agentCLAWHUBUnverified

建站骨架 (EdgeOne Pages)

一句话说需求,AI 生成完整前后端网站并自动部署到 EdgeOne Pages。支持电商栈(Auth/购物车/支付)、AI 栈(SSE 流式对话)、管理后台。 Skill: 建站骨架 (EdgeOne Pages) Owner: liuboacean Summary: 一句话说需求,AI 生成完整前后端网站并自动部署到 EdgeOne Pages。支持电商栈(Auth/购物车/支付)、AI 栈(SSE 流式对话)、管理后台。 Tags: ai-chat:3.2.1, ecommerce:3.2.1, edgeone:3.2.1, edgeone-pages:3.0.6, full-stack:3.0.6, fullstack:3.2.1, latest:3.2.1, saas:3.2.1, web-development:3.0.6, website-scaffold:3.2.1 Version history: v3.2.1 | 2026-05-28T01:57:33.762Z | user v3.2.1: 重新发布以触发ClawScan审核。新增HttpOnly Cookie鉴权(

OpenClaw

Rank

62

Safety

84

Downloads

1.2k

Updated

Oct 11, 2026

Version

3.2.1

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 11, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 11, 2026
Adoption signal
1.2K downloadsadoption · observed Oct 11, 2026
Latest release
3.2.1release · observed May 28, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s1779brgcyhkdmz9tgjpwarx3h84vb82:website-skeleton
  1. Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
  2. Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-liuboacean-website-skeleton/snapshot"

Documentation

CLAWHUB

160,000 characters of source documentation, loaded on request.

Extracted files

5 files captured from the source.

SKILL.md

---
name: 建站骨架 (EdgeOne Pages)
description: 一句话说需求,AI 生成完整前后端网站并自动部署到 EdgeOne Pages。支持电商栈(Auth/购物车/支付)、AI 栈(SSE 流式对话)、管理后台。
version: "3.2.1"
category: openclaw-imports
tags:
  - edgeone
  - website
  - ecommerce
  - deploy
triggers:
  - 帮我建网站
  - 建一个电商网站
  - 做 AI 客服站
  - 建管理后台
  - EdgeOne Pages 建站
  - 搭建网站
  - 做个网站
  - 生成网站
  - 建站
  - 创建网站
  - 我要建站
  - 商城网站
  - 下单支付网站
  - 全栈网站
  - build a website
  - create a full-stack app
  - e-commerce website
  - 建电商
  - 网站骨架
  - 部署网站
env:
  JWT_SECRET:
    description: JWT 签名密钥(HS256),Edge + Cloud 共享
    required: true
    secret: true
  AI_API_KEY:
    description: AI 模型调用 API Key(仅 AI 栈需要)
    required: false
    secret: true
  WX_APPID:
    description: 微信支付 AppID(仅电商栈需要)
    required: false
    secret: true
  WX_MCHID:
    description: 微信支付商户号(仅电商栈需要)
    required: false
    secret: true
  DATABASE_URL:
    description: D1 数据库绑定
    required: false
    secret: true
---

# 建站 Skill — EdgeOne Pages 全栈网站骨架

> **版本:** 3.2.0 · **日期:** 2026-05-26 · **工程完缮(SPA详情页 + 227项测试 + 迁移/脚本/模板联动)**
> **一句话描述:** 用户说一句话,AI 生成完整前后端网站,自动部署到 EdgeOne Pages。

---

## 一、核心设计理念

```
一次设计,无限复用 = 5 个模块 × 3 个场景 × 1 个部署平台
```

将"建站"拆解为 **Layer 0 基础设施** + **Layer 1 能力栈** + **Layer 2 可选增强**:

| 层级 | 内容 | 性质 |
|------|------|------|
| **Layer 0**(Core) | SPA 骨架 + Auth + Middleware + EventBus | 必选,不可裁剪 |
| **Layer 1**(Stack) | 🛒 电商栈 · 🤖 AI 栈 · 📊 管理栈 | 按需组合,互不依赖 |
| **Layer 2**(Addon) | SEO · Analytics · i18n | 可选增强 |

**场景模板优先**:用户选"电商"、"AI 助手"或"管理后台"场景,不选模块——模块由模板自动组合。

---

## 二、技术架构

### 2.1 EdgeOne Pages 双运行时

```
┌──────────────────────────────────────────────────────────────┐
│  Platform Middleware(middleware.js)                        │
│  ① CORS 预检(OPTIONS)                                     │
│  ② CSP Header 注入                                          │
│  ③ 轻量 Bearer 检查(公开路径放行)                           │
│  ④ 支付回调 IP 白名单 → 直接 return,不进 Edge Middleware     │
└──────────────────────────────────────────────────────────────┘
                              ↓(非回调路径)
┌──────────────────────────────────────────────────────────────┐
│  Edge Functions Middleware(V8 + KV)                      │
│  ⑤ JWT 详细校验(crypto.subtle)                             │
│  ⑥ KV session 验证                                          │
│  ⑦ KV 限流计数器(滑动窗口)                                   │
└──────────────────────────────────────────────────────────────┘
```

