ZeroToken
Token-efficient, safe agent execution Skill: ZeroToken Owner: phoenixlucky Summary: Token-efficient, safe agent execution Tags: agent-discipline:1.6.0, latest:1.17.0, token-efficient:1.6.0, zerotoken:1.6.0 Version history: v1.17.0 | 2026-09-20T07:34:38.599Z | user 安全:移除未受信任桥脚本探测与执行(修复审计 T07)并补充第三方数据外发提示;audit_encoding 移除 .env 避免误报;收窄 SKILL.md 自动触发条件;fix_encoding 无 --backup 时告警 v1.16.0 | 2026-09-20T05:42:26.932Z | user 新增站内锚点与脚本引用审计;回归测试自动发现;README 瘦身 45%
Rank
62
Safety
84
Downloads
2.4k
Updated
Oct 9, 2026
Version
1.17.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.4K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.4K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.17.0release · observed Sep 20, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17705e3p3j221cp70a66wbscd844f38:zerotoken-skill- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-phoenixlucky-zerotoken-skill/snapshot"
Documentation
CLAWHUB
155,430 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: zerotoken-skill
version: 1.17.0
description: Token-efficient assistant discipline for concise, direct answers and minimal-context task execution. Use only when the user explicitly requests low-token / direct output (e.g. says「省 token」「直接给结果」) or invokes this skill by name; includes optional file-encoding and Windows PowerShell utilities (single entry: `python scripts/zt.py help`).
metadata:
security:
capabilities:
- filesystem-read: "read local files"
- filesystem-write: "write/modify local files"
- batch-edit: "apply multiple text replacements to a single file"
- encoding-conversion: "batch file encoding detection and conversion"
- gbk-contamination-detection: "detect and repair GBK-contaminated UTF-8 files"
- git-operations: "git config and commit operations"
permissions-declared: true
language: "回答语言跟随用户交互语言(用中文问就中文答);文档正文为 zh-CN"
platforms: "auto-detects OS at session start (detect_env.py): Windows/PowerShell -> Mode F, Linux/macOS -> Mode G"
references: "细节按需读取 references/*.md(Windows 陷阱 / 重构手册 / 搜索规范 / 发布手册 / 工具映射)"
---
# ZeroToken Skill
> **语言**:回答语言跟随用户交互语言——用中文问就用中文答,用英文问就用英文答
> (语言可自选;本文件正文用 zh-CN 只是默认,不强制)。
> 平台环境由 `python scripts/detect_env.py` 自动识别,不需要用户声明语言或平台。
> *(Answer in the user's language; environment detection is automatic.)*
用最少必要 token 和最精准提示词完成任务。省 token ≠ 偷工减料;核心是减少无效上下文、无效解释、无效工具调用、无效输出。
> **🛡️ 能力与安全披露**(安装前请确认符合你的安全策略)
