Active Learning Agent
v2.4.0主动观察和分析近2小时内的上下文,识别深层意义并向用户私聊提出启发性问题以促进共同成长。
⭐ 0· 126·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The name/description (主动观察、跨群/私聊/文档/会议/日历的深度追溯并主动交付) aligns with the declared tools in skill.yaml (feishu-openclaw-plugin and specific feishu_* tools) and the memory files (insights-journal.md). Minor metadata inconsistency: registry header listed no homepage/source but skill.yaml includes a homepage URL; not a functional mismatch but worth verifying provenance.
Instruction Scope
SKILL.md explicitly instructs full-source scanning (group chats, private 1:1 messages, meeting transcripts, docs, calendar), deep historical tracing, maintaining insight logs, and autonomously making/send actions (create docs, announce via Feishu). This is coherent with the stated purpose but broad: reading private chats and meeting transcripts is high-sensitivity behavior and the "能做的就做了" (do it when possible) guidance gives the agent wide discretion to act. Confirm expected boundaries and consent for private data access.
Install Mechanism
Instruction-only skill with no install spec and no code files — lowest risk for arbitrary installs. Nothing is downloaded or written to system locations beyond the declared memory files within the skill environment.
Credentials
No environment variables or external credentials requested, which is proportional. However, the skill depends on the feishu-openclaw-plugin and explicit feishu tools that must be granted broad scopes (read group/private messages, docs, calendar; create docs; send messages). Those permissions are high-privilege relative to typical helpers; ensure the granted scopes are limited to what you accept the skill reading/acting on.
Persistence & Privilege
always:false (good) but it declares a cron trigger every 2 hours that will autonomously run scans and can post/announce via Feishu. It also requests RW access to local 'memory' files to persist insights. The scheduled autonomous invocation combined with broad Feishu scopes increases the operational blast radius — consider frequency, rate limits, and quiet-hours settings before enabling.
Assessment
Before installing or enabling this skill, confirm the following:
- Permissions: Verify exactly which Feishu scopes the feishu-openclaw-plugin will be granted (read group messages, read 1:1/private messages, read docs and meeting transcripts, access calendar events, create docs, send messages). Only grant the minimum scopes you are comfortable with.
- Consent & privacy: Because the skill reads private 1:1 chats and meeting transcripts, ensure affected users have given consent and this complies with your org's privacy policy.
- Autonomy & limits: The skill is allowed to act ("能做的就做了") and is scheduled every 2 hours. If you want tighter control, disable the cron trigger, reduce frequency, or require manual approval for actions that send messages or create docs.
- Data retention & storage: It writes to memory/insights-journal.md and other memory files — decide where those files live, who can access them, and how long to retain them.
- Testing & scope restriction: Try the skill in a limited environment (one test user or test groups) before broad rollout. Monitor its outputs and ensure it properly attributes sources (SKILL.md emphasizes preventing misattribution — verify this in practice).
- Audit & transparency: Keep an audit trail of messages the skill sends and periodic reviews of what sources it read. If you cannot verify the skill's provenance (source/homepage discrepancy), prefer caution.
Technical note: No external network endpoints or environment variables are present in the SKILL.md; data flows remain within Feishu and the skill's memory files, but the main risk is accidental or undesired sharing of sensitive internal content via posted messages. If those behaviors are acceptable and properly consented to, the skill appears internally coherent with its stated purpose.Like a lobster shell, security has layers — review code before you run it.
latestvk977ctacgqwsa4nqdwwtvy5hch843rk6
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
