Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

智能微信公众号发布技能

v1.1.4

自动收集15条AI新闻,生成HTML内容,并定时发布至微信公众号草稿箱,支持多模板和自定义发布时间。

0· 102·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for 403914291/smart-wechat-publisher.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "智能微信公众号发布技能" (403914291/smart-wechat-publisher) from ClawHub.
Skill page: https://clawhub.ai/403914291/smart-wechat-publisher
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install smart-wechat-publisher

ClawHub CLI

Package manager switcher

npx clawhub@latest install smart-wechat-publisher
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill claims to '自动收集 15 条 AI 新闻' but the visible publish.py builds content from static placeholders (no news-scraping or aggregator calls). The skill also documents auxiliary scripts (install.sh, activate.py) that are referenced in SKILL.md but are not present in the file manifest — this mismatch suggests the package as provided is incomplete or the documentation is out of date.
!
Instruction Scope
SKILL.md instructs storing AppID/AppSecret and running install/activation flows; the runtime script reads config files and an environment variable (WECHAT_APP_SECRET) that is not declared in the registry metadata. The instructions reference external purchase/activation interactions (contacting a maintainer, scanning QR codes) which are outside the skill runtime and rely on out-of-band processes. The code writes local license/usage/token files under its own memory directory (expected) but the discrepancy between claimed automatic news collection and the actual content preparation is scope creep / inconsistency.
Install Mechanism
There is no external install spec or network download embedded in the skill bundle itself — the skill is instruction/code-only. No install-from-URL or extract operations were specified in the manifest, which lowers installation risk. (That said, SKILL.md mentions an external zip source in docs; the bundle provided here does not include such a download.)
Credentials
Requesting WeChat credentials (AppID and AppSecret) is appropriate for a publisher skill. However, the registry metadata lists no required env vars while the code reads an environment variable WECHAT_APP_SECRET if present (and falls back to a config file). That undeclared env-var and the mismatch between declared required credentials in the manifest and in SKILL.md/configs is an inconsistency the maintainer should clarify before you enter secrets.
Persistence & Privilege
The skill does not request always:true, does not modify other skills, and stores data under its own script_dir/memory subdirectory (token cache, usage, license). It requires typical local persistence for caching and trial accounting but does not request elevated system privileges in the visible code.
What to consider before installing
Do not paste your WeChat AppSecret or AppID into this skill yet. The code you shipped does not show any actual news-collection logic (it uses static placeholders) and SKILL.md refers to install/activation scripts that are missing from the package — this could be an incomplete release or deliberately partial. Before installing or entering credentials: 1) request the full, un-truncated publish.py and the missing scripts (install.sh, activate.py) and review them for outbound network calls beyond api.weixin.qq.com; 2) verify where config/credentials will be stored on disk (~/.agents/... or the skill directory) and inspect those files for any upload/telemetry behavior; 3) if you must test, run the skill in an isolated environment (throwaway account or container) and monitor network traffic; 4) prefer to configure AppSecret in a per-skill config file rather than as a system-wide env var, and revoke/reset the AppSecret after testing if anything looks suspicious. The package's mismatches lower my confidence — clarifying the missing files and confirming the code that actually fetches news would move this toward 'benign.'

Like a lobster shell, security has layers — review code before you run it.

latestvk97cjdsm6r7s0pd9p2bzmaqcdn83pgph
102downloads
0stars
6versions
Updated 1mo ago
v1.1.4
MIT-0

微信公众号发布技能

技能名称: wechat-publisher
版本: V1.1.2
描述: 自动发布 AI 新闻到微信公众号草稿箱
作者: 小蛋蛋
技术支持: 403914291@qq.com
公众号: 心识孤独的猪手


📋 功能特性

  • ✅ 自动收集 15 条 AI 新闻
  • ✅ 自动生成 HTML 格式内容
  • ✅ 自动发布到公众号草稿箱
  • ✅ 支持 5 套专业模板
  • ✅ 50 次免费试用 + 8.8 元永久买断
  • ✅ 支持自定义发布时间

🔧 配置项

配置项说明默认值是否必填
app_id公众号 AppID-✅ 是
app_secret公众号 AppSecret-✅ 是
schedule发布时间06:00❌ 否
template发布模板v5-simple❌ 否
news_count新闻条数15❌ 否
timezone时区Asia/Shanghai❌ 否

📖 使用说明

安装技能

openclaw skill install wechat-publisher

配置技能

openclaw skill config wechat-publisher

设置发布时间

openclaw schedule wechat-publisher 07:00

查看状态

openclaw skill status wechat-publisher

💰 授权说明

  • 试用版: 50 次免费使用(约 1 个月)
  • 专业版: 8.8 元永久买断
  • 购买命令: openclaw skill buy wechat-publisher

📊 试用次数说明

50 次免费试用包含:

  • ✅ 测试所有 5 套模板
  • ✅ 配置调试和学习成本
  • ✅ 约 1 个月的实际使用
  • ✅ 充分体验自动发布功能

试用次数用完后:

  • 运行 openclaw skill buy wechat-publisher 购买专业版
  • 8.8 元永久买断,无限次使用

📞 支付联系方式

支付流程:

  1. 运行购买命令后,系统生成订单
  2. 用户扫码支付(微信/支付宝)
  3. 支付成功后,通过以下方式联系管理员获取激活码:
联系方式说明
微信添加管理员微信:lylovejava(备注:技能购买)
公众号关注"小蛋蛋助手"公众号,发送订单号
邮箱support@wechat-publisher.ai(24 小时内回复)
GitHubhttps://github.com/403914291 提交 Issue

自动激活(推荐):

  • 支付成功后,系统自动发送激活码到用户邮箱
  • 或在购买界面直接显示激活码

📁 文件结构

wechat-publisher-skill/
├── SKILL.md              # 技能定义文件
├── publish.py            # 核心发布脚本
├── scripts/
│   ├── install.sh        # 安装脚本
│   └── activate.py       # 激活脚本
├── templates/
│   ├── v5-simple.html    # V5 简洁模板
│   └── ...               # 其他模板
├── config/
│   └── default.json      # 默认配置
└── docs/
    └── USER_GUIDE.md     # 用户手册

创建日期:2026-03-26
最后更新:2026-03-26

Comments

Loading comments...