安全扫描
OpenClaw
可疑
high confidenceNULL
评估建议
Before installing or using this skill: 1) Note the SKILL.md requires ACEDATACLOUD_API_TOKEN but the package metadata does not declare it — treat that as an inconsistency and only provide a token you control and that is scoped/minimal. 2) The skill targets https://api.acedata.cloud and mentions an optional pip package (mcp-seedream). If you plan to 'pip install' that package, verify its origin (PyPI publisher, source repo, checksum) before installing. 3) The skill has no homepage and the owner ID...详细分析 ▾
ℹ 用途与能力
The SKILL.md describes a Seedream (AceDataCloud) image-generation/editing client and the calls shown (curl to api.acedata.cloud) match that purpose. However, the registry metadata lists no required environment variables while the SKILL.md explicitly says the skill 'Requires ACEDATACLOUD_API_TOKEN' — metadata/manifest inconsistency.
✓ 指令范围
Instructions are scoped to calling AceDataCloud endpoints and to providing an API token. They do not instruct the agent to read unrelated files, system credentials, or to exfiltrate local data. The only extra action is an optional pip install recommendation for 'mcp-seedream'.
ℹ 安装机制
This is an instruction-only skill (no install spec). It suggests 'pip install mcp-seedream' or using a hosted MCP URL; installing that package would install third-party code on the system — vet the package source before installing. No automatic downloads or extract steps are specified by the skill itself.
⚠ 凭证需求
The SKILL.md requires ACEDATACLOUD_API_TOKEN (expected for an API client) but the registry metadata lists no required env vars or primary credential. This mismatch is a red flag: the runtime needs a secret that the metadata does not declare. Ensure you only provide a token scoped to AceDataCloud and understand its permissions and data retention policy.
✓ 持久化与权限
The skill does not request persistent 'always' inclusion, does not declare config paths, and does not attempt to modify other skills or agent-wide settings in the provided instructions.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/3/22
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install acedatacloud-seedream-image
镜像加速npx clawhub@latest install acedatacloud-seedream-image --registry https://cn.longxiaskill.com