Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
xinwencaiji
v1.0.0Run a self-contained Chinese and international AI news workflow inside the current workspace. Use when the user wants either high-frequency RSS capture only...
⭐ 0· 98·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The skill's code and SKILL.md align with the stated purpose: collecting RSS/Atom feeds, deduplicating, producing cumulative Excel files and a Word brief, and optionally calling an AI model for titles/summaries. However, the registry metadata did not declare the external model credential (ARK_API_KEY) or model base (ARK_API_BASE) even though SKILL.md and scripts require them; this mismatch is unexpected and should be corrected.
Instruction Scope
Runtime instructions are narrowly scoped to the workspace (config, data, reports, state) and to running the bundled Python scripts. The scripts fetch arbitrary RSS/Atom URLs from user-provided config files and will POST content to an external model API for AI summarization. That behavior is coherent with the skill's purpose but means collected article text (and any credentials present in feed configs) will be transmitted externally.
Install Mechanism
There is no install spec in the registry (instruction-only). The bundled scripts list Python dependencies (openpyxl, python-docx) to be installed via pip — a low-risk, typical approach. No arbitrary binary downloads or obscure installers are present.
Credentials
The SKILL.md and scripts require ARK_API_KEY (and allow ARK_MODEL / ARK_API_BASE overrides) to call an external model service. The registry's required-env list is empty, which is inconsistent. Requesting an API key for the external model is proportionate to the AI-summary functionality, but the missing declaration and the default ARK_API_BASE (https://ark.cn-beijing.volces.com/api/v3) require you to verify the endpoint and trust the operator before supplying credentials.
Persistence & Privilege
The skill does not request always:true and does not modify other skills or system-wide settings. It writes state, logs, caches, reports, and snapshots into the workspace (data/, reports/, state/, logs/), which is normal for this type of tool.
What to consider before installing
This skill appears to do what it says (fetch RSS feeds, build Excel/Word reports, and optionally call an external model for summaries). Before installing or running it, consider the following:
- The scripts will send collected article content to an external model endpoint using ARK_API_KEY / ARK_API_BASE. The registry metadata did not list these required env vars — verify the skill author and the endpoint before providing keys.
- Default ARK_API_BASE points to an external service (https://ark.cn-beijing.volces.com). Confirm this is a trusted API and that your ARK_API_KEY is scoped appropriately. If you do not want outbound data sent, run with --disable-ai or omit ARK_API_KEY.
- Feed configs can include authentication (username/password or custom headers). Those credentials may be used by the feed fetcher and stored under workspace state/logs; keep sensitive feeds out of the same workspace or review how credentials are provided.
- The skill will create and write files/directories (data/, reports/, state/, logs/, snapshots/) in the chosen workspace. Back up or isolate any existing data you care about.
- The package source is unknown and has no homepage; if you intend to run it in a production or sensitive environment, review the full script contents (they are bundled) and verify the model endpoint and data handling behavior.
If you trust the code and endpoint: set ARK_API_KEY (and ARK_API_BASE/ARK_MODEL if needed), run dependency installation in an isolated environment, and consider running with --disable-ai first to validate data ingestion without external network calls.Like a lobster shell, security has layers — review code before you run it.
latestvk973dk0a4109q02pep3fjvpked833vqn
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