### 2.2 运行时职责边界

| 运行时 | 存储 | 职责 | 说明 |
|--------|------|------|------|
| **Edge Functions**(V8) | KV | Auth 登录/me、Products 公开读、Cart、Orders 读、AI History 读、幂等锁 | 延迟敏感、无密钥 |
| **Cloud Functions**(Node) | D1 | Auth 注册/bcrypt、Payment 创建/回调、Admin CRUD、Orders 创建/取消、AI SSE 流 | 密钥操作、复杂事务 |

> ⚠️ **平台约束(EdgeOne Pages):**
> - KV 仅 Edge Functions 可用,Cloud Functions 无法访问
> - Cloud Functions 目录名必须为 `cloud-functions/`
> - bcrypt 必须在 Cloud Functions 中执行

### 2.3 分层目录结构

```
website-skeleton/
├── SKILL.md                    # 本文件,Skill 核心指令
│
├── templates/                  # 场景预设模板
│   ├── e-commerce.json         # 🛒

README.md

<p align="center">
  <img src="https://img.shields.io/badge/version-v3.2.0-blue?style=flat-square" alt="version">
  <img src="https://img.shields.io/badge/EdgeOne_Pages-ready-brightgreen?style=flat-square" alt="EdgeOne Pages">
  <img src="https://img.shields.io/badge/license-MIT_No_Attribution-green?style=flat-square" alt="license">
  <img src="https://img.shields.io/badge/status-stable-brightgreen?style=flat-square" alt="status">
  <img src="https://img.shields.io/badge/Phase_5_工程完缮-%E2%9C%85-success?style=flat-square" alt="Phase 5">
  <a href="https://website-skeleton-demo-8mv8fitk.edgeone.cool?eo_token=587119f1f48590b7dded3b65f6001030&eo_time=1779867268"><img src="https://img.shields.io/badge/demo-live-purple?style=flat-square" alt="Demo"></a>
</p>

# Website Skeleton Skill

> **One sentence to build a full-stack website.** Generate auth, payments, AI chat, and admin panel — deploy to EdgeOne Pages.

[English](#english) · [中文](#chinese) · [Demo](https://website-skeleton-demo-8mv8fitk.edgeone.cool?eo_token=587119f1f48590b7dded3b65f6001030&eo_time=1779867268)

---

## English

**website-skeleton-skill** is an EdgeOne Pages skill that scaffolds full-stack websites from a single prompt. It combines 5 reusable modules (Auth, Cart, Payment, AI Chat, Admin) across 3 scene templates (E-commerce, AI Assistant, SaaS Admin).

### Quick Start

```bash
npm install -g edgeone
edgeone login --site china
edgeone pages deploy -n my-site
```


### Features

| Feature | Status | Description |
|---------|--------|-------------|
| 🔐 Auth | ✅ | JWT dual-track (RS256 + HS256), bcrypt, KV Session, RT rotation |
| 🛒 Cart & Payment | ✅ | WeChat/Alipay, Edge idempotency lock, multi-tenant KV cart |
| 🤖 AI Chat | ✅ | SSE streaming via Cloud Functions, KV history, rate-limited |
| 📊 Admin Panel | ✅ | RBAC (superadmin/tenant_admin/user), CRUD, stats, audit logs |
| 🏢 Multi-tenant | ✅ | Phase 4A: {tenant} forced SQL, KV prefix isolation, quotas |
| 📦 npm Packages | ✅ | Phase 4B: @website-skeleton/{shared,payment,admin} |
| 🌍 i18n | ✅ | Chinese + English, extensible |
| 🔍 SEO | ✅ | JSON-LD structured data, meta tags |
| 📈 Analytics | ✅ | KV-based event tracking, opt-out support |

### Demo

[Live Demo →](https://website-skeleton-demo-8mv8fitk.edgeone.cool?eo_token=587119f1f48590b7dded3b65f6001030&eo_time=1779867268)

Deploy your own with a single command: `edgeone pages deploy -n my-site`

---

## Chinese

# website-skeleton-skill

> 一句话描述需求 → AI 生成完整前后端网站 → 自动部署到 EdgeOne Pages 全球 CDN。

**版本:** v3.2.0 · **Phase 5(工程完缮)已全部完成**

---

## 目录

- [一、快速开始](#一快速开始)
- [二、架构](#二架构)
- [三、功能特性](#三功能特性)
- [四、Phase 4 变更概要](#四phase-4-变更概要)
- [五、目录结构](#五目录结构)
- [六、安全设计](#六安全设计)
- [七、评审历程](#七评审历程)
- [八、版本历史](#八版本历史)
- [九、License](#九license)

---

## 一、快速开始

