Extract and summarize public QQ app pages, announcements, and group invites without login or message access.
⭐ 0· 267·0 current·0 all-time
byClawKK@codekungfu
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
medium confidencePurpose & Capability
Name/description (extract/summarize public QQ pages, announcements, group invites) match the SKILL.md content. The skill only targets public pages and explicitly disclaims login/message access, which aligns with the declared purpose.
Instruction Scope
SKILL.md instructs fetching public share pages, extracting title/author/time/body/tags, and waiting for dynamic rendering. It does not ask the agent to read unrelated files or environment variables and warns about frequency control. However, it relies on the ability to render dynamic content (e.g., a headless browser) but does not state or require any specific runtime capabilities or binaries — this is an operational omission rather than a malicious instruction.
Install Mechanism
Instruction-only skill with no install spec, packages, or external downloads. This is low-risk; nothing is written to disk by the skill itself.
Credentials
The skill requires no environment variables, credentials, or config paths. That is proportionate for a scraper of public pages. There are no unrelated credentials requested.
Persistence & Privilege
The skill does not request always:true or any elevated persistent privileges. Default autonomous invocation is allowed (platform default) and is not by itself a concern here.
Assessment
This skill appears coherent for scraping and summarizing public QQ pages, but check these operational points before installing:
- Runtime rendering: SKILL.md says content is dynamically loaded and requires waiting for rendering. Ensure your agent environment provides an HTML renderer/headless browser (e.g., Puppeteer/Playwright or a browser tool). The skill does not declare this dependency.
- Rate limits & robots: Implement rate-limiting and respect QQ's robots/terms of service to avoid blocking or legal issues. The SKILL.md mentions frequency control but does not enforce it.
- Data handling: The skill can extract page content. Decide where scraped data will be stored or transmitted and ensure sensitive or private data are not collected or leaked. The skill gives no guidance about downstream storage or external endpoints.
- Verify compliance: Confirm that summarizing and storing public announcements or invite pages is allowed under QQ's terms and applicable law in your jurisdiction.
No code files or regex scan findings were present — behavior will depend entirely on how your agent implements web fetching/rendering. If you need the skill to run in your environment, consider adding explicit runtime requirements (browser binary, timeouts, proxy settings) and conservative rate limits.Like a lobster shell, security has layers — review code before you run it.
latestvk975e4kww2ckjjk5qgnc89pqkd831w0h
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
