📦 IceCube Voice Clone
v1.0.0🧊 IceCube 声音克隆 — AI 声音克隆技术指南与集成。支持 ElevenLabs、Fish Audio、Resemble AI 等主流工具。当用户提到“声音克隆”、“voice clone”、“克隆声音”、“AI 语音”时使用。
0· 57·0 当前·0 累计
下载技能包
License
MIT
安全扫描
OpenClaw
可疑
medium confidenceThe skill is largely a coherent how-to for voice cloning, but it references provider APIs and local scripts that aren't declared or included and doesn't explicitly declare how/when API keys would be used — these inconsistencies deserve caution before installing or granting credentials.
评估建议
This appears to be a legitimate voice-cloning guide rather than hidden malware, but take these precautions before using it:
- The SKILL.md references scripts and sample files that are not included; ask the author for the missing files or clarify whether those are just planned artifacts. Do not assume absent scripts will be created automatically.
- The guide shows API examples requiring provider keys (e.g., xi-api-key). Confirm how the agent will request/store those keys and never paste keys int...详细分析 ▾
ℹ 用途与能力
The name and description match the SKILL.md content: it's a guide for voice-cloning using ElevenLabs, Fish Audio, Resemble AI, and open-source SoVITS. However the document lists a file structure with scripts and sample audio that are not present in the package manifest, which is an inconsistency between claimed deliverables and what's actually provided.
✓ 指令范围
Runtime instructions are instructional only (how to upload audio, call provider APIs, deploy GPT-SoVITS). The SKILL.md does not instruct reading unrelated system files or harvesting credentials from the environment. It includes example API calls (with placeholders for API keys) but does not autonomously direct the agent to exfiltrate data.
✓ 安装机制
There is no install spec and no code files beyond SKILL.md, so nothing will be written to disk by an installer. This is low-risk from an installation perspective.
ℹ 凭证需求
The skill declares no required environment variables or credentials, yet the instructions show API usage (e.g., xi-api-key for ElevenLabs). Requesting API keys at runtime would be proportionate to the described functionality, but the skill does not state how keys are provided or stored — check whether the agent will prompt for/require keys and how they are handled. Also note that voice-cloning inherently requires sensitive audio data and provider tokens; ensure you only provide credentials for services you trust.
✓ 持久化与权限
The skill is not set to always: true and does not request persistent presence or elevated agent privileges. It does mention integrating with an existing ElevenLabs skill but does not indicate modifying other skills or global agent configuration.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
安装命令
点击复制官方npx clawhub@latest install icecube-voice-clone
镜像加速npx clawhub@latest install icecube-voice-clone --registry https://cn.longxiaskill.com