{"id":"2da1c15f-0727-42c6-84bf-3b063450a8ea","entityType":"agent","slug":"clawhub-georgechou17-chameleon-ultra-cli-skill","name":"Chameleon Ultra Cli","canonicalUrl":"https://www.xpersona.co/agent/clawhub-georgechou17-chameleon-ultra-cli-skill","canonicalPath":"/agent/clawhub-georgechou17-chameleon-ultra-cli-skill","generatedAt":"2026-10-09T21:14:55.266Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T09:07:20.076Z","emptyReason":null},"description":"控制变色龙(Chameleon)Ultra 读写卡器，通过其 chameleon_cli_main 命令行程序操作设备。当用户想用命令行操作 Chameleon Ultra 设备时使用本技能：连接设备、扫描/读取高频(HF/NFC)或低频(LF)卡片、运行 MIFARE Classic 攻击(nested/darkside/hardnested)、管理模拟卡槽、载入/保存 dump、修改设备设置，或自动化任意 chameleon_cli_main 命令。本技能以非交互方式驱动交互式 REPL，并在首次配置后持久保存可执行文件路径。 Skill: Chameleon Ultra Cli Owner: georgechou17 Summary: 控制变色龙(Chameleon)Ultra 读写卡器，通过其 chameleon_cli_main 命令行程序操作设备。当用户想用命令行操作 Chameleon Ultra 设备时使用本技能：连接设备、扫描/读取高频(HF/NFC)或低频(LF)卡片、运行 MIFARE Classic 攻击(nested/darkside/hardnested)、管理模拟卡槽、载入/保存 dump、修改设备设置，或自动化任意 chameleon_cli_main 命令。本技能以非交互方式驱动交互式 REPL，并在首次配置后持久保存可执行文件路径。 Tags: latest:0.1.0 Version history: v0.1.0 | 2026-07-25T15:24:55.695Z | auto Initial release of","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 3.2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s176y064ps888173yfc6zmjp498b0fqn:chameleon-ultra-cli-skill","sourceUrl":"https://clawhub.ai/georgechou17/chameleon-ultra-cli-skill","homepage":"https://clawhub.ai/georgechou17/skills/chameleon-ultra-cli-skill","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/georgechou17/chameleon-ultra-cli-skill","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/georgechou17/skills/chameleon-ultra-cli-skill","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":70,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"控制变色龙(Chameleon)Ultra 读写卡器，通过其 chameleon_cli_main 命令行程序操作设备。当用户想用命令行操作 Chameleon Ultra 设备时使用本技能：连接设备、扫描/读取高频(HF/NFC)或低频(LF)卡片、运行 MIFARE Classic 攻击(nested/darksi"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:07:20.076Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:07:20.076Z","emptyReason":null},"stars":null,"forks":null,"downloads":3214,"packageName":null,"latestVersion":"0.1.0","tractionLabel":"3.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:07:20.076Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T09:07:20.076Z","lastCrawledAt":"2026-10-09T09:07:20.076Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T09:07:20.076Z","lastVerifiedAt":null,"highlights":[{"version":"0.1.0","createdAt":"2026-07-25T15:24:55.695Z","changelog":"Initial release of chameleon-ultra-cli-skill. - Enables scriptable, non-interactive control of Chameleon Ultra CLI via a PTY-wrapped chameleon_cli_main binary. - Supports device connection, card scanning (HF/LF), MIFARE Classic attacks, slot management, dump load/save, and device settings. - Guides initial executable path configuration with persistent storage in config.json. - Handles platform dependencies automatically (pywinpty for Windows, pty for POSIX). - Provides troubleshooting steps and attack strategy reference for various MIFARE Classic approaches.","fileCount":9,"zipByteSize":23600}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s176y064ps888173yfc6zmjp498b0fqn:chameleon-ultra-cli-skill","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T21:14:55.266Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-georgechou17-chameleon-ultra-cli-skill/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T09:07:20.076Z","emptyReason":null},"readme":"Skill: Chameleon Ultra Cli\n\nOwner: georgechou17\n\nSummary: 控制变色龙(Chameleon)Ultra 读写卡器，通过其 chameleon_cli_main 命令行程序操作设备。当用户想用命令行操作 Chameleon Ultra 设备时使用本技能：连接设备、扫描/读取高频(HF/NFC)或低频(LF)卡片、运行 MIFARE Classic 攻击(nested/darkside/hardnested)、管理模拟卡槽、载入/保存 dump、修改设备设置，或自动化任意 chameleon_cli_main 命令。本技能以非交互方式驱动交互式 REPL，并在首次配置后持久保存可执行文件路径。\n\nTags: latest:0.1.0\n\nVersion history:\n\nv0.1.0 | 2026-07-25T15:24:55.695Z | auto\n\nInitial release of chameleon-ultra-cli-skill.\n\n- Enables scriptable, non-interactive control of Chameleon Ultra CLI via a PTY-wrapped chameleon_cli_main binary.\n- Supports device connection, card scanning (HF/LF), MIFARE Classic attacks, slot management, dump load/save, and device settings.\n- Guides initial executable path configuration with persistent storage in config.json.\n- Handles platform dependencies automatically (pywinpty for Windows, pty for POSIX).\n- Provides troubleshooting steps and attack strategy reference for various MIFARE Classic approaches.\n\nArchive index:\n\nArchive v0.1.0: 9 files, 23600 bytes\n\nFiles: LICENSE (1047b), README.md (24676b), references (0b), references/cli_reference.md (5133b), scripts (0b), scripts/chameleon_control.py (12948b), skill-card.md (2523b), SKILL.md (8335b), _meta.json (144b)\n\nFile v0.1.0:SKILL.md\n\n---\r\nname: chameleon-ultra-cli\r\ndescription: \"控制变色龙(Chameleon)Ultra 读写卡器，通过其 chameleon_cli_main 命令行程序操作设备。当用户想用命令行操作 Chameleon Ultra 设备时使用本技能：连接设备、扫描/读取高频(HF/NFC)或低频(LF)卡片、运行 MIFARE Classic 攻击(nested/darkside/hardnested)、管理模拟卡槽、载入/保存 dump、修改设备设置，或自动化任意 chameleon_cli_main 命令。本技能以非交互方式驱动交互式 REPL，并在首次配置后持久保存可执行文件路径。\"\r\nagent_created: true\r\n---\r\n\r\n# 变色龙 Ultra CLI 控制器\r\n\r\n通过命令直接驱动 Chameleon Ultra 设备的 `chameleon_cli_main` 程序，无需在交互式\r\nREPL 中手动敲命令。本技能把可执行文件包裹在伪终端(pseudo-terminal)中，从而可以脚本化\r\n下发命令并可靠捕获输出（官方 CLI 是交互式的 `prompt_toolkit` REPL，在 Windows 上无法\r\n通过管道输入来驱动）。\r\n\r\n## 何时使用\r\n\r\n只要用户想通过 CLI 对 Chameleon Ultra 做任何操作，就应使用本技能，包括但不限于：\r\n\r\n- 连接 / 断开设备，读取固件版本、芯片 ID、设备模式\r\n- 扫描或读取高频卡(ISO14443-A / NFC)或低频卡(EM410x / HID)\r\n- MIFARE Classic 攻击：`nested`、`darkside`、`hardnested`、密钥恢复\r\n- 管理模拟卡槽（类型、初始化、启用、切换、载入/保存 dump）\r\n- 修改设备设置（LED 动画、BLE 配对密钥）\r\n- 用户提到的任何其他 `chameleon_cli_main` 命令\r\n\r\n## 首次配置（必需，仅一次）\r\n\r\n可执行文件路径**无法预先获知**。在运行任何命令前，先确认是否已配置：\r\n\r\n1. 运行辅助脚本的 `--show-config`。如果 `exe_path` 已设置且有效，则跳到下面的\"运行命令\"。\r\n2. 如果尚未配置，向用户询问 `chameleon_cli_main` 的完整路径\r\n   （例如 `C:\\tools\\chameleon\\chameleon_cli_main.exe`）。\r\n   使用 AskUserQuestion 工具询问；仅当用户之前提到过某个路径时，才提供合理的默认值。\r\n3. 