📦 WeShop CLI — AI 时尚图片视频生成
v1.0.3专业 AI 时尚照片、图片和视频生成器,CLI 驱动。
1· 115·0 当前·0 累计
下载技能包
最后更新
2026/4/9
安全扫描
OpenClaw
安全
medium confidenceThe skill's declared requirements and instructions are coherent with an image/video generation CLI — it only needs a WESHOP_API_KEY and the weshop CLI — but it relies on an external npm/GitHub CLI and will upload content to a third‑party service, so review the vendor and package before use.
评估建议
This skill is coherent for calling the weshop CLI, but it depends on an external npm/GitHub CLI and a remote service. Before installing or using it: 1) Verify the weshop-cli package and its GitHub repository (review code, maintainer reputation, recent releases). 2) Understand that images (including faces) you provide will likely be uploaded to the vendor (openapi.weshop.ai) — do not upload images with minors or people who haven't consented. 3) Keep your WESHOP_API_KEY secret; follow the SKILL.md...详细分析 ▾
✓ 用途与能力
The skill is an instruction-only wrapper for the weshop CLI and declares WESHOP_API_KEY as its sole credential; that aligns with an image/video generation/editing tool. The listed commands (virtualtryon, face-swap, removebg, etc.) are consistent with the described fashion/image transformations.
ℹ 指令范围
SKILL.md instructs the agent to check WESHOP_API_KEY and to run the weshop CLI (e.g., weshop --version, weshop <command>). It does not instruct reading unrelated system files or other environment variables. Important: using the CLI will typically upload user images to the vendor (openapi.weshop.ai) — the document asserts the API key is sent only to that endpoint but the agent/user should assume image data will be transmitted to the remote service. The skill also contains many sensitive transformation options (face swap, age/gender/bodysize transforms) which require ethical consideration and consent.
ℹ 安装机制
There is no automated install spec in the skill bundle (instruction-only). However SKILL.md recommends installing weshop-cli via npm (npm install -g weshop-cli@0.2.1) and points to a GitHub repo. Installing a third-party global npm package executes code on the host and is a moderate risk: you should inspect the package/source and provenance before installing.
✓ 凭证需求
Only WESHOP_API_KEY is required and declared as the primary credential, which is proportionate for a CLI that talks to an external API. The SKILL.md also explicitly warns not to pass the API key on the command line and to ask the user only if the env var is missing; no other secrets or unrelated env vars are requested.
✓ 持久化与权限
The skill is not always-enabled, does not request persistent platform privileges, and does not declare any actions that modify other skills or global agent configuration. Autonomous invocation is allowed (platform default) but that is not combined with elevated privileges here.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.32026/4/3
weshop-cli-skill 1.0.3 - No changes in code or documentation detected for this version. - Skill functionality and description remain unchanged.
● 可疑
安装命令
点击复制官方npx clawhub@latest install weshop-cli-skill
镜像加速npx clawhub@latest install weshop-cli-skill --registry https://cn.longxiaskill.com