安全扫描
OpenClaw
可疑
medium confidenceThe skill's description (Instagram analysis) mostly matches its instructions, but metadata and files are inconsistent (an API config implying Facebook Graph access vs. a no-op index.js and no declared credential requirements), so it appears unfinished or sloppy and needs clarification before trusting with real credentials or data.
评估建议
This skill looks like a mostly harmless, creative Instagram analysis tool, but its files are inconsistent: config.json hints at automatic Graph API access (instagram_id + access_token), while the actual code (index.js) is a no-op returning a static Italian message and the SKILL.md/prompt expect profile data to be provided. Before installing or supplying any real credentials: 1) Ask the author/source to explain whether the skill will fetch data from the Facebook/Instagram API or only operate on u...详细分析 ▾
ℹ 用途与能力
The stated purpose (generate Instagram content strategy) matches the prompts and SKILL.md. However, config.json declares type: "api-agent", inputs instagram_id and access_token and a Facebook Graph API base_url — which suggests the skill will fetch data from Instagram — while the skill's manifest and requirement list declare no required env/credentials. This is an internal inconsistency: either it needs API credentials or it expects input data to be supplied externally.
ℹ 指令范围
SKILL.md and prompt.md instruct the agent to analyze profile data and the last 10 posts (captions, engagement). They do not tell the agent to read unrelated files or env vars, nor to transmit data to unexpected endpoints. But prompt.md assumes the agent will 'receive' profile data; there are no instructions for how the skill should obtain that data (manual user input vs. Graph API). That ambiguity grants broad discretion and should be clarified.
✓ 安装机制
No install spec is present and the skill is instruction/code-only. Nothing will be downloaded or written during install according to the provided metadata.
ℹ 凭证需求
The skill does not declare required environment variables and the registry metadata lists none. Yet config.json lists instagram_id and access_token as inputs and a Graph API base_url — implying it may require Instagram/Facebook credentials to function. index.js as provided does not use these inputs. This mismatch means the skill may later be changed to request sensitive credentials; do not provide access tokens without confirmation of how they will be used/stored.
✓ 持久化与权限
The skill is not always-enabled and is user-invocable; it does not request persistent system privileges or claim to modify other skills or system settings.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/20
- Initial release of Instagram Strategic Analyzer for Il Prato. - Analyzes artist profiles and generates tailored Instagram content strategies. - Provides post ideas, storytelling concepts, and artistic branding suggestions. - Outputs include content ideas, captions, and creative direction. - Optimized for emotionally rich, narrative-driven musical content.
● 无害
安装命令
点击复制官方npx clawhub@latest install instagram-strategic-analyzer
镜像加速npx clawhub@latest install instagram-strategic-analyzer --registry https://cn.longxiaskill.com