调用辅助脚本持久化保存：\r\n\r\n   ```\r\n   python SKILL_DIR/scripts/chameleon_control.py --set-exe \"C:\\path\\to\\chameleon_cli_main.exe\"\r\n   ```\r\n\r\n   这会把 `exe_path` 保存到脚本同级的 `config.json` 中，之后所有运行都会复用该路径。\r\n\r\n始终先检查 `--show-config`；如果路径已保存，不要重复询问用户。\r\n\r\n## 运行命令\r\n\r\n把用户的需求翻译成一条或多条 `chameleon_cli_main` 命令（命令树参见\r\n`references/cli_reference.md`；设备上可用 command-group -h 查看精确的、与固件版本\r\n对应的语法）。然后用辅助脚本运行，每条命令作为独立引号参数传入：\r\n\r\n```\r\npython SKILL_DIR/scripts/chameleon_control.py \"hw connect\" \"hf 14a scan\"\r\n```\r\n\r\n辅助脚本的关键行为：\r\n\r\n- 会自动在命令前补 `hw connect`（除非加 `--no-connect`），并在末尾补 `exit`，\r\n  因此每次调用都是一个全新的、可自行结束的会话。\r\n- 多条命令在同一会话中顺序执行——把相关步骤（如卡槽设置 + 载入 + 启用）放在一次调用中。\r\n- 需要等待卡片或计算的命令（如 `hf 14a scan`、`hf mf nested`）可能耗时较久，\r\n  可用 `--timeout SECONDS` 调大上限（默认 120 秒）。\r\n- `--file commands.txt` 会逐行运行文件中的命令（`#` 开头为注释）。\r\n- `--raw` 保留 ANSI 转义码和回显输入；否则会对输出做清理以提升可读性。\r\n\r\n示例——把一张 MIFARE dump 读入卡槽 8 并启用：\r\n\r\n```\r\npython SKILL_DIR/scripts/chameleon_control.py \"hw slot type -s 8 -t MIFARE_1024\" \"hw slot init -s 8 -t MIFARE_1024\" \"hw slot enable -s 8 --hf\" \"hw slot change -s 8\"\r\n```\r\n\r\n运行后，把捕获到的设备输出呈现给用户并据此处理（例如汇总扫描到的 UID、报告恢复出的密钥）。\r\n\r\n## 依赖\r\n\r\n在首次真正运行（非仅配置）时，辅助脚本会确保存在 PTY 后端：\r\n\r\n- **Windows**：会在 `SKILL_DIR/.venv` 本地创建一个 venv 并安装 `pywinpty`\r\n  （一次性，需要网络）。随后进程会用该解释器重新执行自身，无需手动安装。\r\n- **POSIX**：使用标准库 `pty` 模块——无需安装。\r\n\r\n若一次性的 `pywinpty` 安装失败（无网络），辅助脚本会清晰报错；恢复网络后重试即可。\r\n\r\n## MIFARE 攻击方式速查\r\n\r\n`chameleon_cli_main` 内置 5 种 MIFARE Classic 密钥攻击方式，各有适用场景。\r\n\r\n| 攻击方式 | 核心原理 | 适用场景 |\r\n|----------|----------|----------|\r\n| Darkside（黑暗侧信道攻击） | 利用卡片在认证失败时返回的特殊错误信息（NACK）来逆向出密钥 | 完全不依赖任何已知密钥，可从零开始 |\r\n| Nested（嵌套攻击） | 利用一个已知的扇区密钥去「偷听」并破解其他扇区的密钥 | 至少需要知道一个扇区的密钥 |\r\n| StaticNested（静态嵌套攻击） | 嵌套攻击的一个变种，针对伪随机数生成器（PRNG）有缺陷的卡片 | 卡片生成随机数的规律较弱时 |\r\n| Hardnested（硬嵌套攻击） | 嵌套攻击的「终极版」，不依赖卡片的随机数质量，仅凭一个已知密钥即可破解，但计算量巨大 | 卡片随机数质量很好，其他攻击无效时 |\r\n| MFKEY32 v2 | 通常用于分析你之前「嗅探」到的刷卡数据，以计算出密钥 | 当你用 Chameleon 在「监听模式」下抓取过卡片与读卡器的通信数据时 |\r\n\r\n对应 CLI 命令与典型用法：\r\n- Darkside：`hf mf darkside`（0 扇区起手）\r\n- Nested：`hf mf nested --blk BLOCK -k KEY --tblk TBLOCK [-a|-b] [--ta|-tb]`\r\n- StaticNested：`hf mf nested` + 使用内置 `staticnested` 工具（`hf mf nested --static` 之类，因固件版本而异，先 `hf mf nested -h`）\r\n- Hardnested：`hf mf hardnested --blk BLOCK -k KEY [--tblk TBLOCK] [--slow] [--keep-nonce-file]`\r\n- MFKEY32 v2：先用 `hf mf econfig --enable-log` 开启认证日志，再用 Chameleon 模拟卡刷一次读卡器，下来后 `hf mf elog` / `hf mf elog --decrypt`\r\n\r\n> 选择策略：先用 Darkside（无须已知密钥）；拿到一个密钥后再用 Nested 扩大战果；\r\n> 遇到弱随机数卡直接 StaticNested；其他都失效时上 Hardnested（耗时可能数十分钟到数小时）。\r\n> 监听到真实刷卡数据时优先 MFKEY32 v2。\r\n\r\n## 注意事项\r\n\r\n- 设备必须通过 USB 连接（或已通过 BLE 配对），`hw connect` 才能成功；\r\n  在此之前离线命令都会失败。\r\n- 每次辅助脚本调用都是独立的——调用之间没有持久会话。多步流程请放在同一次调用内。\r\n- 固件版本不同命令略有差异；不确定某命令的参数时，可通过辅助脚本运行对应的\r\n  command-group 帮助（如 `hw -h`）来查看设备实时的帮助信息。\r\n\r\n### 排查指南\r\n\r\n如果运行命令后**没有任何输出**（不报错也不显示设备提示符），按以下顺序排查：\r\n\r\n1. **设备是否连上？** 先去 Windows 设备管理器确认看到 `USB Serial Device (COM3)`\r\n   （VID_6868&PID_8686），再用 `--raw \"hw version\"` 看原始输出。\r\n2. **换行符不执行？** `chameleon_cli_main` 基于 prompt_toolkit，其 REPL 只认\r\n   `LF(\\n)` 为「执行」键。`CR(\\r)` 会被当成补全触发，表现为列出子命令菜单而非执行。\r\n   辅助脚本已统一使用 `\\n`，无需手动处理；但如果直接调试 winpty，注意这个区别。\r\n3. **REPL 卡在终端查询？** prompt_toolkit 启动时会向终端发送能力查询\r\n   （如 `\\x1b[c` 设备属性查询、`\\x1b[6n` 光标位置请求），必须收到应答才会渲染\r\n   提示符。`chameleon_control.py` 已在读取线程中自动回写标准应答，无需手动干预。\r\n   如果换了不同固件版本的 exe 且 prompt_toolkit 版本差异导致查询序列变化，可\r\n   先用 `--raw` 抓取原始终端序列，对照 `respond_to_queries()` 补新的应答。\r\n4. **标准 python 调用丢输出？** 若通过 `python chameleon_control.py` 调用返回空输出，\r\n   检查是否走了 `os.execv` 重执行路径（老版本有此问题，已修复为 `subprocess.run`）。\r\n   仍不行时直接用技能目录 `.venv/Scripts/python.exe` 运行脚本，绕过 bootstrap。\n\nFile v0.1.0:README.md\n\n# chameleon-ultra-cli\n\n一个用于 [WorkBuddy](https://www.codebuddy.cn/) 的技能（Skill），让你用大白话指挥\n[Chameleon Ultra](https://github.com/RfidResearchGroup/ChameleonUltra) 读写卡器，\n把加密 IC 卡（门禁卡、电梯卡等）复制、读取、模拟出来，全程不用自己敲命令行。\n\n## 语言 / Languages / Langues\n\n- **中文**\n  - [简体中文](#简体中文)\n  - [香港正體](#香港正體)\n  - [新加坡中文](#新加坡中文)\n- [English](#english)\n- [Français](#french)\n\n---\n\n## 简体中文\n\n### 背景介绍\n\n在国内，很多小区的物业会限制业主自由使用属于自己的门禁卡：补一张卡动辄几十上百元、\n绑定手机号、甚至规定「一张卡只能对应一个人」，本质是把本该免费提供给业主的便利变成\n持续的收费项目，情节严重的已经涉嫌恶意收费、侵占业主权益。\n\n而绝大多数业主手里的门禁卡其实是**加密的 IC 卡（MIFARE Classic 居多）**。一旦丢了或\n需要多备一张，物业就借机收费。其实，只要是你**自己小区、自己名下的卡**，复制一张备用\n完全是你个人的正当权利。\n\n问题在于：变色龙 Ultra 这类设备的官方操作依赖一个命令行程序，要在交互式界面里手敲一堆\n命令，对普通小白极不友好。为了解决这个问题，我制作了这个 Skill——把复杂的命令行交互\n封装起来，你只需要用自然语言告诉 WorkBuddy 想做什么，它就会自动完成连接、读卡、复制、\n模拟等全流程操作。\n\n> 说明：本工具仅用于复制**你本人拥有合法使用权**的卡片（自家门禁、自家电梯卡等）。\n> 请勿用于复制不属于你的、或未经授权的他人卡片。\n\n### 使用方法（小白向）\n\n**第 1 步：下载变色龙 Ultra 的命令行程序**\n\n本程序**只支持 Windows 系统**，请在 Windows 电脑上操作。\n\n- 下载地址：https://wwaxz.lanzoul.com/iar123ylt1sh\n- 提取密码：**6bm4**\n- 下载后解压，你会得到一个 `chameleon_cli_main.exe` 文件，**记住它的完整路径**\n  （例如 `C:\\tools\\chameleon\\chameleon_cli_main.exe`）。\n\n**第 2 步：安装本 Skill 到 WorkBuddy**\n\n把整个 `chameleon-ultra-cli` 文件夹放到 WorkBuddy 的用户技能目录：\n\n```\nC:\\Users\\你的用户名\\.workbuddy\\skills\\chameleon-ultra-cli\\\n```\n\n**第 3 步：告诉 Skill 程序在哪（只需一次）**\n\n打开 WorkBuddy，对助手说类似这样的话，把第 1 步记下的路径填进去：\n\n```\n请设置变色龙程序路径为 C:\\tools\\chameleon\\chameleon_cli_main.exe\n```\n\n（本质就是执行了 `python scripts/chameleon_control.py --set-exe \"你的路径\"`，\n路径会保存下来，以后不用再设。）\n\n**第 4 步：插上设备，开始用大白话指挥**\n\n用 USB 把变色龙 Ultra 连上电脑，然后直接用自然语言下指令即可，例如：\n\n- 「读一下我这张门禁卡的信息」\n- 「把这张卡复制一份到卡槽 8 里」\n- 「扫描一下这张高频卡，看看 UID 是什么」\n\nSkill 会自动连上设备、执行对应命令、把结果翻成你能看懂的话返回给你。\n\n**常用参数（进阶，可不看）**\n\n- `--timeout 秒数`：读卡 / 跑攻击比较慢时用，把等待时间调大（默认 120 秒）\n- `--file 命令.txt`：把一堆命令写进文本文件，逐行批量执行（`#` 开头是注释）\n- `--raw`：保留原始终端输出，仅在排查问题时用\n\n### 技术原理（简述）\n\n为什么不能直接用官方命令行程序？因为它是一个**交互式 REPL**（基于 prompt_toolkit），\n就像个一直在等你敲命令的小窗口——你没法简单地把命令「管道」喂给它，在 Windows 上尤其\n会直接报错。\n\n本 Skill 的解法是：\n\n1. **伪终端（PTY）包裹**：在 Windows 上用 `pywinpty`（首次运行会自动建好环境安装），\n   在 Linux / macOS 上用系统自带的 `pty` 模块，把官方程序包进一个「假终端」里，\n   这样就能像真人一样给它下发命令、并可靠地读回输出。\n2. **自动会话管理**：每次调用都会自动先发 `hw connect` 连设备、最后发 `exit` 退出，\n   保证每次都是干净、能自己结束的独立会话。\n3. **踩过的关键坑**（已自动处理，你无需关心）：\n   - 换行符必须用 `LF(\\n)`，用回车 `\\r` 会被当成补全触发；\n   - 程序启动会发终端能力查询并等应答才显示提示符，Skill 会自动回写应答，\n     否则它会「卡死」、什么都不输出。