AI News ZH - 中文AI科技日报
v1.0.0中文AI科技日报自动采集与推送。从The Verge、Wired、TechCrunch等英文源抓取最新AI资讯,自动翻译整理为中文,按分类推送到飞书/Telegram/Discord等渠道。适合关注AI行业动态的中文用户。
⭐ 11· 4.5k·63 current·67 all-time
by子豪@aizain
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name/description align with the runtime instructions: collecting news via web_fetch, translating, classifying, and pushing to chat channels. However, the skill claims push support for Feishu/Telegram/Discord but does not declare any required credentials, config paths, or explain how the agent will authenticate to those services. The absence of expected push credentials is an incoherence between claimed capability and declared requirements.
Instruction Scope
SKILL.md stays on-topic (fetch sources, extract metadata, translate, dedupe, format, push). But the instructions are vague about crucial runtime details: where '已采集内容' (for dedup/incremental updates) is stored, how long-term state or history is persisted, and exactly how pushes are delivered (which tool handles authentication). It also grants broad discretion for filtering/sorting without deterministic rules, which could make behavior unpredictable.
Install Mechanism
Instruction-only skill with no install spec or code files — minimal install risk. All external fetching relies on platform tools (web_fetch, optional web_search/message); nothing is downloaded or written by an installer.
Credentials
No environment variables or primary credential are declared, yet the skill expects to push to external messaging platforms and optionally use a Brave API key for web_search. The absence of declared credentials for push endpoints (tokens, webhook URLs, etc.) is disproportionate to the claimed capability and leaves unclear how secrets are to be supplied and protected.
Persistence & Privilege
The skill does not request always-on inclusion or any special platform privileges. It does reference scheduled (cron) runs, but that is normal. No evidence it attempts to modify other skills or system-wide settings.
What to consider before installing
This skill appears to do what it says (scrape news, translate, and push), but important details are missing. Before installing or enabling it: (1) confirm how push credentials (Feishu/Telegram/Discord tokens or webhook URLs) are provided and stored — do not paste long-lived secrets into a chat; use the platform's secure secret storage if available; (2) ask where deduplication/history is stored (conversation memory, external DB, local file?) and ensure it meets your privacy needs; (3) test with manual runs to verify formatting and rate limits before enabling a cron schedule; (4) be cautious about optional tools (web_search/Brave API key) — only supply optional API keys if you trust the integration; and (5) request an explicit mapping of required environment variables or tool configurations from the skill author (or refuse installation until those are documented). If the author cannot explain where credentials and persistent state live, treat the skill as untrusted.Like a lobster shell, security has layers — review code before you run it.
aivk973x38xwwefrhcd6qgcws342h81zktwchinesevk973x38xwwefrhcd6qgcws342h81zktwdaily-briefingvk973x38xwwefrhcd6qgcws342h81zktwlatestvk973x38xwwefrhcd6qgcws342h81zktwnewsvk973x38xwwefrhcd6qgcws342h81zktwrssvk973x38xwwefrhcd6qgcws342h81zktw
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
