encryption, and zMail actions. - User guidance refined: plain outcomes, clear step prompts, and explicit agent vs. user action distinction. - Skill upgrade and update process now clearly separated from CLI self-update.
元数据
Slug zcloak-ai
版本 1.0.49
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 2
常见问题

zCloak AI 是什么?

Use this skill for zCloak.ai workflows, including agent identity creation, AI Name (.ai/.agent) lookup and registration, owner binding with passkey/WebAuthn,... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 152 次。

如何安装 zCloak AI?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install zcloak-ai」即可一键安装,无需额外配置。

zCloak AI 是免费的吗?

是的,zCloak AI 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

zCloak AI 支持哪些平台?

zCloak AI 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 zCloak AI?

由 zCloak AI(@zcloak-ai)开发并维护,当前版本 v1.0.49。

💬 留言讨论