\n\n### 致谢\n\n本 Skill 建立在变色龙 Ultra 开源项目的成果之上，衷心感谢原作者的无私开源：\n\n**RfidResearchGroup / ChameleonUltra**\nhttps://github.com/RfidResearchGroup/ChameleonUltra\n\n没有这个优秀的开源硬件与固件，普通用户根本无法低成本地拿回本就属于自己那张卡的控制权。\n\n---\n\n## 香港正體\n\n### 背景介紹\n\n在國內，很多小區的物業會限制業主自由使用屬於自己的門禁卡：補一張卡動輒幾十上百元、\n綁定手機號、甚至規定「一張卡只能對應一個人」，本質是把本該免費提供給業主的便利變成\n持續的收費項目，情節嚴重的已經涉嫌惡意收費、侵占業主權益。\n\n而絕大多數業主手裡的門禁卡其實是**加密的 IC 卡（MIFARE Classic 居多）**。一旦掉了或\n需要多備一張，物業就藉機收費。其實，只要是你**自己小區、自己名下的卡**，複製一張備用\n完全是你個人的正當權利。\n\n問題在於：變色龍 Ultra 這類設備的官方操作依賴一個命令列程式，要在互動式介面裡手敲一堆\n命令，對普通小白極不友善。為了解決這個問題，我製作了這個 Skill——把複雜的命令列互動\n封裝起來，你只需要用自然語言告訴 WorkBuddy 想做什麼，它就會自動完成連接、讀卡、複製、\n模擬等全流程操作。\n\n> 說明：本工具僅用於複製**你本人擁有合法使用權**的卡片（自家門禁、自家電梯卡等）。\n> 請勿用於複製不屬於你的、或未經授權的他人卡片。\n\n### 使用方法（小白向）\n\n**第 1 步：下載變色龍 Ultra 的命令列程式**\n\n本程式**只支援 Windows 系統**，請在 Windows 電腦上操作。\n\n- 下載地址：https://wwaxz.lanzoul.com/iar123ylt1sh\n- 提取密碼：**6bm4**\n- 下載後解壓，你會得到一個 `chameleon_cli_main.exe` 檔案，**記住它的完整路徑**\n  （例如 `C:\\tools\\chameleon\\chameleon_cli_main.exe`）。\n\n**第 2 步：安裝本 Skill 到 WorkBuddy**\n\n把整個 `chameleon-ultra-cli` 資料夾放到 WorkBuddy 的使用者技能目錄：\n\n```\nC:\\Users\\你的使用者名稱\\.workbuddy\\skills\\chameleon-ultra-cli\\\n```\n\n**第 3 步：告訴 Skill 程式在哪（只需一次）**\n\n開啟 WorkBuddy，對助手說類似這樣的話，把第 1 步記下的路徑填進去：\n\n```\n請設定變色龍程式路徑為 C:\\tools\\chameleon\\chameleon_cli_main.exe\n```\n\n（本質就是執行了 `python scripts/chameleon_control.py --set-exe \"你的路徑\"`，\n路徑會儲存下來，以後不用再設。）\n\n**第 4 步：插上裝置，開始用大白話指揮**\n\n用 USB 把變色龍 Ultra 連上電腦，然後直接用自然語言下指令即可，例如：\n\n- 「讀一下我這張門禁卡的資訊」\n- 「把這張卡複製一份到卡槽 8 裡」\n- 「掃描一下這張高頻卡，看看 UID 是什麼」\n\nSkill 會自動連上裝置、執行對應命令、把結果翻成你能看懂的話傳回給你。\n\n**常用參數（進階，可不看）**\n\n- `--timeout 秒數`：讀卡 / 跑攻擊比較慢時用，把等待時間調大（預設 120 秒）\n- `--file 命令.txt`：把一堆命令寫進文字檔，逐行批次執行（`#` 開頭是註解）\n- `--raw`：保留原始終端輸出，僅在排查問題時用\n\n### 技術原理（簡述）\n\n為什麼不能直接用官方命令列程式？因為它是一個**互動式 REPL**（基於 prompt_toolkit），\n就像個一直在等你敲命令的小視窗——你沒法簡單地把命令「管道」餵給它，在 Windows 上尤其\n會直接報錯。\n\n本 Skill 的解法是：\n\n1. **偽終端（PTY）包裹**：在 Windows 上用 `pywinpty`（首次執行會自動建好環境安裝），\n   在 Linux / macOS 上用系統自帶的 `pty` 模組，把官方程式包進一個「假終端」裡，\n   這樣就能像真人一樣給它下發命令、並可靠地讀回輸出。\n2. **自動會話管理**：每次呼叫都會自動先發 `hw connect` 連裝置、最後發 `exit` 退出，\n   保證每次都是乾淨、能自己結束的獨立會話。\n3. **踩過的關鍵坑**（已自動處理，你無需關心）：\n   - 換行符必須用 `LF(\\n)`，用回車 `\\r` 會被當成補全觸發；\n   - 程式啟動會發終端能力查詢並等應答才顯示提示符，Skill 會自動回寫應答，\n     否則它會「卡死」、什麼都不輸出。\n\n### 致謝\n\n本 Skill 建立在變色龍 Ultra 開源專案的成果之上，衷心感謝原作者的無私開源：\n\n**RfidResearchGroup / ChameleonUltra**\nhttps://github.com/RfidResearchGroup/ChameleonUltra\n\n沒有這個優秀的開源硬體與韌體，普通用戶根本無法低成本地拿回本就屬於自己那張卡的控制權。\n\n---\n\n## 新加坡中文\n\n### 背景介绍\n\n在中国，许多住宅区（组屋区 / 公寓区）的物业管理公司会限制居民自由使用属于自己的门禁卡：\n补一张卡动辄几十上百元、绑定手机号、甚至规定「一张卡只能对应一个人」，本质是把本应免费\n提供给居民的便利变成持续的收费项目，情节严重的已涉嫌恶意收费、侵犯居民权益。\n\n而绝大多数居民手里的门禁卡其实是**加密的 IC 卡（MIFARE Classic 居多）**。一旦遗失或\n需要多备一张，物管公司就借机收费。其实，只要是你**自己住宅、自己名下的卡**，复制一张\n备用完全是你个人的正当权利。\n\n问题在于：变色龙 Ultra 这类设备的官方操作依赖一个命令行程序，要在交互式界面里手敲一堆\n命令，对普通用户极不友好。为了解决这个问题，我制作了这个 Skill——把复杂的命令行交互\n封装起来，你只需用自然语言告诉 WorkBuddy 想做什么，它就会自动完成连接、读卡、复制、\n模拟等全流程操作。\n\n> 说明：本工具仅用于复制**你本人拥有合法使用权**的卡片（自家门禁、自家电梯卡等）。\n> 请勿用于复制不属于你的、或未经授权的他人卡片。\n\n### 使用方法（小白向）\n\n**第 1 步：下载变色龙 Ultra 的命令行程序**\n\n本程序**只支持 Windows 系统**，请在 Windows 电脑上操作。\n\n- 下载地址：https://wwaxz.lanzoul.com/iar123ylt1sh\n- 提取密码：**6bm4**\n- 下载后解压，你会得到一个 `chameleon_cli_main.exe` 文件，**记下它的完整路径**\n  （例如 `C:\\tools\\chameleon\\chameleon_cli_main.exe`）。\n\n**第 2 步：安装本 Skill 到 WorkBuddy**\n\n把整个 `chameleon-ultra-cli` 文件夹放到 WorkBuddy 的用户技能目录：\n\n```\nC:\\Users\\你的用户名\\.workbuddy\\skills\\chameleon-ultra-cli\\\n```\n\n**第 3 步：告诉 Skill 程序在哪（只需一次）**\n\n打开 WorkBuddy，对助手说类似这样的话，把第 1 步记下的路径填进去：\n\n```\n请设置变色龙程序路径为 C:\\tools\\chameleon\\chameleon_cli_main.exe\n```\n\n（本质就是执行了 `python scripts/chameleon_control.py --set-exe \"你的路径\"`，\n路径会保存下来，以后不用再设。）\n\n**第 4 步：插上设备，开始用大白话指挥**\n\n用 USB 把变色龙 Ultra 连上电脑，然后直接用自然语言下指令即可，例如：\n\n- 「读一下我这张门禁卡的信息」\n- 「把这张卡复制一份到卡槽 8 里」\n- 「扫描一下这张高频卡，看看 UID 是什么」\n\nSkill 会自动连上设备、执行对应命令、把结果翻成你能看懂的话返回给你。\n\n**常用参数（进阶，可不看）**\n\n- `--timeout 秒数`：读卡 / 跑攻击比较慢时用，把等待时间调大（默认 120 秒）\n- `--file 命令.txt`：把一堆命令写进文本文件，逐行批量执行（`#` 开头是注释）\n- `--raw`：保留原始终端输出，仅在排查问题时用\n\n### 技术原理（简述）\n\n为什么不能直接用官方命令行程序？因为它是一个**交互式 REPL**（基于 prompt_toolkit），\n就像个一直在等你敲命令的小窗口——你没法简单地把命令「管道」喂给它，在 Windows 上尤其\n会直接报错。\n\n本 Skill 的解法是：\n\n1. **伪终端（PTY）包裹**：在 Windows 上用 `pywinpty`（首次运行会自动建好环境安装），\n   在 Linux / macOS 上用系统自带的 `pty` 模块，把官方程序包进一个「假终端」里，\n   这样就能像真人一样给它下发命令、并可靠地读回输出。\n2. **自动会话管理**：每次调用都会自动先发 `hw connect` 连设备、最后发 `exit` 退出，\n   保证每次都是干净、能自己结束的独立会话。\n3. **踩过的关键坑**（已自动处理，你无需关心）：\n   - 换行符必须用 `LF(\\n)`，用回车 `\\r` 会被当成补全触发；\n   - 程序启动会发终端能力查询并等应答才显示提示符，Skill 会自动回写应答，\n     否则它会「卡死」、什么都不输出。\n\n### 致谢\n\n本 Skill 建立在变色龙 Ultra 开源项目的成果之上，衷心感谢原作者的无私开源：\n\n**RfidResearchGroup / ChameleonUltra**\nhttps://github.com/RfidResearchGroup/ChameleonUltra\n\n没有这个优秀的开源硬件与固件，普通用户根本无法低成本地拿回本就属于自己那张卡的控制权。\n\n---\n\n## English\n\nA [WorkBuddy](https://www.codebuddy.cn/) Skill that lets you command the\n[Chameleon Ultra](https://github.com/RfidResearchGroup/ChameleonUltra) card reader\nin plain language — clone, read, and emulate encrypted IC cards (access cards,\nelevator cards, etc.) without ever typing commands yourself.\n\n### Background\n\nIn China, many residential communities' property management restricts owners from\nfreely using their own access cards: replacing a lost card can cost dozens or even\nover a hundred yuan, they force-binding phone numbers, and some even rule that\n\"one card may only belong to one person\". In essence, a convenience that should be\nprovided to owners for free is turned into a recurring money-making scheme — in\nserious cases it amounts to extortionate fees that infringe on owners' rights.\n\nMost owners' access cards are actually **encrypted IC cards (mostly MIFARE Classic)**.\nThe moment you lose one or need a spare, the property management charges you again.\nIn reality, as long as it is a card for **your own home that you legitimately own**,\nmaking a backup copy is entirely your personal right.\n\nThe problem: operating the Chameleon Ultra officially requires a command-line program\nwhere you must type a pile of commands in an interactive prompt — far too unfriendly\nfor ordinary users. To solve this, I built this Skill: it wraps the complex CLI\ninteraction so you only need to tell WorkBuddy what you want in natural language, and\nit automatically connects, reads, clones, and emulates the card for you.