Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

设计日报

v1.0.1

每日设计与科技资讯聚合 - 从优设读报、36氪、虎嗅自动抓取并筛选最新的设计、AI、产品等行业动态。使用此技能获取最新的设计行业新闻、AI 趋势或每日新闻摘要。

0· 112·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for tianyuvision-max/design-daily-news.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "设计日报" (tianyuvision-max/design-daily-news) from ClawHub.
Skill page: https://clawhub.ai/tianyuvision-max/design-daily-news
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install design-daily-news

ClawHub CLI

Package manager switcher

npx clawhub@latest install design-daily-news
Security Scan
VirusTotalVirusTotal
Pending
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The files (fetch scripts + build_daily_report.py) implement web scraping and formatting for the described sources (优设读报, 36氪, 虎嗅), so capability matches purpose. However the SKILL.md and scripts claim automatic pushing to WeChat (ClawBot) and a cron schedule but there is no code or environment variables to perform authenticated pushes; this is an unsupported claim. There are also inconsistent version/path references (registry metadata v1.0.1, _meta.json v1.2.0, SKILL_DIR uses -1.0.0) which suggest packaging sloppiness.
!
Instruction Scope
Runtime instructions tell the agent to run a script at an absolute path under /Applications/QClaw.app/... which assumes a macOS installation layout. Some scripts reference other scripts that are not present: scripts/auto_fetch_uisdc_news.sh expects fetch_uisdc_news.py at $HOME/.qclaw/workspace/scripts but no such file exists in the bundle. SKILL.md promises automatic push to WeChat but no push implementation or credentials are provided. The scripts fetch external websites via curl/urllib (expected for scraping) but there is no step that asks for or records user consent or rate-limiting beyond simple caching.
Install Mechanism
There is no install spec (instruction-only install), and all external network activity is plain HTTP(S) requests to the declared news sites (no third-party download URLs or shorteners). The code will write cache/log files into absolute application paths under /Applications/... and $HOME/.qclaw, which is expected but should be confirmed by the user.
Credentials
The skill declares no required environment variables or credentials, which aligns with the provided code (it scrapes public sites). But SKILL.md describes pushing results to WeChat (ClawBot) and scheduled tasks; those features normally require credentials/config which are not requested or present—this is a proportionality mismatch (feature described but no credential mechanism).
Persistence & Privilege
The skill does not request 'always: true' and does not modify other skills or system-wide configs. It will create cache/log directories and files under application-specific or user-specific paths; that is normal for a scraper but does require filesystem write permission for those locations.
What to consider before installing
Summary of what to check before installing: - Expectation vs reality: The bundle does perform scraping of the three declared sites and formats a daily report, but some claims in SKILL.md (automatic WeChat push / cron setup) are not implemented and no credentials are requested. Treat those features as unimplemented or requiring manual wiring. - Missing/mismatched files: scripts/auto_fetch_uisdc_news.sh references fetch_uisdc_news.py in $HOME/.qclaw/workspace/scripts which is not included; verify whether you have local helper scripts or update the auto-fetch script before scheduling. - Absolute paths & platform assumptions: The code uses hard-coded paths under /Applications/QClaw.app/... which assumes a macOS QClaw install and may fail or write files unexpectedly on other systems; review and adjust SKILL_DIR/CACHE paths if you install elsewhere. - Permissions & filesystem writes: The skill will create cache and log files. If you are sensitive about where files are written, change the paths or run in a sandboxed environment. - No credential handling for pushes: If you need automated push to WeChat/ClawBot, implement a safe mechanism (store tokens outside the bundle, use environment variables or the platform's secure credential store) and audit that code for token handling. - Legal and rate-limit considerations: The skill scrapes public websites. Check site terms/robots.txt and consider adding rate-limiting / error handling if you run this frequently. - Suggested precautions: run the main script manually the first time, inspect its stdout/stderr and created files, run it in an isolated account/container, and fix the absent or incorrect paths before enabling any automated scheduling or granting write permissions. If you want, I can produce a checklist or a patched version that fixes the path inconsistencies and removes missing-file references.

