Whispers from the Star CN
v1.0.0星之低语 - 科幻生存冒险游戏。玩家扮演 Stella Chen,一位坠落在陌生星球的宇航员,需要在盖亚星球上探索、生存、解谜,寻找回家之路。支持多场景探索、资源管理、外星生物互动。适用于科幻冒险、生存模拟、互动叙事等场景。
⭐ 5· 1.6k·2 current·2 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The skill's name/description (a sci‑fi survival/interactive narrative) matches the files and runtime instructions. It requires no credentials, binaries, or unusual system access, which is proportionate for an instruction-only story/game skill.
Instruction Scope
SKILL.md and the references direct the agent to read and use local reference files (references/*.md) to drive scenes and choices. There are no instructions to read unrelated system files, environment variables, or to call external endpoints, nor any vague 'gather whatever context you need' language that would grant broad discretion.
Install Mechanism
No install spec or code files are present — this lowers disk/write/execute risk. The skill is instruction-only and will not download or extract code at install time.
Credentials
The skill declares no required environment variables, credentials, or config paths. The content does not attempt to access secrets or unrelated services; requested permissions are minimal/none.
Persistence & Privilege
always is false and there is no action that would modify other skills or system-wide agent settings. The skill does not request permanent presence or elevated privileges.
Assessment
Technical risk: very low — this skill is instruction-only and only references local markdown files, so it does not request credentials, install packages, or contact external endpoints. However, consider these non-security things before installing: 1) Source provenance: the skill's source/homepage are unknown — if you need a trustworthy author or license (e.g., for commercial use or redistribution), ask the publisher for attribution and licensing. 2) Content review: review the narrative content for any sensitive, copyrighted, or policy‑relevant material you don't want in your workspace. 3) Autonomous invocation: the skill may be invoked by an agent (disable-model-invocation is false by default). Although this skill has no elevated privileges, confirm your agent's behavior policy if you don't want automated runs. 4) Test in a sandbox: because the registry metadata shows an unknown owner and no homepage, try it in a non-production/sandbox agent first to confirm behavior and to inspect outputs. Overall: low security risk but check author/license and confirm you’re comfortable with an unverified content source.Like a lobster shell, security has layers — review code before you run it.
latestvk97c4e89hzsxjwd1b2v8ej6a3n800vbf
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