\n\n> Note: This tool is only for cloning cards **you yourself have the legal right to\n> use** (your own access card, your own elevator card, etc.). Do not use it to clone\n> someone else's card without authorization.\n\n### How to use (for beginners)\n\n**Step 1: Download the Chameleon Ultra command-line program**\n\nThis program **only supports Windows**. Use a Windows computer.\n\n- Download: https://wwaxz.lanzoul.com/iar123ylt1sh\n- Password: **6bm4**\n- After extracting you get a `chameleon_cli_main.exe` file — **remember its full path**\n  (e.g. `C:\\tools\\chameleon\\chameleon_cli_main.exe`).\n\n**Step 2: Install this Skill into WorkBuddy**\n\nPlace the whole `chameleon-ultra-cli` folder into WorkBuddy's user skills directory:\n\n```\nC:\\Users\\your-username\\.workbuddy\\skills\\chameleon-ultra-cli\\\n```\n\n**Step 3: Tell the Skill where the program is (once only)**\n\nOpen WorkBuddy and tell the assistant something like this, filling in the path from Step 1:\n\n```\nSet the Chameleon program path to C:\\tools\\chameleon\\chameleon_cli_main.exe\n```\n\n(Under the hood this runs `python scripts/chameleon_control.py --set-exe \"your-path\"`;\nthe path is saved so you never set it again.)\n\n**Step 4: Plug in the device and just talk to it**\n\nConnect the Chameleon Ultra to your PC via USB, then give instructions in natural language, e.g.:\n\n- \"Read the info of this access card of mine\"\n- \"Clone this card into slot 8\"\n- \"Scan this HF card and show me the UID\"\n\nThe Skill auto-connects, runs the right commands, and returns the result in plain language.\n\n**Common parameters (advanced, optional)**\n\n- `--timeout SECONDS`: raise the wait limit for slow reads / attacks (default 120)\n- `--file commands.txt`: run commands listed line-by-line in a text file (`#` starts a comment)\n- `--raw`: keep raw terminal output, only for troubleshooting\n\n### Technical principle (brief)\n\nWhy can't we just use the official CLI directly? Because it is an **interactive REPL**\n(based on prompt_toolkit) — like a little window that always waits for you to type. You\ncannot simply pipe commands into it; on Windows it fails outright.\n\nThis Skill's approach:\n\n1. **Pseudo-terminal (PTY) wrapping**: on Windows it uses `pywinpty` (auto-installed on\n   first run), and on Linux / macOS it uses the built-in `pty` module, wrapping the\n   official program in a \"fake terminal\" so we can feed commands like a human and reliably\n   read back the output.\n2. **Automatic session management**: every call auto-sends `hw connect` first and `exit`\n   last, guaranteeing a clean, self-terminating independent session each time.\n3. **Key pitfalls already handled for you**:\n   - The line terminator must be `LF(\\n)`; a carriage return `\\r` is mistaken for completion.\n   - On startup the program sends terminal capability queries and waits for a reply before\n     showing the prompt; the Skill auto-replies, otherwise it would \"freeze\" with no output.\n\n### Acknowledgements\n\nThis Skill is built upon the Chameleon Ultra open-source project. Deep thanks to the\noriginal authors for their generous open-source work:\n\n**RfidResearchGroup / ChameleonUltra**\nhttps://github.com/RfidResearchGroup/ChameleonUltra\n\nWithout this excellent open-source hardware and firmware, ordinary users could never\nlow-cost regain control over a card that was rightfully theirs.\n\n---\n\n## French\n\nUn Skill pour [WorkBuddy](https://www.codebuddy.cn/) qui vous permet de piloter le lecteur\n[Chameleon Ultra](https://github.com/RfidResearchGroup/ChameleonUltra) en langage courant —\ncloner, lire et émuler des cartes IC chiffrées (cartes d'accès, cartes d'ascenseur, etc.)\nsans jamais taper de commandes vous-même.\n\n### Contexte\n\nEn Chine, la gestion immobilière de nombreuses résidences restreint les propriétaires dans\nl'usage libre de leur propre carte d'accès : remplacer une carte perdue coûte des dizaines\nvoire plus d'une centaine de yuans, impose la liaison d'un numéro de téléphone, et certains\nimposent même qu'« une carte ne peut correspondre qu'à une seule personne ». En substance,\nune commodité qui devrait être fournie gratuitement aux propriétaires est transformée en\nsource de revenus récurrents — dans les cas graves, il s'agit de frais abusifs portant\natteinte aux droits des propriétaires.\n\nLa plupart des cartes d'accès des propriétaires sont en réalité des **cartes IC chiffrées\n(le plus souvent MIFARE Classic)**. Dès que vous en perdez une ou en avez besoin d'une\nsupplémentaire, la gestion immobilière vous facture à nouveau. Or, tant qu'il s'agit d'une\ncarte **de votre propre logement dont vous êtes légitimement propriétaire**, en faire une\ncopie de sauvegarde est un droit strictement personnel.\n\nLe problème : utiliser officiellement le Chameleon Ultra exige un programme en ligne de\ncommande où il faut taper une série de commandes dans un invite interactif — beaucoup trop\ndifficile pour un utilisateur ordinaire. Pour résoudre cela, j'ai créé ce Skill : il\nencapsule l'interaction complexe de la CLI pour que vous n'ayez qu'à dire à WorkBuddy ce\nque vous voulez, et il se connecte, lit, clone et émule la carte automatiquement.\n\n> Note : cet outil sert uniquement à cloner les cartes **dont vous détenez légalement\n> l'usage** (votre propre carte d'accès, votre propre carte d'ascenseur, etc.). Ne l'utilisez\n> pas pour cloner la carte de quelqu'un d'autre sans autorisation.\n\n### Mode d'emploi (pour débutants)\n\n**Étape 1 : Télécharger le programme en ligne de commande du Chameleon Ultra**\n\nCe programme **ne fonctionne que sous Windows**. Utilisez un ordinateur Windows.\n\n- Téléchargement : https://wwaxz.lanzoul.com/iar123ylt1sh\n- Mot de passe : **6bm4**\n- Après extraction vous obtenez un fichier `chameleon_cli_main.exe` — **notez son chemin\n  complet** (par ex. `C:\\tools\\chameleon\\chameleon_cli_main.exe`).