> 除提示词纪律外,本 Skill 还声明这些文件系统能力:
> 读取/修改本地文件(`read_file`/`edit_file`/`write_file`);批量替换与编码转换
> (`scripts/batch_edit.py`、`fix_encoding.py`);安全读写与追加(`scripts/safe_io.py`,
> 规避 `Add-Content` 的 GBK 污染);GBK 污染检测修复(`scripts/detect_gbk_contamination.py`);
> Git 配置(`scripts/init_env.ps1` 只改**当前仓库 local 配置**,不动全局);
> 环境探测结果写 `.zerotoken/environment.json`(7 天有效期,已 gitignore)。
---
## 📐 快速决策表
| 用户请求特征 | 模式 | 首轮输出 | 工具偏好 |
|---|---|---|---|
| 问定义/翻译/短建议 | **A. 简单问答** | 1-5 句直接回答 | 直接输出,不跑工具 |
| 单文件修复/配置调整 | **B. 代码小改** | 改动 + 验证结果 | `grep` → `read_file`(局部) → `edit_file` |
| 跨模块功能/常规重构/CI | **C. 多文件任务** | 3-5 步短计划 | `glob` → `grep` → 分批 `read_file` |
| 长文/日志/PR/文档总结 | **D. 大资料总结** | 要点 + 证据位置 | `read_file`(head+tail) → `grep`(关键行) |
| 反复出同类 bug / 加功能越来越难 / 架构与需求不匹配 | **E. 重大重构/架构调整** | 问题诊断 + 目标方案 + 迁移路线图 | `explore` → 分批 `read_file`(详见 [`references/refactor-playbook.md`](references/refactor-playbook.md)) |
| 用户明确说"省 token" | **ZeroToken 强化** | 最短可执行输出 | 同上,但跳过所有非必要探索 |
| 用户说"详细解释/教学" | **➡ 退出 ZeroToken** | 常规详尽模式 | 不限 |
| 系统是 Windows/PowerShell(detect_env.py 自动识别) | **F. Windows/PowerShell 环境适配** | 系统参数已保存,按陷阱规则调整工作流 | 详见 [`references/windows-powershell.md`](references/windows-powershell.md) |
| 系统是 Linux/macOS(detect_env.py 自动识别) | **G. POSIX 标准工作流** | 按 POSIX 规则工作,禁用 PowerShell 语法 | 常规 shell 工具链(sh/bash/zsh) |
> 工具名以当前宿主实际提供的为准;名字不同时见 [`references/tool-mapping.md`](references/tool-mapping.md)。
---
## 🧭 核心原则
1. **先分类,再预算** — 按上表决定上下文深度,不默认全量读取。
2. **压缩提示词** — 目标 + 已知输入 + 约束 + 验收格式;只在缺失项会改变结果时追问。
3. **渐进读取** — 先定位(`grep`/`glob`),再局部读,读完即停README.md
<div align="center"> # ⚡ ZeroToken Skill **让 Agent 用最少的 token 做最准的事** > ⚔️ **先谋后动,军无二令 —— 省 token 是效率,尉缭子是秩序。** > > 💬 **用不完,根本用不完,妈妈再也不用担心我缺 token 了。** []() [](LICENSE) []() [](https://github.com/phoenixlucky/zerotoken-skill/actions/workflows/ci.yml) </div> > **ZeroToken Skill** 是一套为 AI Agent 设计的**提示词纪律规范**——在不降低回答准确性的前提下,压缩无效上下文、无效解释、无效工具调用和无效输出。 > > 它解决的核心问题是:Agent 在任务中经常过度读取、过度思考、过度输出,导致一次对话消耗成千上万不必要的 token。本 Skill 通过一套可执行的**模式决策表 + 行为约束 + 工具链策略**,让 Agent 在每一个任务环节都有明确的"省 token 行为准则"。 > > 🎯 **目标:** 用最精准的提示,做最少的往返,产最精炼的结果。 > > ✅ **适用于:** Reasonix / Codex CLI / OpenCode / Hermes / Cline 等主流 Agent 工具。一次学习,全平台受益。 <div align="center"> <img src="assets/zerotoken-banner.webp" alt="ZeroToken Skill 概览" width="480"> </div> --- ## 目录 - [安装](#-安装) - [能力一览](#-能力一览) - [任务模式速查](#-任务模式速查) - [平台集成](#-平台集成) - [文档地图](#-文档地图) - [延伸阅读](#-延伸阅读) - [核心原则(一句话版)](#-核心原则一句话版) - [Agent 预设](#-agent-预设) - [The King Skills](#-the-king-skills) --- ## 🔌 安装 | 方式 | 操作 | |------|------| | **AI 助手安装(推荐)** | 直接对助手说:`安装这个技能 https://github.com/phoenixlucky/zerotoken-skill`(或 ClawHub 源 `https://clawhub.ai/phoenixlucky/zerotoken-skill`) | | **远程 Skill 仓库引用** | `install-source --source https://github.com/phoenixlucky/zerotoken-skill`(或 `--source https://clawhub.ai/phoenixlucky/zerotoken-skill`) | | **手动载入** | 克隆仓库,将本目录作为 Skill 载入,入口为 [`SKILL.md`](SKILL.md) | > 📦 分发双端:GitHub(源码)+ ClawHub(发布包)。详见 [`references/publishing-clawhub.md`](references/publishing-clawhub.md)(仅维护者)。 --- ## 📋 能力一览 根据请求特征与系统环境,ZeroToken Skill 自动匹配**七种任务模式**。每种模式都有专属的**工具链**、**输出格式**和 **token 预算策略**: | 模式 | 一句话概括 | Token 成本 | |------|-----------|:----------:| | **A. 💬 简单问答** | 直接回答,不跑工具 | 🔵 极低 | | **B. 🔧 代码小改** | 定位 → 读 → 精准改 → 最小验证 | 🟢 低 | | **C. 📦 多文件任务** | 短计划 → 分批加载 → 按步推进 | 🟡 中 | | **D. 📚 大资料总结** | 要点 + 证据位置,不逐段复述 | 🟠 中高 | | **E. 🏗️ 重大架构调整** | 诊断根因 → 确认方案 → 增量迁移 | 🔴 高(但可控) | | **F. 🖥️ Windows/PowerShell 环境适配** | 系统参数自动识别保存 + 15 条陷阱规则 + 脚本工具,Windows 系统自动启用 | 🟢 低 | | **G. 🐧 POSIX 标准工作流** | Linux/macOS 自动启用:sh/bash 工具链,不套用 PowerShell 规则 | 🔵 极低 | > 平台环境由 `python scripts/detect_env.py` 自动识别(`SKILL.md` 中的 F/G 模式),无需用户声明语言或平台。 --- ## 🧩 任务模式速查 | 模式 | 典型信号 | 行为要点 | 不做什么 | |------|---------|---------|---------| | **A. 简单问答** | 定义查询、翻译、短建议 | 从已加载上下文/内置知识提取,1-3 句直接回答 | ❌ 不搜索代码库 ❌ 不加客套话 | | **B. 代码小改** | 单文件 bug、配置调整、重命名 | grep 定位 → 只读命中行附近 → 精准改 → 最小验证 | ❌ 不写长计划 ❌ 不重构无关代码 | | **C. 多文件任务** | 新增功能、常规重构、接口变更 | 3-5 步短计划,一次加载 2-3 个文件,改一批验一批 | ❌ 不一次性加载所有文件 ❌ 不超 5 步 | | **D. 大资料总结** | 长文档、日志、PR 差异 | 只标记关键信息,输出「要点 + 证据位置」 | ❌ 不逐段复述 ❌ 不加无关评语 | | **E. 重大架构调整** | 反复同类 bug、架构不匹配 | **唯一必须先确认方案再执行**:诊断根因 → 2-3 方案 → 增量迁移 | ❌ 不跳过影响面评估 ❌ 不做不可逆大改 | | **F. Windows/PowerShell** | `detect_env.py` 报 Windows | 按保存的系统参数选
_meta.json
{
"ownerId": "kn7dpzpqn086by5pfg5sbf64zx80zr6m",
"slug": "zerotoken-skill",
"version": "1.17.0",
"publishedAt": 1789889678599
}references/publishing-clawhub.md
# ClawHub 发布(skill 分发与同步)
> 本文是**维护者手册**——使用者无需阅读。
> 项目通过 ClawHub 分发:<https://clawhub.ai/phoenixlucky/zerotoken-skill>。
> 以下规则来自实测发布过程,发布任何版本时必须遵守。
## 关键事实
- ❗ **ClawHub 不是 Git 端点** — 仓库远程 `clawhub` 只是发布页地址,
`git fetch/push clawhub` 必然 404(`repository not found`)。**发布必须走 clawhub CLI**,
不能指望 git push。
- 发布 CLI 由 pnpm 全局安装:`%LOCALAPPDATA%\pnpm\clawhub.CMD`
