agent-travel — 代理-travel
v0.2.11Re搜索 unresolved 代理 problems during 心跳, cron, task-end, or idle windows; use local 上下文 and memory to f对象关系映射 safe 网页 queries; 搜索 official...
0· 164·0 当前·0 累计
安全扫描
OpenClaw
安全
high confidenceThe skill's manifest, instructions, and included scripts are internally consistent with a background 'quiet-window' research helper that requires Python and relies on the host to perform web/search actions; nothing requested or installed is disproportionate to that purpose.
评估建议
This package appears coherent and well-scoped, but you should still: 1) review the actual Python scripts (e.g., scripts/plan_travel.py, scripts/should_travel.py, scripts/validate_suggestions.py) for any unexpected network calls or file-system access before running them; 2) confirm your host enforces the SKILL.md rules (redaction, advisory-only output, no writing to core/system prompts or permanent memory); 3) note that disable-model-invocation:true means the host/scheduler must call the skill (i...详细分析 ▾
✓ 用途与能力
Name/description match the delivered artifacts: the repo contains trigger/plan/validator scripts and documentation for a host-driven background research flow. Requiring python/python3 is appropriate for the included Python scripts; no unrelated credentials, binaries, or config paths are requested.
✓ 指令范围
SKILL.md bounds runtime behavior: build a redacted fingerprint, prefer public-first search, redact secrets, do dry-run planning locally (plan_travel.py claims no network), require cross-validation, and write advisory-only hints to an isolated suggestion channel. The instructions explicitly forbid adding results to system prompts or permanent memory and require redaction before any search.
✓ 安装机制
No install spec is provided (instruction-only skill). The package includes Python scripts and test fixtures but does not declare downloads or post-install steps. This is low-risk relative to other install mechanisms; the host will need to run the included scripts.
✓ 凭证需求
No environment variables or external credentials are requested. The skill's operational needs (local Python scripts, reading provided JSON state fixtures) align with this. SKILL.md also emphasizes redaction and opts-in usage for private/internal sources.
✓ 持久化与权限
The skill does not request always:true and does not declare model invocation capability (disable-model-invocation: true), so it cannot be autonomously invoked by the model in-band; this matches the design where the host (scheduler/heartbeat) should call it. It does write structured suggestions to an isolated suggestion channel per its contract, which is intended and scoped to the active conversation only.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
安装命令
点击复制官方npx clawhub@latest install agent-travel
镜像加速npx clawhub@latest install agent-travel --registry https://cn.longxiaskill.com 镜像可用
本土化适配说明
agent-travel — 代理-travel 安装说明: 安装命令:["openclaw skills install agent-travel","npx clawhub@latest install agent-travel"]