\n\n**Étape 2 : Installer ce Skill dans WorkBuddy**\n\nPlacez tout le dossier `chameleon-ultra-cli` dans le répertoire des compétences utilisateur\nde WorkBuddy :\n\n```\nC:\\Users\\votre-nom-utilisateur\\.workbuddy\\skills\\chameleon-ultra-cli\\\n```\n\n**Étape 3 : Indiquer à le Skill où se trouve le programme (une seule fois)**\n\nOuvrez WorkBuddy et dites à l'assistant quelque chose comme ceci, en renseignant le chemin\nde l'étape 1 :\n\n```\nDéfinir le chemin du programme Chameleon sur C:\\tools\\chameleon\\chameleon_cli_main.exe\n```\n\n(En coulisses, cela exécute `python scripts/chameleon_control.py --set-exe \"votre-chemin\"` ;\nle chemin est enregistré et vous n'aurez plus à le redéfinir.)\n\n**Étape 4 : Branchez l'appareil et parlez-lui simplement**\n\nConnectez le Chameleon Ultra à votre PC via USB, puis donnez des instructions en langage\nnaturel, par ex. :\n\n- « Lis les infos de cette carte d'accès à moi »\n- « Clone cette carte dans le slot 8 »\n- « Scanne cette carte HF et montre-moi l'UID »\n\nLe Skill se connecte automatiquement, exécute les bonnes commandes et renvoie le résultat\nen langage clair.\n\n**Paramètres courants (avancé, facultatif)**\n\n- `--timeout SECONDES` : augmente la durée d'attente pour les lectures / attaques lentes\n  (par défaut 120)\n- `--file commandes.txt` : exécute les commandes ligne par ligne depuis un fichier texte\n  (`#` commence un commentaire)\n- `--raw` : conserve la sortie terminal brute, uniquement pour le dépannage\n\n### Principe technique (en bref)\n\nPourquoi ne peut-on pas simplement utiliser la CLI officielle directement ? Parce que c'est\nun **REPL interactif** (basé sur prompt_toolkit) — comme une petite fenêtre qui attend\ntoujours que vous tapiez. On ne peut pas simplement lui envoyer des commandes via un tube ;\nsous Windows, cela échoue carrément.\n\nL'approche de ce Skill :\n\n1. **Enrobage dans un pseudo-terminal (PTY)** : sous Windows il utilise `pywinpty`\n   (installé automatiquement à la première exécution), et sous Linux / macOS il utilise le\n   module natif `pty`, enveloppant le programme officiel dans un « faux terminal » afin de\n   pouvoir envoyer des commandes comme un humain et relire la sortie de façon fiable.\n2. **Gestion automatique des sessions** : chaque appel envoie automatiquement `hw connect`\n   au début et `exit` à la fin, garantissant une session indépendante, propre et\n   auto-terminable à chaque fois.\n3. **Pièges connus déjà gérés pour vous** :\n   - Le terminateur de ligne doit être `LF(\\n)` ; un retour chariot `\\r` est pris pour une\n     complétion.\n   - Au démarrage, le programme envoie des requêtes de capacités du terminal et attend une\n     réponse avant d'afficher l'invite ; le Skill y répond automatiquement, sinon il\n     « gelait » sans rien afficher.\n\n### Remerciements\n\nCe Skill s'appuie sur le projet open-source Chameleon Ultra. Merci profondément aux auteurs\noriginaux pour leur travail généreusement partagé :\n\n**RfidResearchGroup / ChameleonUltra**\nhttps://github.com/RfidResearchGroup/ChameleonUltra\n\nSans ce matériel et ce firmware open-source d'excellente qualité, les utilisateurs ordinaires\nne pourraient jamais, à faible coût, retrouver le contrôle d'une carte qui leur appartient\nlégitimement.\n\n---\n\n## 许可证 / License / Licence\n\n[MIT-0](./LICENSE) —— 无需署名，可自由使用、修改、再分发 / No attribution required, free to\nuse, modify and redistribute / Aucune attribution requise, libre d'utiliser, modifier et\nredistribuer.\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn71cn3h6s4p3eq2qpvbnxq1k98b1r7b\",\n  \"slug\": \"chameleon-ultra-cli-skill\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1784993095695\n}\n\nFile v0.1.0:references/cli_reference.md\n\n# Chameleon Ultra CLI 命令参考 (chameleon_cli_main)\n\n本参考整理自 RfidResearchGroup/ChameleonUltra 官方命令树（docs/cli.md、chameleon_cli_unit.py）。\nchameleon_cli_main 是一个**交互式 REPL**，按功能分区组织命令：\n\n- hw  —— 设备本身（连接、模式、版本、设置、卡槽）\n- hf  —— 高频 / NFC（13.56MHz），如 ISO14443-A、MIFARE Classic\n- lf  —— 低频 / 125kHz，如 EM410x、HID\n\n通用提示\n- 任何层级都可以加 -h / --help 查看该组命令与参数，例如 hw -h、hf mf -h、hw slot -h。\n- 不同固件版本命令略有差异；以设备实际 *-h 输出为准。\n- 本 skill 的 chameleon_control.py 会自动在每条命令前补 hw connect（除非 --no-connect），并在末尾补 exit。\n- 需要等待卡片的命令（如 hf 14a scan、hf mf nested）可能耗时数秒到数十秒，可用 --timeout 调整上限。\n\n---\n\n## 根命令（REPL 控制）\n\n| 命令 | 说明 |\n|------|------|\n| clear | 清屏 |\n| rem (text) | 在输出中插入带时间戳的注释 |\n| exit / quit / q | 退出 CLI 并断开设备 |\n| dump_help | 列出所有命令（-d 显示描述，-g 按分组） |\n\n---\n\n## hw —— 设备控制\n\n| 命令 | 参数 | 说明 |\n|------|------|------|\n| hw connect | -p PORT | 连接设备；自动检测失败时用 -p COM11（Windows）或 -p /dev/ttyACM0（Linux） |\n| hw disconnect | — | 断开连接 |\n| hw mode | -r(reader) / -e(emulator) | 获取 / 切换设备模式（读卡器 / 模拟器） |\n| hw chipid | — | 读取芯片 ID |\n| hw address | — | 读取蓝牙地址 |\n| hw version | — | 读取固件版本与型号 |\n| hw settings animation | -m (NONE\\|MINIMAL\\|...) | 设置 LED 动画（NONE 最隐蔽） |\n| hw settings blekey | -k (key) | 修改 BLE 配对密钥（默认 12345，强烈建议修改） |\n| hw settings | -h | 查看全部设备设置子命令 |\n\n---\n\n## hw slot —— 卡槽管理（最多 8 个，每个含 HF + LF）\n\n| 命令 | 参数 | 说明 |\n|------|------|------|\n| hw slot list | — | 列出所有卡槽及状态 |\n| hw slot type | -s (slot) -t (type) | 设置卡槽类型，如 MIFARE_1024 |\n| hw slot init | -s (slot) -t (type) | 用指定类型的默认内容初始化卡槽 |\n| hw slot enable | -s (slot) --hf / --lf | 启用某卡槽的 HF 或 LF 模拟 |\n| hw slot disable | -s (slot) --hf / --lf | 禁用某卡槽的 HF 或 LF 模拟 |\n| hw slot change | -s (slot) | 切换到指定卡槽（设为当前激活槽） |\n| hw slot | -h | 查看其余子命令（nickname、delete 等） |\n\n典型模拟流程（MFKEY32v2 示例）\n```\nhw connect\nhw slot list\nhw slot type   -s 8 -t MIFARE_1024\nhw slot init   -s 8 -t MIFARE_1024\nhw slot enable -s 8 --hf\nhw slot change -s 8\nhf mf econfig --enable-log\n# 断开，去读卡器上刷几次卡，再连回：\nhw connect\nhf mf elog\nhf mf elog --decrypt\nhf mf econfig --disable-log\n```\n\n---\n\n## hf —— 高频 / NFC（13.56MHz）\n\n### hf 14a —— ISO14443-A\n\n| 命令 | 说明 |\n|------|------|\n| hf 14a scan | 扫描 14a 标签，显示 UID / ATQA / SAK |\n| hf 14a info | 扫描并做详细分析（猜测卡片类型、PRNG 强度等） |\n| hf 14a | -h 查看读卡、raw 等子命令 |\n\n### hf mf —— MIFARE Classic 攻击 / 操作\n\n| 命令 | 参数 | 说明 |\n|------|------|------|\n| hf mf nested | --blk BLOCK -k KEY [--tblk TBLOCK] [-a\\|-b] [--ta\\|-tb] | Nested 攻击恢复密钥 |\n| hf mf darkside | — | Darkside 攻击（0 扇区） |\n| hf mf hardnested | --blk BLOCK -k KEY [--tblk TBLOCK] [--slow] [--keep-nonce-file] | HardNested 攻击（硬 PRNG） |\n| hf mf elog | [--decrypt] | 查看 / 解密模拟器采集到的认证 nonce 日志 |\n| hf mf econfig | --enable-log / --disable-log | 开启 / 关闭模拟器认证日志 |\n| hf mf eload | (file) | 将 dump 文件载入当前模拟卡槽 |\n| hf mf esave | (file) | 将当前模拟卡槽保存为 dump 文件 |\n| hf mf chk | -k (keys) | 用给定密钥批量检测扇区 |\n| hf mf rdbl / hf mf wrbl | 块读写（需先认证） | 读取 / 写入指定块 |\n| hf mf | -h 查看全部子命令（cget/cset 等） |\n\n---\n\n## lf —— 低频 / 125kHz\n\n### lf em 410x —— EM4100/EM410x（ID 卡）\n\n| 命令 | 参数 | 说明 |\n|------|------|------|\n| lf em 410x scan | — | 扫描 EM410x 标签，显示 ID |\n| lf em 410x write | --id (HEXID) | 将 EM410x 数据写入 T55xx 模拟槽 |\n| lf em 410x | -h 查看其余子命令 |\n\n### 其他 lf\n\n- lf hid 等协议族：lf -h 查看完整列表（HID、T55xx、EM4x 等）。