yoooclaw-hotspot-topic-scout

ReviewAudited by ClawScan on May 14, 2026.

Overview

This skill is coherent for topic scouting, but it deserves review because it can read broad phone notifications and group/team messages and use those private signals in external web searches.

Review this skill before installing. It is not shown to be malicious and its behavior matches its topic-scouting purpose, but you should only use it if you are comfortable letting it read selected notifications and possibly use private discussion topics in web searches. Configure narrow source allowlists and avoid including personal chats, authentication codes, confidential team channels, or sensitive client/customer messages.

Publisher note

Scan your group chats, app notifications, and the web to surface trending topics and content ideas tailored to your niche.

Findings (3)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may read a broad set of notifications, including unrelated personal or sensitive messages, before filtering them for topic ideas.

Why it was flagged

The skill instructs the agent to execute a notification-search command scoped only by time, with no app/group/source filter in the command itself.

Skill content
command: openclaw ntf search --from 开始时间 --to 结束时间
Recommendation

Require explicit user confirmation and narrow the command by allowed apps, groups, and time range before reading notifications.

What this means

Installing or invoking the skill may expose private notifications, team discussions, and fan messages to the agent’s context.

Why it was flagged

The skill relies on access to private app notifications and potentially work/group communication, which is sensitive account or workspace-adjacent data.

Skill content
内部信号:用户手机上的消息通知(内容平台推送、行业群聊、团队讨论、粉丝反馈)
Recommendation

Use only with clearly limited notification permissions and an allowlist of sources; avoid granting access to personal chats, OTPs, private family messages, or unrelated workspaces.

What this means

Sensitive topics from private group chats, team discussions, or fan feedback could be sent to an external search provider as search queries.

Why it was flagged

The workflow can turn internal notification-derived topics into external web-search queries, but it does not define sanitization or approval boundaries for private terms.

Skill content
基于内部信号和用户配置,使用 `byted-web-search`(火山引擎联网搜索)补充外部热点。... 如果内部信号中出现了高频话题但信息不完整,针对该话题补搜
Recommendation

Before external searches, summarize or redact private notification content and ask the user before sending any internal or non-public topic to a web-search provider.