安全扫描
OpenClaw
安全
high confidence此技能仅存储用户提供的个性特征文件, 无需外部凭证、安装或隐藏网络行为。
评估建议
["此技能如声称般运作:构建和存储用户输入的个性特征,用于模拟响应。","使用前注意:","1. 不要粘贴他人敏感/私人信息(健康、财务、私人消息)。","2. 为真实人物创建个人资料前,获得同意;谨慎模拟活跃的公众人物。","3. 如果存储敏感回忆,保护 ~/.sister-skill 文件夹(考虑文件系统权限或加密)。","4. 记住 SKILL.md 中的“无外部传输”是政策声明,不是技术保证——如果需要更强的保证,请检查代理/运行时设置和网络策略。","5. 注意此技能的来源/主页未知;如果来源重要性,优先选择有可见维护者或审计过的源代码的技能。"]...详细分析 ▾
✓ 用途与能力
The skill's name/description (distilling sisters' personalities) aligns with its files and declared requirements: no binaries, no env vars, and only local storage under ~/.sister-skill. Nothing requested is disproportionate to the stated purpose.
ℹ 指令范围
SKILL.md gives concrete runtime behavior (extract dimensions from user input, create/update local PROFILE.md and JSONL logs, answer in stored style). It explicitly states it will not access social accounts or transmit data. Note: the skill permits simulating real people (including public creators) — this is an ethical/privacy risk and the user must ensure consent and avoid entering sensitive personal data.
✓ 安装机制
Instruction-only skill with no install spec and no code files to execute. Lowest-risk install surface (nothing is downloaded or written by an installer).
✓ 凭证需求
No environment variables, credentials, or config paths are requested. Declared storage path (~/.sister-skill) is reasonable and narrowly scoped.
✓ 持久化与权限
always:false and user-invocable:true (normal). The skill persists only to its own stated folder; it does not request system-wide changes or cross-skill config modifications.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.12026/4/10
**主要简化和以隐私为首的重设计。现在完全专注于用户驱动的本地记忆捕获。**
● 无害
安装命令 点击复制
官方npx clawhub@latest install sister
镜像加速npx clawhub@latest install sister --registry https://cn.clawhub-mirror.com
技能文档
简介
此技能模拟姐妹、闺蜜或女性内容创作者的个性特征,完全基于本地存储,尊重用户隐私。使用指南
- 输入个性描述以创建个人资料
- 使用创建的个人资料模拟响应
注意事项
- 仅存储本地, 无外部数据传输
- 尊重他人隐私,获得同意后创建个人资料
# ... (原始代码块、命令行指令和 Markdown 格式保持不变,仅示例)
数据来源:ClawHub ↗ · 中文优化:龙虾技能库
OpenClaw 技能定制 / 插件定制 / 私有工作流定制
免费技能或插件可能存在安全风险,如需更匹配、更安全的方案,建议联系付费定制