```bash
# 1. 安装 EdgeOne CLI
npm install -g edgeone

# 2. 登录
edgeone login --site china

# 3. 部署(交互式引导)
edgeone pages deploy -n my-site

# 4. 按提示选择场景模板、填写配置、执行数据库迁移
```

### 场景模板

| 模板 | 适用场景 | 包含模块 | 快速命令 |
|------|---------|----

_meta.json

{
  "ownerId": "kn73qbrbqs4s8t2nh8pm22wxbd84vm7r",
  "slug": "website-skeleton",
  "version": "3.2.1",
  "publishedAt": 1779933453762
}

references/admin-module.md

# Admin 管理后台模块参考文档

> **版本:** v2.2 · **Phase:** Layer 1(管理栈)
> **职责:** RBAC 权限体系、商品/订单/用户 CRUD、运营统计、审计日志

---

## 一、RBAC 权限体系

### 角色定义

```javascript
// sharing/constants.js
export const UserRole = {
  USER:   'user',     // 普通用户:下单、查看自己的订单
  ADMIN:  'admin',    // 管理员:全站 CRUD
  MANAGER:'manager',  // 运营:订单管理、商品上下架
};
```

### 权限矩阵

| 操作 | user(本人) | manager | admin |
|------|------------|---------|-------|
| 查看自己的订单 | ✅ | ✅ | ✅ |
| 管理任意订单 | ❌ | ✅ | ✅ |
| 商品上架/下架 | ❌ | ✅ | ✅ |
| 修改商品价格 | ❌ | ❌ | ✅ |
| 用户管理 | ❌ | ❌ | ✅ |
| 查看运营统计 | ❌ | ✅ | ✅ |
| 审计日志 | ❌ | ❌ | ✅ |
| 系统设置 | ❌ | ❌ | ✅ |

---

## 二、Admin Guard 中间件

```javascript
// cloud-functions/utils/admin-guard.js

/**
 * 验证管理员权限
 * @param {Request} request
 * @param {Object} env
 * @param {string[]} allowedRoles - 允许的角色,如 ['admin', 'manager']
 * @returns {{ userId, role } | Response} 成功返回用户信息,失败返回 Response
 */
export async function adminGuard(request, env, allowedRoles = ['admin']) {
  const authHeader = request.headers.get('Authorization') || '';
  const token = authHeader.startsWith('Bearer ') ? authHeader.slice(7) : null;

  if (!token) {
    return new Response(JSON.stringify({ error: 'Unauthorized' }), { status: 401 });
  }

  const payload = await verifyJWT(token, env);
  if (!payload) {
    return new Response(JSON.stringify({ error: 'Invalid token' }), { status: 401 });
  }

  if (!allowedRoles.includes(payload.role)) {
    return new Response(JSON.stringify({ error: 'Forbidden: insufficient permissions' }), { status: 403 });
  }

  return { userId: payload.sub, role: payload.role };
}
```

---

## 三、商品管理 CRUD

### 3.1 列表查询(支持分页 + 筛选)

```javascript
// cloud-functions/api/admin/products.js

export async function onRequest(request, env) {
  // Admin Guard
  const auth = await adminGuard(request, env);
  if (auth instanceof Response) return auth;

  const url = new URL(request.url);
  const page = Math.max(1, parseInt(url.searchParams.get('page') || '1'));
  const pageSize = Math.min(100, parseInt(url.searchParams.get('pageSize') || '20'));
  const offset = (page - 1) * pageSize;
  const category = url.searchParams.get('category');
  const status = url.searchParams.get('status'); // active / inactive
  const keyword = url.searchParams.get('keyword');

  const pool = new Pool({ connectionString: env.DATABASE_URL });

  // WHERE 条件构建
  const conditions = [];
  const params = [];
  if (category) { conditions.push('category_id = ?'); params.push(category); }
  if (status) { conditions.push('status = ?'); params.push(status); }
  if (keyword) { conditions.push('name LIKE ?'); params.push(`%${keyword}%`); }
  const where = conditions.length ? `WHERE ${conditions.join(' AND ')}` : '';

  const whereClause = where || 'WHERE 1=1';

  const [rows] = await pool.query(
    `SELECT id, name, category_id, price, stock, status, version, created_at
     FROM products ${whereClause}
     ORDER BY id DESC
     LIMIT ? OFFSET ?`,
    [...params, pageSize, offset]
  );

  const [[{ total }]] = await pool.que

references/ai-chat-module.md

# AI Chat 模块参考文档

## 一、架构选择

**Edge Function 限制:**
- 200ms **CPU time** 限制(不是 wall clock time)
- `fetch()` 到外部 AI API 的 I/O 等待**不计入** CPU time
- **无 `waitUntil`**:异步写 KV 无法保证在响应发送前完成

