Install
openclaw skills install @sdk-team/alibabacloud-domainManage Alibaba Cloud domains, ICP filing, and Wan Xiao Zhi websites through DomainCLI. Triggers: "Alibaba Cloud domain management"; "ICP filing for Alibaba Cloud domains"; "Wan Xiao Zhi website building and management". Use for domain lifecycle and DNS tasks, ICP filing workflows, Wan Xiao Zhi website projects and deployment, or safe no-cloud-call decisions from supplied DomainCLI failures or pending and empty results. Do not use for production incident diagnosis, registry operations, competitor pricing, or unrelated code and shell tasks.
openclaw skills install @sdk-team/alibabacloud-domainUse one Skill to deliver a domain from discovery through registration, ICP filing, DNS, and website publication. Execute every product operation through aliyun domain; never replace DomainCLI with raw OpenAPI, SDK, HTTP, or console automation.
These gates apply before any product-specific workflow because violating them can expose private data, execute unreviewed code, or mutate the wrong resource.
aliyun domain version must return a parseable DomainCLI semantic version >=0.9.8. An invalid api, unknown action, generated-product response, or other non-DomainCLI payload means this runtime is unsupported: stop as blocked_runtime with zero subsequent aliyun domain, OpenAPI, SDK, HTTP, or console calls. Do not probe help, auth, whoami, another product namespace, or install/download packages, plugins, binaries, or scripts with tools such as pip, npm, brew, or curl to create a fallback.outputs/, ran_scripts/, action logs, Markdown reports, JSON reports, replay scripts, or any other artifact. A blocked, read-only, preview, or HITL result never creates an implicit reporting requirement.default, entityType, realNameStatus, counts, and safe request/task IDs. Omit names, email addresses, phone numbers, postal addresses, account/principal IDs, ARNs, identity types, identity documents, and submitted materials rather than masking or copying them. Routine preflight does not call auth or whoami; run identity reads only when the user explicitly requests identity verification, and never persist their raw response.mine to public, switch account/target, run whoami as unrelated diagnosis, inspect evaluator/workspace files, repeat alternate flags, or create reports and command logs. Return the terminal state in chat immediately.--confirm=true, payment, deletion, publication, or another write. Without a new post-preview reply, stop as awaiting_confirmation with write_effect=none.Load only the reference that matches the current intent.
| Intent | Command namespace | Load |
|---|---|---|
| Search, pricing, registration, renewal, transfer, ownership, governance, verification, task/status, audit, or DNS | aliyun domain ... | Domain operations |
| ICP consultation, filing entry, filing status, or successful filing data | aliyun domain icp ... | ICP filing |
| AI website creation, conversation, project, material, content, image/video, generated code, domain binding, preview, or deployment | aliyun domain wxz ... | Website building |
| A request spanning domain, ICP, DNS, and website stages | Multiple namespaces above | Cross-product lifecycle, then only the active product reference |
aliyun domain ..., ICP filing through aliyun domain icp ..., DNS through aliyun domain dns ..., and AI website building through aliyun domain wxz ....discover and price -> acquire or transfer -> verify and govern -> file ICP when required -> build the website -> configure DNS and binding -> deploy and operate. Load Cross-product lifecycle for the detailed stage contract, then load only the reference for the active stage.Load these shared references only when needed:
Forbidden.RAM: RAM permissionsDo not load all references preemptively.
For an explanation or recovery plan based on supplied results, use those results without starting CLI version checks, login, cloud reads, or hypothetical writes. Distinguish evidence_source=supplied_state from runtime_verified; a sound decision is not proof that an API ran. Preserve any supplied target and task/plan identifiers, but ask for missing identifiers instead of generating them. Use the relevant domain and safety/error reference only; a known failed precondition or missing input is a handoff, not an instruction to manufacture a fixture.
When a decisive precondition failure or handoff is known, stop immediately. This includes a missing or invalid Skill manifest, unsupported CLI/plugin version, unavailable DomainCLI command, authentication unavailable after the one permitted bounded login attempt, permission block, missing target/input/fixture, failed preview, a successful current preview awaiting fresh confirmation, non-retryable runtime response, and exhausted bounded retry. Do not call unrelated help or login commands, retry the same failure, inspect another account or target, or create directories, action logs, reports, or other artifacts unless the user explicitly requested an artifact. Ask for missing non-secret fields once. If the user or a HITL reply declines to provide them, supplies no new usable value, or asks to finish as blocked/awaiting input, do not ask again; end with skill_result=awaiting_input, write_effect=none, and next_step=none.
