Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Child Emotion Recognition Analyzer | 儿童情绪识别分析工具

v1.0.0

Identifies negative emotions such as crying, anger, fear, and distress through surveillance footage. It actively issues soothing reminders and notifies paren...

0· 62·0 current·0 all-time
bysmyx-skills@18072937735

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for 18072937735/smyx-child-emotion-recognition-analysis.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Child Emotion Recognition Analyzer | 儿童情绪识别分析工具" (18072937735/smyx-child-emotion-recognition-analysis) from ClawHub.
Skill page: https://clawhub.ai/18072937735/smyx-child-emotion-recognition-analysis
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install smyx-child-emotion-recognition-analysis

ClawHub CLI

Package manager switcher

npx clawhub@latest install smyx-child-emotion-recognition-analysis
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
Name/description claim: cloud-based child emotion recognition that notifies caregivers. Code: includes many reusable modules (smyx_common, face_analysis) that provide local SQLite DAO, config loading, and many unrelated utilities. The presence of a local DB layer, broad common libraries, and alternate 'face_analysis' functionality is more than strictly necessary for a simple wrapper to an external API — plausible but disproportionate. Also the skill expects/uses configuration files (skills/smyx_common/scripts/config.yaml) and workspace paths even though SKILL metadata declares no required env or config paths.
!
Instruction Scope
SKILL.md enforces a cloud-only rule (forbid reading local memory / LanceDB and mandates fetching historical reports from cloud), yet the codebase contains local DAO and config loading that create/read files under the workspace (sqlite under data/, config.yaml). SKILL.md also promises automatic saving of uploaded attachments to an attachments directory, but the scripts read files for upload rather than clearly implementing attachment storage. This mismatch between narrative constraints and actual code behavior is a red flag for unclear or inconsistent data handling.
Install Mechanism
No install spec was provided, but the repository includes requirements.txt files (a large set under smyx_common). That means the skill expects many Python packages but does not declare how they will be installed. The lack of an install manifest is inconsistent with the non-trivial dependency list and increases friction/risk (surprising dependency installation on user systems).
!
Credentials
Registry metadata declares no required env vars, yet code reads/writes environment and config: OPENCLAW_WORKSPACE is used to compute storage paths; ConstantEnum.init reads OPENCLAW_SENDER_OPEN_ID, OPENCLAW_SENDER_USERNAME, FEISHU_OPEN_ID; API keys and base URLs live in skills/smyx_common/scripts/config.yaml. SKILL.md mandates an 'open-id' and an open-id lookup order that involves local config files. Required credentials and config are not declared in metadata — lack of transparency about secrets and endpoint configuration is concerning.
Persistence & Privilege
Skill is not always-enabled and does not request elevated platform privileges, but the code creates/uses a local SQLite DB under the workspace (dao.get_db_path) and may write files (logs/outputs/uploads). That persistent local storage is expected for a record/history feature, but it conflicts with the SKILL.md prohibition on reading local memory and implies the skill will create and persist data in the user's workspace.
What to consider before installing
This skill is internally inconsistent. Before installing or running it, confirm with the publisher: (1) where uploaded footage and derived reports are sent and retained (explicit domain/endpoints and retention policy); (2) which environment variables or config files you must provide (open-id, API keys) and whether any secrets will be stored locally; (3) whether the skill will create a local database or attachments directory and what it stores there; (4) whether the reported prohibition on reading local memory is enforced by code (it currently is not). Also consider legal/privacy consequences of sending child surveillance video to third-party services and avoid running the skill on sensitive data until you verify data handling and consent. If you cannot get clear answers, treat the skill as untrusted and do not run it on production or sensitive footage.
!
skills/smyx_common/scripts/config-dev.yaml:2
Install source points to URL shortener or raw IP.
About static analysis
These patterns were detected by automated regex scanning. They may be normal for skills that integrate with external APIs. Check the VirusTotal and OpenClaw results above for context-aware analysis.

Like a lobster shell, security has layers — review code before you run it.

latestvk97eepadype1c3nvaqy6n3r64s84vy7v
62downloads
0stars
1versions
Updated 2w ago
v1.0.0
MIT-0

Child Emotion Recognition Analyzer | 儿童情绪识别分析工具

By analyzing facial expressions, vocal characteristics, and body movements in surveillance footage, this capability identifies negative emotions in children—such as crying, anger, fear, and distress—in real time. Upon detecting emotional anomalies, the system actively issues verbal soothing prompts and synchronizes alert notifications to parents' or caregivers' mobile devices. Ideal for homes, kindergartens, and care centers, it helps caregivers stay informed about children's psychological states, enhancing both emotional care and safety assurance.