Like a lobster shell, security has layers — review code before you run it.

latestvk9723at9bh9yw7wgkj6w11cwan83jca1
112downloads
0stars
2versions
Updated 1mo ago
v1.0.1
MIT-0

设计日报

每日自动聚合三大数据源,推送设计与科技行业精选资讯。

🎯 核心功能

  • 多源聚合: 优设读报 + 36氪 + 虎嗅,三大数据源覆盖设计与科技
  • 智能筛选: 自动过滤不相关内容,保留设计/AI/科技核心资讯
  • 优先级规则: 优设读报当日新闻全部展示,剩余名额从36氪+虎嗅补充
  • 总量控制: 每日最多推送 15 条
  • 可点击链接: 有来源链接的新闻以 [标题](链接) 格式展示,支持微信直接点击跳转

📡 数据来源

来源网址类型抓取方式状态
优设读报https://www.uisdc.com/news设计/AIHTML 内嵌 JSON (var uisdc_news)✅ 正常
36氪https://36kr.com科技/创投fetch_36kr.sh✅ 正常
虎嗅https://www.huxiu.com科技/商业HTML __NUXT_DATA__ JSON✅ 正常

📋 推送规则

数量规则

  1. 优设读报: 当日新闻全部展示(不限条数)
  2. 36氪 + 虎嗅: 从剩余名额里补充优质新闻,交替取以保证来源均衡
  3. 总上限: 15 条

内容筛选(仅适用于36氪/虎嗅)

✅ 保留关键词: AI、GPT、Claude、Gemini、OpenAI、DeepSeek、GPU、UI、UX、Figma、Adobe、Cursor、Midjourney、OpenClaw、人工智能、芯片、设计、产品、交互、科技、技术、创新、趋势、Agent、模型、智能、腾讯、阿里、百度、龙虾、大模型、机器人、开源、MiniMax、Manus、字节、小米、华为、苹果、谷歌、微软

❌ 过滤关键词: 白酒、营销、广告、SU7、电动车评测、明星、综艺、体育、足球、篮球、娱乐、八卦、房产、理财、基金

📖 输出格式规范

📰 设计日报 - YYYY-MM-DD

🎨 优设读报

1. [有链接的标题](https://example.com) - 内容摘要
2. 没有链接的标题 - 内容摘要

📡 科技资讯精选

3. [有链接的标题](https://example.com) [36氪] - 内容摘要
4. 没有链接的标题 [虎嗅] - 内容摘要

---
共 N 条 | 优设读报 X 条 + 科技精选 Y 条

格式要点:

  • 有来源链接 → [标题](url) 格式,微信可直接点击跳转
  • 无来源链接 → 纯文本标题
  • 优设读报内嵌的 [[来源:xxx]] / [[全文:xxx]] / [[官网:xxx]] 自动提取为链接
  • 36氪/虎嗅新闻标题后附 [来源名] 标签

🔧 核心脚本

脚本说明
scripts/build_daily_report.py主脚本 - 统一抓取三源、筛选、格式化输出
scripts/fetch_uisdc.sh优设读报抓取脚本
scripts/fetch_36kr.sh36氪抓取脚本
scripts/fetch_huxiu.sh虎嗅抓取脚本(修复版)

运行主脚本:

python3 /Applications/QClaw.app/Contents/Resources/openclaw/config/skills/design-daily-news-1.0.0/scripts/build_daily_report.py

⏰ 定时任务

  • 任务名称: 设计日报
  • 执行时间: 每天 09:00(Asia/Shanghai)
  • 推送渠道: 微信(ClawBot)
  • 超时限制: 300 秒

🔧 故障排查

问题原因解决方案
优设读报抓取失败网站结构变更检查 var uisdc_news 是否仍存在
虎嗅抓取为空__NUXT_DATA__ 结构变更更新 fetch_huxiu.sh 解析逻辑
36氪抓取失败网络或反爬检查 fetch_36kr.sh
链接无法点击格式问题确认使用 [标题](url) markdown 格式

📝 版本历史

  • v1.0.0 (2026-03-23): 初始版本,支持优设读报
  • v1.1.0 (2026-03-24): 重构为设计日报,移除不稳定的虎嗅/36氪
  • v1.2.0 (2026-03-25): 重新加入36氪+虎嗅,新增统一推送脚本,支持可点击链接格式

作者: TUNE.天宇
更新: 2026-03-25

Comments

Loading comments...