📦 Family AI Starter — 全家智能助手
v1.0.0一键把 OpenClaw 变成专属家庭助理:作业辅导、家务打卡、菜谱排期、共享日历与消息提醒全搞定,让全家协作更轻松。
0· 96·0 当前·0 累计
下载技能包
最后更新
2026/3/20
安全扫描
OpenClaw
可疑
medium confidenceNULL
评估建议
This skill coherently implements a family assistant but asks you to provide and store sensitive personal data (medical info, insurance, emergency contacts, IEPs) and to enable proactive behaviors without specifying security controls. Before installing: (1) confirm where workspace files are stored and whether they are encrypted/backed up; (2) decide whether you want to store highly sensitive items in these files — consider redacting or keeping them out of the workspace; (3) require explicit, manu...详细分析 ▾
ℹ 用途与能力
The name and description (homework helper, meal planner, chore tracker, family vault) align with the SKILL.md instructions to create configuration files and sub-skills. However, the 'family vault' and the onboarding interview request sensitive items (medical conditions, insurance, emergency contacts, IEPs). The skill does not declare any secure storage, encryption, or access-control mechanisms for these data, which is a capability/requirements gap for a vault-like feature.
⚠ 指令范围
Runtime instructions explicitly instruct the agent to run an interview that collects highly sensitive personal data (health conditions, insurance, schools, emergency contacts) and then auto-generate local configuration and personality files. The SKILL.md also directs proactive behavior (flagging allergies, sending check-ins). There are no limits, retention rules, or explicit constraints (e.g., 'never transmit externally without explicit consent'), so the instruction scope grants broad discretion to collect, store, and act on sensitive data — potentially beyond what some users expect.
✓ 安装机制
This is an instruction-only skill with no install spec and no code files; nothing is downloaded or executed during install, which minimizes supply-chain risk. The lack of install steps is coherent with the described behavior of generating local files and templates.
ℹ 凭证需求
The skill declares no required environment variables or credentials, yet it asks which communication platform the family uses and promises to act in family chats. If the skill later integrates with Telegram/Discord/other, platform tokens/credentials will be necessary — these are not declared here. Also, although no secrets are requested up front, the skill asks to store sensitive personal data in workspace files without describing access controls, which is a proportionality/privacy concern.
ℹ 持久化与权限
always:false (good). The skill will create persistent files (family-config.json, SOUL-family.md, HEARTBEAT-family.md, USER-template.md) in the workspace and defines sub-skills that 'activate automatically when you need it.' Autonomous invocation is allowed by default — combined with stored sensitive data and proactive messaging behavior this increases risk if users haven't explicitly configured where/how messages are sent or who can access the workspace files.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/3/20
NULL
● 无害
安装命令
点击复制官方npx clawhub@latest install family-ai-starter
镜像加速npx clawhub@latest install family-ai-starter --registry https://cn.longxiaskill.com