1Password CLIの導入と認証を確認し、保存したパスワードやAPIキーをコマンドや設定へ渡します。デスクトップ連携やサービスアカウントにも対応します。
- 1Password CLIを導入したいとき
- APIキーをコマンドに渡したいとき
- CIでサービスアカウント認証を使う
OpenClawの脆弱性報告を、公開済みのバージョンと信頼範囲の根拠で確認し、終了・継続・影響の絞り込みを判断して、管理者向けの返信案をまとめます。
原文Triage OpenClaw security advisories, drafts, and GHSA reports with shipped-tag and trust-model proof.
インストール方法を見るOpenClawの脆弱性報告やGitHubのセキュリティ勧告であるGHSAを確認し、終了するか、継続するか、影響範囲を絞って継続するかを判断します。SECURITY.md、該当コード、公開済みのタグやnpmリリース、既存の報告を照合し、根拠を添えた管理者向け返信案を作ります。
開発中のmainでは修正済みでも、公開版への反映を確かめたいときに便利です。報告が重複しているか、信頼する利用者や構成要素の範囲を越える問題かを整理したい場合にも向いています。脆弱性の判定と、任意の安全性向上策を分けて検討します。
確認にはgh、Git、npmと、対象の報告・コードを読む権限が必要です。原文のクリップボード操作にはpbcopyを使います。通常は一件ずつ返信案を作り、人による投稿や議論を待ちます。公開文面では修正コミットや実装の詳細を避け、修正済みリリースを示す方針です。
この紹介文は、公開されている SKILL.md をもとに AI(Claude Haiku)が作成しました。正確な仕様は下の原文を確認してください。
インストールする前に、エージェントに与えられる指示の中身を確認できます。
Use when reviewing OpenClaw security advisories, drafts, or GHSA reports.
Goal: high-confidence maintainers' triage without over-closing real issues or shipping unnecessary regressions.
Close only if one of these is true:
SECURITY.mdDo not close only because main is fixed. If latest shipped tag or npm release is affected, keep it open until released or published with the right status.
Before answering:
SECURITY.md.gh api /repos/openclaw/openclaw/security-advisories/<GHSA>.git tag --sort=-creatordate | headnpm view openclaw version --userconfig "$(mktemp)"git tag --contains <fix-commit>git show <tag>:path/to/fileSECURITY.mdFor each advisory, decide:
closekeep openkeep open but narrowDefault to one advisory at a time when comments/closures are involved:
Do not batch multiple close comments unless Peter explicitly asks for a batch.
Check in this order:
SECURITY.md explicitly call this class out as out of scope or hardening-only?SECURITY.md, do not treat "injection markers" alone as a security bug.When preparing a maintainer-ready close reply:
Keep tone firm, specific, non-defensive.
SECURITY.md boundary, and say clearly that the GHSA will close without publication.### Patched Versions with the fixed release. Do not explain how the patch works unless Peter explicitly asks for that public detail.When Peter is manually posting GHSA comments, use this flow:
close, keep open, or keep open but narrow).pbcopy.If the GitHub API cannot post comments for private advisories, say so once and keep using clipboard/UI paste.
After drafting the final post body for the current advisory, copy it:
pbcopy <<'EOF'
<final response>
EOF
Tell the user that the clipboard now contains the proposed response for that advisory.
gh api /repos/openclaw/openclaw/security-advisories/<GHSA>
gh api /repos/openclaw/openclaw/security-advisories --paginate
git tag --sort=-creatordate | head -n 20
npm view openclaw version --userconfig "$(mktemp)"
git tag --contains <commit>
git show <tag>:<path>
gh search issues --repo openclaw/openclaw --match title,body,comments -- "<terms>"
gh search prs --repo openclaw/openclaw --match title,body,comments -- "<terms>"
For permitted defensive work interrupted by a cyber classifier, use an approved, available Daybreak Blue route only for that bounded task, then restore the previous model. Preserve the approved identity, scope, permissions, sandbox, and review gates. Never switch models to bypass access denials, disallowed requests, or refused tool actions; if that route also refuses, stop and report. Follow OpenAI's guidance for approved model access.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
1Password CLIの導入と認証を確認し、保存したパスワードやAPIキーをコマンドや設定へ渡します。デスクトップ連携やサービスアカウントにも対応します。
OpenClawへの自然な言葉の依頼をClaude Codeなどの外部コーディングエージェントへ振り分け、作業の開始や継続、スレッド内の会話をつなぐスキルです。
Add and live-prove a model provider with non-interactive config one-liners, without exposing credentials.
日本語の概要は準備中です。原文の説明を表示しています。
Requested GitHub PR/issue agent transcripts: redact, trim, preview, and insert safely.
日本語の概要は準備中です。原文の説明を表示しています。
macOSのApple Notesをエージェントから作成・検索・編集・削除し、フォルダ間の移動やHTML・Markdownへの書き出しを行うスキル。
Apple Remindersの予定付きToDoをMacから確認・追加・編集するスキル。リストの管理や完了・削除にも対応し、iPhoneやiPadで見るタスクを整理できます。