(PowerShell `PATH` 未包含 pnpm 目录时直接调 `clawhub` 会「无法识别」,需用全路径)。
- 登录状态用 `clawhub whoami` 验证(应输出 `phoenixlucky`)。
- 新版本提交后 ClawHub 会跑**安全扫描**(异步、分钟级),**提交成功 ≠ 立即可见**。
- 发布包内容以**发布时的工作区文件**为准:GitHub 提交 ≠ ClawHub 包同步。
打包范围由 `package.json` 的 `files` 字段声明(改目录结构时必须同步核对)。
## 发布陷阱表(C 系,与 F 模式 #1-15 区分)
| # | 陷阱 | 症状 | 解决方案 |
|---|------|------|----------|
| C1 | **PowerShell `curl` 是别名** | `curl -s -o NUL https://...` 报「缺少参数 SessionVariable」 | PS 里 `curl` = `Invoke-WebRequest`(参数不兼容);探测网络/API 一律用 **`curl.exe`** |
| C2 | **`clawhub publish` 相对路径解析错误** | `publish .` 报 `Error: SKILL.md required` | CLI 默认 `--dir skills`(相对 workdir),相对路径找不到根目录 SKILL.md;✅ 传**绝对路径** |
| C3 | **发布命令长时零输出** | 前台发布跑 2 分钟无输出被超时终止,ClawHub 无变化 | 上传 registry 需 5-6 分钟且**全程零输出**(易误判卡死);✅ 用后台运行(`run_in_background`)+ 轮询等待 |
| C4 | **安全扫描异步** | 发布提交成功(`Update submitted ... pending security scans before it becomes public`)但 registry/页面仍是旧版本号 | 平台规则:扫描通过才公开;✅ 用 `clawhub inspect phoenixlucky/zerotoken-skill --json` 或页面 `og:image` 复查,看到新版本号即已公开 |
| C5 | **发布前工作区有未提交改动** | 工作区脏时发布,未提交改动**已随包上传 ClawHub** 但 GitHub 缺失,两端分叉 | ✅ 发布前先 `git status` 确认干净(或先提交)再发布;发布后复查 `git status` |
| C6 | **带 source 参数触发上传 ticket 失效** | `publish ... --source-repo ... --source-commit <sha>` 报 `Skill upload ticket is missing, used, or expired`(连续重试 + 等冷却无效) | 实测:**去掉 `--source-repo` / `--source-commit` 重试即成功**;source 元数据可发布后通过页面/GitHub 关联,不影响打包内容 |
## 推荐发布时序(每次发布固定流程)
```text
0. git status 确认工作区干净;git log 记录待发布版本号
1. 一键校验:python scripts/zt.py check
(回归测试 + 编码审计 + 文档一致性 + 版本号三处联动;与 CI 同一条命令)
2. git push origin main(GitHub 先行)
3. clawhub publish <仓库绝对路径> --slug zerotoken-skill --owner phoenixlucky \
--version <新版本> --changelog "<变更摘要>" --no-input
—— 先加 --dry-run 预览(应输出 Would publish <slug>@<version>),
确认无误后移除 --dry-run 再次执行,并放后台运行(陷阱 C3)
4. clawhub inspect phoenixlucky/zerotoken-skill 复查公开状态(异步,陷阱 C4)
```
> 版本号用 `python scripts/zt.py version <x.y.z>` 写入三处;`zt.py check` 与 CI 跑同一套校验。references/refactor-playbook.md
# E 模式参考:重大重构 / 架构调整 > **触发信号**(满足任意一条即可进入此模式): > - 同一模块反复修同一个类型的 bug,修了又犯 > - 加一个小功能需要改 5+ 个文件,牵一发动全身 > - 现有架构无法合理支持新需求,强行扩展会导致更深的 technical debt > - 测试覆盖率低、或测试需要大量 mock 才能跑,说明耦合度过高 > - 代码逻辑纠缠不清,修改的「实际影响面」远超「预期影响面」 > > 这是唯一**必须先确认方案再执行**的模式;其他模式识别即执行。 ## 流程 1. **诊断根因,不治症状** — 先用跨文件探索工具(`explore`,或宿主提供的代码图工具)了解问题模块的全景(入口、调用链、数据流),定位系统性根源而非表面 bug。 产出:根因陈述(1-2 句话)。 