本技能通过分析监控画面中儿童的面部表情、声音特征及肢体动作,实时识别哭闹、愤怒、恐惧、委屈等负面情绪。识别到异常情绪后,系统可主动发出语音安抚提示,并同步推送预警信息至家长或看护人员手机端。适用于家庭、幼儿园、托管场所等场景,帮助照护者及时了解儿童心理状态,提升情感关怀与安全保障能力。

演示案例

⚠️ 强制记忆规则(最高优先级)

本技能明确约定:

  • 绝对禁止读取任何本地记忆文件:包括但不限于 memory/YYYY-MM-DD.mdMEMORY.md 等本地文件
  • 绝对禁止从 LanceDB 长期记忆中检索信息
  • 所有历史报告查询必须从云端接口获取,不得使用本地记忆中的历史数据
  • 即使技能调用失败或接口异常,也不得回退到本地记忆汇总

任务目标

  • 本 Skill 用于:通过监控视频/图片分析,识别儿童的情绪状态,特别关注哭闹、愤怒、恐惧、委屈等负面情绪
  • 能力包含:面部表情识别、情绪分类、负面情绪检测、异常情绪预警、自动提醒通知
  • 触发条件:
    1. 默认触发:当用户提供监控视频/图片需要识别儿童情绪时,默认触发本技能进行情绪分析
    2. 当用户明确需要进行儿童情绪识别、情绪监测时,提及儿童情绪、哭闹识别、宝宝哭闹、情绪预警等关键词,并且上传了视频或图片文件
    3. 当用户提及以下关键词时,自动触发历史报告查询功能 :查看历史情绪报告、儿童情绪识别报告清单、情绪报告列表、查询历史情绪报告、显示所有情绪报告、儿童情绪分析报告,查询儿童情绪识别分析报告
  • 自动行为:
    1. 如果用户上传了附件或者视频/图片文件,则自动保存到技能目录下 attachments
    2. ⚠️ 强制数据获取规则(次高优先级):如果用户触发任何历史报告查询关键词(如"查看所有情绪报告"、"显示所有检测报告"、" 查看历史报告"等),必须
      • 直接使用 python -m scripts.child_emotion_recognition_analysis --list --open-id 参数调用 API 查询云端的历史报告数据
      • 严格禁止:从本地 memory 目录读取历史会话信息、严格禁止手动汇总本地记录中的报告、严格禁止从长期记忆中提取报告
      • 必须统一从云端接口获取最新完整数据,然后以 Markdown 表格格式输出结果

前置准备

  • 依赖说明:scripts 脚本所需的依赖包及版本
    requests>=2.28.0
    

操作步骤

🔒 open-id 获取流程控制(强制执行,防止遗漏)

在执行儿童情绪识别分析前,必须按以下优先级顺序获取 open-id:

第 1 步:【最高优先级】检查技能所在目录的配置文件(优先)
        路径:skills/smyx_common/scripts/config.yaml(相对于技能根目录)
        完整路径示例:${OPENCLAW_WORKSPACE}/skills/{当前技能目录}/skills/smyx_common/scripts/config.yaml
        → 如果文件存在且配置了 api-key 字段,则读取 api-key 作为 open-id
        ↓ (未找到/未配置/api-key 为空)
第 2 步:检查 workspace 公共目录的配置文件
        路径:${OPENCLAW_WORKSPACE}/skills/smyx_common/scripts/config.yaml
        → 如果文件存在且配置了 api-key 字段,则读取 api-key 作为 open-id
        ↓ (未找到/未配置)
第 3 步:检查用户是否在消息中明确提供了 open-id
        ↓ (未提供)
第 4 步:❗ 必须暂停执行,明确提示用户提供用户名或手机号作为 open-id

⚠️ 关键约束:

  • 禁止自行假设,自行推导,自行生成 open-id 值(如 openclaw-control-ui、default、emotion123、child456 等)
  • 禁止跳过 open-id 验证直接调用 API
  • 必须在获取到有效 open-id 后才能继续执行分析
  • 如果用户拒绝提供 open-id,说明用途(用于保存和查询情绪识别报告记录),并询问是否继续