\n- 模拟 EM410x：hw slot enable -s (slot) --lf 后配合 lf em 410x write --id ...。\n\n---\n\n## 使用建议\n\n1. 先连接：几乎所有操作前都需要 hw connect（本 skill 默认自动补）。\n2. 查帮助：不确定参数时，用 command-group -h 即时查看，例如 hw slot -h、hf mf nested -h。\n3. 模拟 vs 读取：hw mode -e 进入模拟器模式、hw mode -r 进入读卡器模式；本 skill 多步命令建议在一个 chameleon_control.py 调用里连续下发，保证同一会话。\n4. 等待类命令：hf 14a scan / hf mf nested 等会阻塞等待卡片或计算，按需调大 --timeout。\n\nFile v0.1.0:skill-card.md\n\n## Description:\n\nControls Chameleon Ultra RFID hardware through the chameleon_cli_main command-line program for device connection, HF/LF card scanning, MIFARE Classic workflows, slot management, dump handling, and device settings.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[georgechou17](https://clawhub.ai/user/georgechou17)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and authorized Chameleon Ultra users use this skill to translate natural-language requests into CLI commands for reading, scanning, emulating, and managing RFID card workflows on hardware they are permitted to operate.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can run card-cloning, emulation, BLE key changes, and MIFARE attack commands against RFID hardware.\n\nMitigation: Install and use it only when authorized to operate the target cards and readers, and require explicit confirmation before cloning, writing, emulating, changing BLE keys, or running attack commands.\n\nRisk: The setup path references a third-party executable download for chameleon_cli_main.\n\nMitigation: Replace that download with an official, verified ChameleonUltra release and check hashes or signatures before running the configured executable.\n\nRisk: The Windows helper may install pywinpty at runtime if the dependency is missing.\n\nMitigation: Avoid unpinned runtime package installation where possible by preinstalling reviewed dependencies from trusted package indexes or pinned artifacts.\n\n## Reference(s):\n\n- [Server-resolved GitHub import](https://github.com/GeorgeChou17/chameleon-ultra-cli-skill)\n- [Chameleon Ultra CLI command reference](references/cli_reference.md)\n- [RfidResearchGroup ChameleonUltra](https://github.com/RfidResearchGroup/ChameleonUltra)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and summarized device output]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include captured Chameleon CLI output; commands require a configured chameleon_cli_main executable and connected hardware.]\n\n## Skill Version(s):\n\n0.1.0 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.1.0:LICENSE\n\nMIT No Attribution (MIT-0)\n\nCopyright (c) 2026 GeorgeChou17\n\nPermission is hereby granted, free of charge, to any person obtaining a copy of\nthis software and associated documentation files (the \"Software\"), to deal in the\nSoftware without restriction, including without limitation the rights to use, copy,\nmodify, merge, publish, distribute, sublicense, and/or sell copies of the Software,\nand to permit persons to whom the Software is furnished to do so.\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,\nINCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A\nPARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT\nHOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF\nCONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE\nOR THE USE OR OTHER DEALINGS IN THE SOFTWARE.","readmeExcerpt":"Skill: Chameleon Ultra Cli Owner: georgechou17 Summary: 控制变色龙(Chameleon)Ultra 读写卡器，通过其 chameleon_cli_main 命令行程序操作设备。当用户想用命令行操作 Chameleon Ultra 设备时使用本技能：连接设备、扫描/读取高频(HF/NFC)或低频(LF)卡片、运行 MIFARE Classic 攻击(nested/darkside/hardnested)、管理模拟卡槽、载入/保存 dump、修改设备设置，或自动化任意 chameleon_cli_main 命令。本技能以非交互方式驱动交互式 REPL，并在首次配置后持久保存可执行文件路径。 Tags: latest:0.1.0 Version history: v0.1.0 | 2026-07-25T15:24:55.695Z | auto Initial release of","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"C:\\Users\\你的用户名\\.workbuddy\\skills\\chameleon-ultra-cli\\"},{"language":"text","snippet":"请设置变色龙程序路径为 C:\\tools\\chameleon\\chameleon_cli_main.exe"},{"language":"text","snippet":"C:\\Users\\你的使用者名稱\\.workbuddy\\skills\\chameleon-ultra-cli\\"},{"language":"text","snippet":"請設定變色龍程式路徑為 C:\\tools\\chameleon\\chameleon_cli_main.exe"},{"language":"text","snippet":"C:\\Users\\你的用户名\\.workbuddy\\skills\\chameleon-ultra-cli\\"},{"language":"text","snippet":"请设置变色龙程序路径为 C:\\tools\\chameleon\\chameleon_cli_main.exe"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\r\nname: chameleon-ultra-cli\r\ndescription: \"控制变色龙(Chameleon)Ultra 读写卡器，通过其 chameleon_cli_main 命令行程序操作设备。当用户想用命令行操作 Chameleon Ultra 设备时使用本技能：连接设备、扫描/读取高频(HF/NFC)或低频(LF)卡片、运行 MIFARE Classic 攻击(nested/darkside/hardnested)、管理模拟卡槽、载入/保存 dump、修改设备设置，或自动化任意 chameleon_cli_main 命令。本技能以非交互方式驱动交互式 REPL，并在首次配置后持久保存可执行文件路径。\"\r\nagent_created: true\r\n---\r\n\r\n# 变色龙 Ultra CLI 控制器\r\n\r\n通过命令直接驱动 Chameleon Ultra 设备的 `chameleon_cli_main` 程序，无需在交互式\r\nREPL 中手动敲命令。本技能把可执行文件包裹在伪终端(pseudo-terminal)中，从而可以脚本化\r\n下发命令并可靠捕获输出（官方 CLI 是交互式的 `prompt_toolkit` REPL，在 Windows 上无法\r\n通过管道输入来驱动）。\r\n\r\n## 何时使用\r\n\r\n只要用户想通过 CLI 对 Chameleon Ultra 做任何操作，就应使用本技能，包括但不限于：\r\n\r\n- 连接 / 断开设备，读取固件版本、芯片 ID、设备模式\r\n- 扫描或读取高频卡(ISO14443-A / NFC)或低频卡(EM410x / HID)\r\n- MIFARE Classic 攻击：`nested`、`darkside`、`hardnested`、密钥恢复\r\n- 管理模拟卡槽（类型、初始化、启用、切换、载入/保存 dump）\r\n- 修改设备设置（LED 动画、BLE 配对密钥）\r\n- 用户提到的任何其他 `chameleon_cli_main` 命令\r\n\r\n## 首次配置（必需，仅一次）\r\n\r\n可执行文件路径**无法预先获知**。