安全扫描
OpenClaw
安全
high confidenceNULL
评估建议
This skill is internally coherent and simply documents how to use the Membrane CLI to work with Subscribe‑HR. Before installing or running commands: (1) verify you trust the @membranehq package and the getmembrane.com service (review publisher, npm package page, and privacy/security docs); (2) prefer using npx or inspect the CLI package before a global npm install; (3) be aware that creating a Membrane connection grants that connection access to your Subscribe‑HR data — limit permissions and rev...详细分析 ▾
✓ 用途与能力
The name and description claim Subscribe‑HR integration and all runtime instructions are about using the Membrane CLI to discover/connect/run actions or proxy requests to Subscribe‑HR. No unrelated services, credentials, or tools are requested.
✓ 指令范围
SKILL.md limits actions to installing/using @membranehq/cli, performing membrane login/connect/action/request commands, and discovering actions. It does not instruct the agent to read arbitrary host files, environment variables, or to transmit data to endpoints outside Membrane/Subscribe‑HR.
ℹ 安装机制
There is no embedded install spec in the skill bundle, but the instructions tell the user to run npm install -g @membranehq/cli (and recommend npx in examples). Installing a global npm package is a reasonable and expected step for a CLI-based integration, but it carries the usual moderate risk of installing third‑party code; prefer npx or auditing the package if you have concerns.
✓ 凭证需求
The skill declares no required environment variables or secrets. Authentication is delegated to Membrane's login flow (browser-based), which is proportional to the goal. Note: creating a connection in Membrane grants that connection access to Subscribe‑HR data, which is appropriate for this integration but is a privilege you should understand and control.
✓ 持久化与权限
The skill is not always-on and does not request elevated platform privileges. It is instruction-only and does not modify other skills or system-wide settings. Autonomous invocation is allowed by default but is not combined with other worrying privileges here.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/9
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install subscribe-hr
镜像加速npx clawhub@latest install subscribe-hr --registry https://cn.longxiaskill.com