**结论:** 流式 SSE 主力实现在 **Cloud Functions**,历史读取在 **Edge Functions**。

## 二、SSE 实现方案 B(前端中转历史)

```
前端
  ↓ GET /api/ai/history(Edge,KV 读取)
  ← 拿到 history JSON

  ↓ 建立 SSE 连接 /api/ai/chat-stream(Cloud)
  ← 带 history context 参数

Cloud SSE 流式响应
  ↓ 完成后异步写 KV(不阻塞响应)
```

```javascript
// Cloud Function: cloud-functions/api/ai/chat-stream.js
export async function onRequest(request, env) {
  const { userId } = await auth(request, env);
  const url = new URL(request.url);
  const historyParam = url.searchParams.get('history');
  const history = historyParam ? JSON.parse(historyParam) : [];

  const stream = new ReadableStream({
    async start(controller) {
      const encoder = new TextEncoder();

      async function sendEvent(type, data) {
        controller.enqueue(encoder.encode(`event: ${type}\ndata: ${JSON.stringify(data)}\n\n`));
      }

      try {
        await sendEvent('status', { status: 'thinking' });

        const response = await fetch('https://api.example.com/chat', {
          method: 'POST',
          headers: {
            'Authorization': `Bearer ${env.AI_API_KEY}`,
            'Content-Type': 'application/json',
          },
          body: JSON.stringify({ messages: history, stream: true }),
        });

        const reader = response.body.getReader();
        const decoder = new TextDecoder();

        while (true) {
          const { done, value } = await reader.read();
          if (done) break;
          const chunk = decoder.decode(value);
          await sendEvent('message', { content: chunk });
        }

        await sendEvent('done', {});

      } catch (err) {
        await sendEvent('error', { message: err.message });
      } finally {
        controller.close();
      }
    }
  });

  return new Response(stream, {
    headers: {
      'Content-Type': 'text/event-stream',
      'Cache-Control': 'no-cache',
      'Connection': 'keep-alive',
    }
  });
}
```

## 三、前端 SSE 客户端

```javascript
// client/src/services/ai.js
import { EventBus } from '../utils/event-bus.js';

class AIService {
  constructor() {
    this.es = null;
  }

  async startChatSession() {
    // Step 1: 从 Edge KV 拿历史
    const history = await fetch('/api/ai/history').then(r => r.json());

    // Step 2: 建立 SSE,带历史 context
    this.es = new EventSource(`/api/ai/chat-stream?history=${encodeURIComponent(JSON.stringify(history))}`);

    this.es.addEventListener('message', (e) => {
      const data = JSON.parse(e.data);
      EventBus.emit('ai:message', { role: 'assistant', content: data.content });
    });

    this.es.addEventListener('status', (e) => {
      EventBus.emit('ai:status', JSON.parse(e.data));
    });

    this.es.addEventListener('done', () => {
      EventBus.emit('ai:status', { status: 'idle' });
    });

    this.es.addEventListener('error', (e) => {
      
Github ReposUpdated 1d agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/liuboacean/skills/website-skeleton",
      "sourceUrl": "https://clawhub.ai/liuboacean/skills/website-skeleton",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T05:08:28.270Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-liuboacean-website-skeleton/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-liuboacean-website-skeleton/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-11T05:08:28.270Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "1.2K downloads",
      "href": "https://clawhub.ai/liuboacean/website-skeleton",
      "sourceUrl": "https://clawhub.ai/liuboacean/website-skeleton",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-11T05:08:28.270Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "3.2.1",
      "href": "https://clawhub.ai/liuboacean/website-skeleton",
      "sourceUrl": "https://clawhub.ai/liuboacean/website-skeleton",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-28T01:57:33.762Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-liuboacean-website-skeleton/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-liuboacean-website-skeleton/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 3.2.1",
      "description": "v3.2.1: 重新发布以触发ClawScan审核。新增HttpOnly Cookie鉴权(防XSS)、Edge API统一错误处理、服务端价格校验、227项测试。无代码变更。",
      "href": "https://clawhub.ai/liuboacean/website-skeleton",
      "sourceUrl": "https://clawhub.ai/liuboacean/website-skeleton",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-05-28T01:57:33.762Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 11, 2026.

Sponsored

Ads related to 建站骨架 (EdgeOne Pages) and adjacent AI workflows.