2. **评估影响面** — 摸清依赖关系:哪些模块依赖问题代码、哪些测试会受影响、是否有外部调用者。 产出:影响模块清单 + 风险等级。 3. **设计方案 & 用户确认** — 输出 2-3 个候选方案的对比(每个含:核心思路、改动量、风险、迁移难度), 用 `ask` 让用户选择,**不要替用户做架构决策**。确认后再进入执行阶段。 4. **制定增量迁移计划** — 将重构拆为可独立验证的小步,每步满足: - 可回滚(不破坏已有功能) - 可通过编译 + 已有测试 - 新旧代码可共存过渡(strangler fig / feature flag / 适配层) 产出:`todo_write` 任务清单(顶层步骤,不含子 bullet)。 5. **安全执行,每步验证** — 按计划逐步执行,每步后: - `lsp_diagnostics` 检查编译(宿主提供时) - 运行相关测试 - 更新 `todo_write` 状态 发现计划外的依赖时暂停,补评估再继续。不得跳过验证走捷径。 6. **清理收尾** — 删除废弃代码(不留「为了兼容以前」的旧实现,见总纲 #6)、移除过渡兼容层、 更新文档 / README / AGENTS.md。最后跑一次完整测试套件。 ## 输出模板(重构/架构类) ```text 问题:<根因 1-2 句> 方案:<选定的方案简述> 迁移计划: Step 1: <做什么> → 验证:<怎么验证> Step 2: ... 风险:<已知风险和缓解措施> 状态:进行中 | 已完成 ``` ## 关键原则 - **先理解再动手**:E 模式允许较高的 token 消耗用于阅读和理解——诊断和设计方案阶段不做省 token 优化。 - **不提前优化**:只重构当前确实有问题的部分,不顺手"优化"无关代码。 - **留退出路径**:每一步都可以撤销或暂停,不做不可逆的一次性大改。
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/phoenixlucky/skills/zerotoken-skill",
"sourceUrl": "https://clawhub.ai/phoenixlucky/skills/zerotoken-skill",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T15:15:09.724Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-phoenixlucky-zerotoken-skill/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-phoenixlucky-zerotoken-skill/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T15:15:09.724Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.4K downloads",
"href": "https://clawhub.ai/phoenixlucky/zerotoken-skill",
"sourceUrl": "https://clawhub.ai/phoenixlucky/zerotoken-skill",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T15:15:09.724Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.17.0",
"href": "https://clawhub.ai/phoenixlucky/zerotoken-skill",
"sourceUrl": "https://clawhub.ai/phoenixlucky/zerotoken-skill",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-20T07:34:38.599Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-phoenixlucky-zerotoken-skill/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-phoenixlucky-zerotoken-skill/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.17.0",
"description": "安全:移除未受信任桥脚本探测与执行(修复审计 T07)并补充第三方数据外发提示;audit_encoding 移除 .env 避免误报;收窄 SKILL.md 自动触发条件;fix_encoding 无 --backup 时告警",
"href": "https://clawhub.ai/phoenixlucky/zerotoken-skill",
"sourceUrl": "https://clawhub.ai/phoenixlucky/zerotoken-skill",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-20T07:34:38.599Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