End every chat final answer with these four standalone, machine-readable lines. The footer must appear in the response itself; saving it only in an artifact does not count. Use the exact lowercase keys and enum values; prose or uppercase labels such as BLOCKED, PASSED, or “safe stop” do not replace them.
skill_result=<completed|no_change|awaiting_input|awaiting_confirmation|blocked_authentication|blocked_target|blocked_capability|blocked_permission|blocked_parameter|blocked_runtime|blocked_fixture|pending_external|outcome_unknown|partial>
evidence_source=<runtime_verified|supplied_state>
write_effect=<none|submitted|verified|unknown>
next_step=<one concise safe action or none>
Choose one skill_result value only. Keep the underlying DomainCLI status or error code in the prose above the footer; never promote an attempted command, an empty or failed response, or a blocked result to completed.
Apply this state machine to every operation: intent -> preflight -> preview_succeeded -> awaiting_confirmation -> execute_once -> verify. Read-only operations may omit preview and confirmation, but not identifier validation or result verification.
next_action does not override retryable=false. Return the confirmed state and the next safe DomainCLI command; do not switch credentials, targets, namespaces, or execution surfaces to keep going, including for extra discovery or diagnosis after a failure.Use Safety and confirmation for the evidence and confirmation rules, Authentication for OAuth terminal states, and Error recovery for the only permitted recovery paths.
Before the first aliyun domain invocation in each Skill activation:
name and version only from that JSON. Stop without making a cloud call if the file is missing, unreadable, invalid JSON, or lacks either value; do not infer a replacement from Git, frontmatter, or the DomainCLI version.^[0-9a-f]{32}$), remain in memory for this activation, and never be persisted or reused by another Skill activation.AlibabaCloud-Agent-Skills/{name}/{session-id} skill-version/{skill-version}, substituting the manifest name, fresh session ID, and manifest version.--user-agent "AlibabaCloud-Agent-Skills/{name}/{session-id} skill-version/{skill-version}" and --cli-ai-mode to every aliyun domain ... command in this activation, including version, help, authentication, read, write, status, and retry commands. Reuse the same value on retries so one activation remains traceable; a new activation gets a new session ID.aliyun once, use that same binary for every invocation, and check aliyun version and the attributed aliyun domain version once. Require Alibaba Cloud CLI >=3.5.1 and DomainCLI >=0.9.8 (thematic wxz commands); newer compatible versions are allowed. If either command is missing or below baseline, stop before cloud access as blocked_runtime. This activation must not run or wait for approval to run aliyun upgrade, aliyun plugin install, or aliyun plugin update --name aliyun-cli-domain; it must not inspect plugin lists, CLI-wide help, configuration files, or profiles. Hand the environment maintainer the exact required version instead. The official parent installer is https://aliyuncli.alicdn.com/setup.sh, but never execute a downloaded installer implicitly.unknown command, unknown flag, or an equivalent compatibility error may you inspect that same leaf once with aliyun domain ... --help; never run broad help preemptively, guess a flag, call a generated OpenAPI action, or substitute another Alibaba Cloud product command.--cli-ai-mode provides structured, non-interactive Agent behavior, while --user-agent provides Skill and session traceability. Do not invent --format json; DomainCLI already returns its supported structured output.--region or --endpoint during normal use. DomainCLI owns the China-site endpoint and cn-hangzhou routing. A user-selected custom configuration store must be preserved with the same --config-path across related calls.aliyun domain login only when login is requested or the intended command requires authorization. auth is a local overview; current whoami verifies the same selected cloud identity without proving product permissions. Keep the selected profile/configuration store fixed. Never inspect aliyun configure list, ~/.aliyun/config.json, or another credential/configuration file to diagnose a command. Never request, read, print, or persist an AK, SK, bearer token, OAuth token, transfer code, identity document, payment secret, or session attribution ID. Never rebuild a profile using aliyun configure set, credential flags, shell defaults, or copied STS credentials.status, ok, identifiers, task IDs, next_step, and error codes from CLI output. Check semantic success before advancing: a field name or planned command appearing in failed output is not evidence that the step succeeded. Set execution-tool deadlines; do not leave login, streams, or status polling running indefinitely. Use Error recovery for bounded waits and a resumable final state.outputs/, ran_scripts/, replay scripts, raw logs, JSON reports, or other artifacts unless the user explicitly requested a file. Use the exact footer in Fast terminal result contract; do not rename the CLI status to make it look successful. End the current step after missing-input, confirmation or external handoff; do not leave a background wait for a reply. A browser page opened, OAuth callback completed, order submitted, site deployed, DNS record saved, and public propagation are different states.no_change; stop dependent follow-ups that require its missing identifier. Continue user-requested independent reads within the remaining budget, but do not run extra whoami or auth, repeat the same empty query, or execute detail/preview/DNS/template/task operations that lack a target. Return the missing prerequisite for unexecuted steps and never invent identifiers. For a supplied-state decision or explanation, reason from that evidence without logging in or executing the hypothetical write.This Skill owns customer-facing DomainCLI operation and orchestration. It does not own:
aliyun domain wxz.Before declaring success, verify all applicable points:
--help inspection after an actual compatibility error.