在运行任何命令前，先确认是否已配置：\r\n\r\n1. 运行辅助脚本的 `--show-config`。如果 `exe_path` 已设置且有效，则跳到下面的\"运行命令\"。\r\n2. 如果尚未配置，向用户询问 `chameleon_cli_main` 的完整路径\r\n   （例如 `C:\\tools\\chameleon\\chameleon_cli_main.exe`）。\r\n   使用 AskUserQuestion 工具询问；仅当用户之前提到过某个路径时，才提供合理的默认值。\r\n3. 调用辅助脚本持久化保存：\r\n\r\n   ```\r\n   python SKILL_DIR/scripts/chameleon_control.py --set-exe \"C:\\path\\to\\chameleon_cli_main.exe\"\r\n   ```\r\n\r\n   这会把 `exe_path` 保存到脚本同级的 `config.json` 中，之后所有运行都会复用该路径。\r\n\r\n始终先检查 `--show-config`；如果路径已保存，不要重复询问用户。\r\n\r\n## 运行命令\r\n\r\n把用户的需求翻译成一条或多条 `chameleon_cli_main` 命令（命令树参见\r\n`references/cli_reference.md`；设备上可用 command-group -h 查看精确的、与固件版本\r\n对应的语法）。然后用辅助脚本运行，每条命令作为独立引号参数传入：\r\n\r\n```\r\npython SKILL_DIR/scripts/chameleon_control.py \"hw connect\" \"hf 14a scan\"\r\n```\r\n\r\n辅助脚本的关键行为：\r\n\r\n- 会自动在命令前补 `hw connect`（除非加 `--no-connect`），并在末尾补 `exit`，\r\n  因此每次调用都是一个全新的、可自行结束的会话。\r\n- 多条命令在同一会话中顺序执行——把相关步骤（如卡槽设置 + 载入 + 启用）放在一次调用中。\r\n- 需要等待卡片或计算的命令（如 `hf 14a scan`、`hf mf nested`）可能耗时较久，\r\n  可用 `--timeout SECONDS` 调大上限（默认 120 秒）。\r\n- `--file commands.txt` 会逐行运行文件中的命令（`#` 开头为注释）。\r\n- `--raw` 保留 ANSI 转义码和回显输入；否则会对输出做清理以提升可读性。\r\n\r\n示例——把一张 MIFARE dump 读入卡槽 8 并启用：\r\n\r\n```\r\npython SKILL_DIR/scripts/chameleon_control.py \"hw slot type -s 8 -t MIFARE_1024\" \"hw slot init -s 8 -t MIFARE_1024\" \"hw slot enable -s 8 --hf\" \"hw slot change -s 8\"\r\n```\r\n\r\n运行后，把捕获到的设备输出呈现给用户并据此处理（例如汇总扫描到的 UID、报告恢复出的密钥）。\r\n\r\n## 依赖\r\n\r\n在首次真正运行（非仅配置）时，辅助脚本会确保存在 PTY 后端：\r\n\r\n- **Windows**：会在 `SKILL_DIR/.venv` 本地创建一个 venv 并安装 `pywinpty`\r\n  （一次性，需要网络）。随后进程会用该解释器重新执行自身，无需手动安装。\r\n- **POSIX**：使用标准库 `pty` 模块——无需安装。\r\n\r\n若一次性的 `pywinpty` 安装失败（无网络），辅助脚本会清晰报错；恢复网络后重试即可。\r\n\r\n## MIFARE 攻击方式速查\r\n\r\n`chameleon_cli_main` 内置 5 种 MIFARE Classic 密钥攻击方式，各有适用场景。\r\n\r\n| 攻击方式 | 核心原理 | 适用场景 |\r\n|----------|----------|----------|\r\n| Darkside（黑暗侧信道攻击） | 利用卡片在认证失败时返回的特殊错误信息（NACK）来逆向出密钥 | 完全不依赖任何已知密钥，可从零开始 |\r\n| Nested（嵌套攻击） | 利用一个已知的扇区密钥去「偷听」并破解其他扇区的密钥 | 至少需要知道一个扇区的密钥 |\r\n| StaticNested（静态嵌套攻击） | 嵌套攻击的一个变种，针对伪随机数生成器（PRNG）有缺陷的卡片 | 卡片生成随机数的规律较弱时 |\r\n| Hardnested（硬嵌套攻击） | 嵌套攻击的「终极版」，不依赖卡片的随机数质量，仅凭一个已知密钥即可破解，但计算量巨大 | 卡片随机数质量很好，其他攻击无效时 |\r\n| MFKEY32 v2 | 通常用于分析你之前「嗅探」到的刷卡数据，以计算出密钥 | 当你用 Chameleon 在「监听模式」下抓取过卡片与读卡器的通信数据时 |\r\n\r\n对应 C"},{"path":"README.md","content":"# chameleon-ultra-cli\n\n一个用于 [WorkBuddy](https://www.codebuddy.cn/) 的技能（Skill），让你用大白话指挥\n[Chameleon Ultra](https://github.com/RfidResearchGroup/ChameleonUltra) 读写卡器，\n把加密 IC 卡（门禁卡、电梯卡等）复制、读取、模拟出来，全程不用自己敲命令行。\n\n## 语言 / Languages / Langues\n\n- **中文**\n  - [简体中文](#简体中文)\n  - [香港正體](#香港正體)\n  - [新加坡中文](#新加坡中文)\n- [English](#english)\n- [Français](#french)\n\n---\n\n## 简体中文\n\n### 背景介绍\n\n在国内，很多小区的物业会限制业主自由使用属于自己的门禁卡：补一张卡动辄几十上百元、\n绑定手机号、甚至规定「一张卡只能对应一个人」，本质是把本该免费提供给业主的便利变成\n持续的收费项目，情节严重的已经涉嫌恶意收费、侵占业主权益。\n\n而绝大多数业主手里的门禁卡其实是**加密的 IC 卡（MIFARE Classic 居多）**。一旦丢了或\n需要多备一张，物业就借机收费。其实，只要是你**自己小区、自己名下的卡**，复制一张备用\n完全是你个人的正当权利。\n\n问题在于：变色龙 Ultra 这类设备的官方操作依赖一个命令行程序，要在交互式界面里手敲一堆\n命令，对普通小白极不友好。为了解决这个问题，我制作了这个 Skill——把复杂的命令行交互\n封装起来，你只需要用自然语言告诉 WorkBuddy 想做什么，它就会自动完成连接、读卡、复制、\n模拟等全流程操作。\n\n> 说明：本工具仅用于复制**你本人拥有合法使用权**的卡片（自家门禁、自家电梯卡等）。\n> 请勿用于复制不属于你的、或未经授权的他人卡片。\n\n### 使用方法（小白向）\n\n**第 1 步：下载变色龙 Ultra 的命令行程序**\n\n本程序**只支持 Windows 系统**，请在 Windows 电脑上操作。\n\n- 下载地址：https://wwaxz.lanzoul.com/iar123ylt1sh\n- 提取密码：**6bm4**\n- 下载后解压，你会得到一个 `chameleon_cli_main.exe` 文件，**记住它的完整路径**\n  （例如 `C:\\tools\\chameleon\\chameleon_cli_main.exe`）。\n\n**第 2 步：安装本 Skill 到 WorkBuddy**\n\n把整个 `chameleon-ultra-cli` 文件夹放到 WorkBuddy 的用户技能目录：\n\n```\nC:\\Users\\你的用户名\\.workbuddy\\skills\\chameleon-ultra-cli\\\n```\n\n**第 3 步：告诉 Skill 程序在哪（只需一次）**\n\n打开 WorkBuddy，对助手说类似这样的话，把第 1 步记下的路径填进去：\n\n```\n请设置变色龙程序路径为 C:\\tools\\chameleon\\chameleon_cli_main.exe\n```\n\n（本质就是执行了 `python scripts/chameleon_control.py --set-exe \"你的路径\"`，\n路径会保存下来，以后不用再设。）\n\n**第 4 步：插上设备，开始用大白话指挥**\n\n用 USB 把变色龙 Ultra 连上电脑，然后直接用自然语言下指令即可，例如：\n\n- 「读一下我这张门禁卡的信息」\n- 「把这张卡复制一份到卡槽 8 里」\n- 「扫描一下这张高频卡，看看 UID 是什么」\n\nSkill 会自动连上设备、执行对应命令、把结果翻成你能看懂的话返回给你。\n\n**常用参数（进阶，可不看）**\n\n- `--timeout 秒数`：读卡 / 跑攻击比较慢时用，把等待时间调大（默认 120 秒）\n- `--file 命令.txt`：把一堆命令写进文本文件，逐行批量执行（`#` 开头是注释）\n- `--raw`：保留原始终端输出，仅在排查问题时用\n\n### 技术原理（简述）\n\n为什么不能直接用官方命令行程序？因为它是一个**交互式 REPL**（基于 prompt_toolkit），\n就像个一直在等你敲命令的小窗口——你没法简单地把命令「管道」喂给它，在 Windows 上尤其\n会直接报错。\n\n本 Skill 的解法是：\n\n1. **伪终端（PTY）包裹**：在 Windows 上用 `pywinpty`（首次运行会自动建好环境安装），\n   在 Linux / macOS 上用系统自带的 `pty` 模块，把官方程序包进一个「假终端」里，\n   这样就能像真人一样给它下发命令、并可靠地读回输出。\n2. **自动会话管理**：每次调用都会自动先发 `hw connect` 连设备、最后发 `exit` 退出，\n   保证每次都是干净、能自己结束的独立会话。\n3. **踩过的关键坑**（已自动处理，你无需关心）：\n   - 换行符必须用 `LF(\\n)`，用回车 `\\r` 会被当成补全触发；\n   - 程序启动会发终端能力查询并等应答才显示提示符，Skill 会自动回写应答，\n     否则它会「卡死」、什么都不输出。\n\n### 致谢\n\n本 Skill 建立在变色龙 Ultra 开源项目的成果之上，衷心感谢原作者的无私开源：\n\n**RfidResearchGroup / ChameleonUltra**\nhttps://github.com/RfidResearchGroup/ChameleonUltra\n\n没有这个优秀的开源硬件与固件，普通用户根本无法低成本地拿回本就属于自己那张卡的控制权。\n\n---\n\n## 香港正體\n\n### 背景介紹\n\n在國內，很多小區的物業會限制業主自由使用屬於自己的門禁卡：補一張卡動輒幾十上百元、\n綁定手機號、甚至規定「一張卡只能對應一個人」，本質是把本該免費提供給業主的便利變成\n持續的收費項目，情節嚴重的已經涉嫌惡意收費、侵占業主權益。\n\n而絕大多數業主手裡的門禁卡其實是**加密的 IC 卡（MIFARE Classic 居多）**。一旦掉了或\n需要多備一張，物業就藉機收費。其實，只要是你**自己小區、自己名下的卡**，複製一張備用\n完全是你個人的正當權利。\n\n問題在於：變色龍 Ultra 這類設備的官方操作依賴一個命令列程式，要在互動式介面裡手敲一堆\n命令，對普通小白極不友善。為了解決這個問題，我製作了這個 Skill——把複雜的命令列互動\n封裝起來，你只需要用自然語言告訴 WorkBuddy 想做什麼，它就會自動完成連接、讀卡、複製、\n模擬等全流程操作。\n\n> 說明：本工具僅用於複製**你本人擁有合法使用權**的卡片（自家門禁、自家電梯卡等）。\n> 請勿用於複製不屬於你的、或未經授權的他人卡片。\n\n### 使用方法（小白向）\n\n**第 1 步：下載變色龍 Ultra 的命令列程式**\n\n本程式**只支援 Windows 系統**，請在 Windows 電"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71cn3h6s4p3eq2qpvbnxq1k98b1r7b\",\n  \"slug\": \"chameleon-ultra-cli-skill\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1784993095695\n}"},{"path":"references/cli_reference.md","content":"# Chameleon Ultra CLI 命令参考 (chameleon_cli_main)\n\n本参考整理自 RfidResearchGroup/ChameleonUltra 官方命令树（docs/cli.md、chameleon_cli_unit.py）。