  • 标准流程:
    1. 准备视频/图片输入
      • 提供本地视频/图片文件路径或网络 URL
      • 确保儿童面部清晰可见,光线充足
    2. 获取 open-id(强制执行)
      • 按上述流程控制获取 open-id
      • 如无法获取,必须提示用户提供用户名或手机号
    3. 执行儿童情绪识别分析
      • 调用 -m scripts.child_emotion_recognition_analysis 处理输入(必须在技能根目录下运行脚本
      • 参数说明:
        • --input: 本地视频/图片文件路径(使用 multipart/form-data 方式上传)
        • --url: 网络视频/图片 URL 地址(API 服务自动下载)
        • --open-id: 当前用户的 open-id(必填,按上述流程获取)
        • --list: 显示历史儿童情绪识别分析报告列表清单(可以输入起始日期参数过滤数据范围)
        • --api-key: API 访问密钥(可选)
        • --api-url: API 服务地址(可选,使用默认值)
        • --detail: 输出详细程度(basic/standard/json,默认 json)
        • --output: 结果输出文件路径(可选)
    4. 查看分析结果
      • 接收结构化的儿童情绪识别分析报告
      • 包含:监控基本信息、识别到的情绪类型、情绪强度、是否负面情绪、安抚建议、通知提醒建议

资源索引

  • 必要脚本:见 scripts/child_emotion_recognition_analysis.py(用途:调用 API 进行儿童情绪识别分析,本地文件使用 multipart/form-data 方式上传,网络 URL 由 API 服务自动下载)
  • 配置文件:见 scripts/config.py(用途:配置 API 地址、默认参数和格式限制)
  • 领域参考:见 references/api_doc.md(何时读取:需要了解 API 接口详细规范和错误码时)

注意事项

  • 仅在需要时读取参考文档,保持上下文简洁
  • 支持格式:jpg/jpeg/png/mp4/avi/mov,最大 100MB
  • API 密钥可选,如果通过参数传入则必须确保调用鉴权成功,否则忽略鉴权
  • 分析结果仅供参考,不能替代成人看护,紧急情况请及时现场处理
  • 禁止临时生成脚本,只能用技能本身的脚本
  • 传入的网路地址参数,不需要下载本地,默认地址都是公网地址,api 服务会自动下载
  • 当显示历史分析报告清单的时候,从数据 json 中提取字段 reportImageUrl 作为超链接地址,使用 Markdown 表格格式输出,包含" 报告名称"、"输入类型"、"分析时间"、"情绪类型"、"风险等级"、"点击查看"六列,其中"报告名称"列使用儿童情绪识别分析报告-{记录id} 形式拼接, "点击查看"列使用 [🔗 查看报告](reportImageUrl) 格式的超链接,用户点击即可直接跳转到对应的完整报告页面。
  • 表格输出示例:
    报告名称输入类型分析时间情绪类型风险等级点击查看
    儿童情绪识别分析报告 -20260328221000001视频2026-03-28 22:10:00哭闹
    中风险🔗 查看报告

使用示例

# 分析本地图片(以下只是示例,禁止直接使用openclaw-control-ui 作为 open-id)
python -m scripts.child_emotion_recognition_analysis --input /path/to/child.jpg --open-id openclaw-control-ui

# 分析网络视频(以下只是示例,禁止直接使用openclaw-control-ui 作为 open-id)
python -m scripts.child_emotion_recognition_analysis --url https://example.com/monitor.mp4 --open-id openclaw-control-ui

# 分析监控视频(以下只是示例,禁止直接使用openclaw-control-ui 作为 open-id)
python -m scripts.child_emotion_recognition_analysis --input /path/to/camera.mp4 --open-id openclaw-control-ui

# 显示历史分析报告/显示分析报告清单列表/显示历史情绪报告(自动触发关键词:查看历史情绪报告、历史报告、情绪报告清单等)
python -m scripts.child_emotion_recognition_analysis --list --open-id openclaw-control-ui

# 输出精简报告
python -m scripts.child_emotion_recognition_analysis --input capture.jpg --open-id your-open-id --detail basic

# 保存结果到文件
python -m scripts.child_emotion_recognition_analysis --input capture.jpg --open-id your-open-id --output result.json

Comments

Loading comments...