中国农历黄历吉凶 · Zhongguo Nongli Huangli Jixiong · China Lunar Almanac
v1.3.1中国农历黄历吉凶 · Zhongguo Nongli Huangli Jixiong · China Lunar Almanac (Auspicious & Inauspicious). Keywords / 关键词: 中国农历, 黄历, 老黄历, 农历查询, 吉凶, 吉日, 宜忌, 择日, 搬家吉日, 结婚吉日...
⭐ 1· 158·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description match the included files and behavior: toolkit.py implements by-date/batch/search against api.nongli.skill.4glz.com, and auth.py provides a CLI device auth flow. Required environment variable HUANGLI_TOKEN is directly related to the stated purpose.
Instruction Scope
SKILL.md and the scripts only direct API calls to api.nongli.skill.4glz.com, local CLI usage, and optional environment variables. The auth flow explicitly prints exports and states it does not write shell profiles or token files by default. No instructions ask the agent to read unrelated system files or send data to unexpected endpoints.
Install Mechanism
There is no install spec (instruction-only) and the included Python scripts use standard library urllib; no external downloads, package installs, or archive extraction are performed by the skill. SKILL.md mentions cloning the GitHub repo for manual installation, which is a normal instruction but not an automated install step.
Credentials
Only HUANGLI_TOKEN (required) and an optional HUANGLI_BASE are declared. auth.py accepts optional helper env vars (HUANGLI_USERNAME/EMAIL/PASSWORD) for CLI convenience; these are reasonable for a CLI auth helper. No unrelated secrets or cloud credentials are requested.
Persistence & Privilege
Skill does not request always: true and does not modify other skills or system-wide settings. The scripts explicitly avoid writing token files or modifying shell profiles by default; persistence is left to the user via their secret manager or manual export.
Assessment
This skill appears to do what it claims: query a Huangli API with a HUANGLI_TOKEN. Before installing or using it, verify you trust the API host (https://api.nongli.skill.4glz.com) and the publisher (repository/homepage links). Keep your HUANGLI_TOKEN secret — anyone with it could access your account/dashboard. The CLI prints shell export commands (which will display the token in your terminal) and does not persist tokens automatically; store tokens in your secret manager if needed. Because the skill performs outbound network calls, review network policies if you are in a restricted environment. If you need stronger assurance, inspect the referenced GitHub repository and confirm the API behavior and token scopes on the service dashboard.Like a lobster shell, security has layers — review code before you run it.
latestvk974gyzz992sbxa785m5m74x8x84qa6v
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