\nchameleon_cli_main 是一个**交互式 REPL**，按功能分区组织命令：\n\n- hw  —— 设备本身（连接、模式、版本、设置、卡槽）\n- hf  —— 高频 / NFC（13.56MHz），如 ISO14443-A、MIFARE Classic\n- lf  —— 低频 / 125kHz，如 EM410x、HID\n\n通用提示\n- 任何层级都可以加 -h / --help 查看该组命令与参数，例如 hw -h、hf mf -h、hw slot -h。\n- 不同固件版本命令略有差异；以设备实际 *-h 输出为准。\n- 本 skill 的 chameleon_control.py 会自动在每条命令前补 hw connect（除非 --no-connect），并在末尾补 exit。\n- 需要等待卡片的命令（如 hf 14a scan、hf mf nested）可能耗时数秒到数十秒，可用 --timeout 调整上限。\n\n---\n\n## 根命令（REPL 控制）\n\n| 命令 | 说明 |\n|------|------|\n| clear | 清屏 |\n| rem (text) | 在输出中插入带时间戳的注释 |\n| exit / quit / q | 退出 CLI 并断开设备 |\n| dump_help | 列出所有命令（-d 显示描述，-g 按分组） |\n\n---\n\n## hw —— 设备控制\n\n| 命令 | 参数 | 说明 |\n|------|------|------|\n| hw connect | -p PORT | 连接设备；自动检测失败时用 -p COM11（Windows）或 -p /dev/ttyACM0（Linux） |\n| hw disconnect | — | 断开连接 |\n| hw mode | -r(reader) / -e(emulator) | 获取 / 切换设备模式（读卡器 / 模拟器） |\n| hw chipid | — | 读取芯片 ID |\n| hw address | — | 读取蓝牙地址 |\n| hw version | — | 读取固件版本与型号 |\n| hw settings animation | -m (NONE\\|MINIMAL\\|...) | 设置 LED 动画（NONE 最隐蔽） |\n| hw settings blekey | -k (key) | 修改 BLE 配对密钥（默认 12345，强烈建议修改） |\n| hw settings | -h | 查看全部设备设置子命令 |\n\n---\n\n## hw slot —— 卡槽管理（最多 8 个，每个含 HF + LF）\n\n| 命令 | 参数 | 说明 |\n|------|------|------|\n| hw slot list | — | 列出所有卡槽及状态 |\n| hw slot type | -s (slot) -t (type) | 设置卡槽类型，如 MIFARE_1024 |\n| hw slot init | -s (slot) -t (type) | 用指定类型的默认内容初始化卡槽 |\n| hw slot enable | -s (slot) --hf / --lf | 启用某卡槽的 HF 或 LF 模拟 |\n| hw slot disable | -s (slot) --hf / --lf | 禁用某卡槽的 HF 或 LF 模拟 |\n| hw slot change | -s (slot) | 切换到指定卡槽（设为当前激活槽） |\n| hw slot | -h | 查看其余子命令（nickname、delete 等） |\n\n典型模拟流程（MFKEY32v2 示例）\n```\nhw connect\nhw slot list\nhw slot type   -s 8 -t MIFARE_1024\nhw slot init   -s 8 -t MIFARE_1024\nhw slot enable -s 8 --hf\nhw slot change -s 8\nhf mf econfig --enable-log\n# 断开，去读卡器上刷几次卡，再连回：\nhw connect\nhf mf elog\nhf mf elog --decrypt\nhf mf econfig --disable-log\n```\n\n---\n\n## hf —— 高频 / NFC（13.56MHz）\n\n### hf 14a —— ISO14443-A\n\n| 命令 | 说明 |\n|------|------|\n| hf 14a scan | 扫描 14a 标签，显示 UID / ATQA / SAK |\n| hf 14a info | 扫描并做详细分析（猜测卡片类型、PRNG 强度等） |\n| hf 14a | -h 查看读卡、raw 等子命令 |\n\n### hf mf —— MIFARE Classic 攻击 / 操作\n\n| 命令 | 参数 | 说明 |\n|------|------|------|\n| hf mf nested | --blk BLOCK -k KEY [--tblk TBLOCK] [-a\\|-b] [--ta\\|-tb] | Nested 攻击恢复密钥 |\n| hf mf darkside | — | Darkside 攻击（0 扇区） |\n| hf mf hardnested | --blk BLOCK -k KEY [--tblk TBLOCK] [--slow] [--keep-nonce-file] | HardNested 攻击（硬 PRNG） |\n| hf mf elog | [--decrypt] | 查看 / 解密模拟器采集到的认证 nonce 日志 |\n| hf mf econfig | --enable-log / --disable-log | 开启 / 关闭模拟器认证日志 |\n| hf mf eload | (file) | 将 dump 文件载入当前模拟卡槽 |\n| hf mf esave | (file) | 将当前模拟卡槽保存为 dump 文件 |\n| hf mf chk | -k (keys) | 用给定密钥批量检测扇区 |\n| hf mf rdbl / hf mf wrbl | 块读写（需先认证） | 读取 / 写入指定块 |\n| hf mf | -h 查看全部子命令（cget/cset 等） |\n\n---\n\n## lf —— 低频 / 125kHz\n\n### lf em 410x —— EM4100/EM410x（ID 卡）\n\n| 命令 | 参数 | 说明 |\n|------|------|------|\n| lf em 410x scan | — | 扫描 EM410x 标签，显示 ID |\n| "},{"path":"skill-card.md","content":"## Description:\n\nControls Chameleon Ultra RFID hardware through the chameleon_cli_main command-line program for device connection, HF/LF card scanning, MIFARE Classic workflows, slot management, dump handling, and device settings.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[georgechou17](https://clawhub.ai/user/georgechou17)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and authorized Chameleon Ultra users use this skill to translate natural-language requests into CLI commands for reading, scanning, emulating, and managing RFID card workflows on hardware they are permitted to operate.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill can run card-cloning, emulation, BLE key changes, and MIFARE attack commands against RFID hardware.\n\nMitigation: Install and use it only when authorized to operate the target cards and readers, and require explicit confirmation before cloning, writing, emulating, changing BLE keys, or running attack commands.\n\nRisk: The setup path references a third-party executable download for chameleon_cli_main.\n\nMitigation: Replace that download with an official, verified ChameleonUltra release and check hashes or signatures before running the configured executable.\n\nRisk: The Windows helper may install pywinpty at runtime if the dependency is missing.\n\nMitigation: Avoid unpinned runtime package installation where possible by preinstalling reviewed dependencies from trusted package indexes or pinned artifacts.\n\n## Reference(s):\n\n- [Server-resolved GitHub import](https://github.com/GeorgeChou17/chameleon-ultra-cli-skill)\n- [Chameleon Ultra CLI command reference](references/cli_reference.md)\n- [RfidResearchGroup ChameleonUltra](https://github.com/RfidResearchGroup/ChameleonUltra)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and summarized device output]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May include captured Chameleon CLI output; commands require a configured chameleon_cli_main executable and connected hardware.]\n\n## Skill Version(s):\n\n0.1.0 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"控制变色龙(Chameleon)Ultra 读写卡器，通过其 chameleon_cli_main 命令行程序操作设备。当用户想用命令行操作 Chameleon Ultra 设备时使用本技能：连接设备、扫描/读取高频(HF/NFC)或低频(LF)卡片、运行 MIFARE Classic 攻击(nested/darkside/hardnested)、管理模拟卡槽、载入/保存 dump、修改设备设置，或自动化任意 chameleon_cli_main 命令。本技能以非交互方式驱动交互式 REPL，并在首次配置后持久保存可执行文件路径。 Skill: Chameleon Ultra Cli Owner: georgechou17 Summary: 控制变色龙(Chameleon)Ultra 读写卡器，通过其 chameleon_cli_main 命令行程序操作设备。当用户想用命令行操作 Chameleon Ultra 设备时使用本技能：连接设备、扫描/读取高频(HF/NFC)或低频(LF)卡片、运行 MIFARE Classic 攻击(nested/darkside/hardnested)、管理模拟卡槽、载入/保存 dump、修改设备设置，或自动化任意 chameleon_cli_main 命令。本技能以非交互方式驱动交互式 REPL，并在首次配置后持久保存可执行文件路径。 Tags: latest:0.1.0 Version history: v0.1.0 | 2026-07-25T15:24:55.695Z | auto Initial release of","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1244,"uniquenessScore":47,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T09:07:20.076Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T09:07:20.076Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:14:55.266Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}