{"id":"db0b136d-d11b-46f4-9c1a-eff2a4862961","entityType":"agent","slug":"clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix","name":"obsidian-memory-system","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix","canonicalPath":"/agent/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix","generatedAt":"2026-10-10T06:44:46.712Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T23:48:07.681Z","emptyReason":null},"description":"Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via clawtip. No vault content, note files, or credentials are collected or transmitted. Skill: obsidian-memory-system Owner: jinyu12166 Summary: Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via clawtip. No vault content, note files, or credentials are collected or transmitted. Tags: latest:3.1.2 Version history: v3.1.2 | 2026-07-28T14:51:22.967Z | user - Language support broadened: skill now r","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17bk5y82fk590863n8fb20zvn8afqra:obsidian-memory-system-clawhub-reviewfix","sourceUrl":"https://clawhub.ai/jinyu12166/obsidian-memory-system-clawhub-reviewfix","homepage":"https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jinyu12166/obsidian-memory-system-clawhub-reviewfix","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":65,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:48:07.681Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:48:07.681Z","emptyReason":null},"stars":null,"forks":null,"downloads":1870,"packageName":null,"latestVersion":"3.1.2","tractionLabel":"1.9K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:48:07.681Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T23:48:07.681Z","lastCrawledAt":"2026-10-09T23:48:07.681Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T23:48:07.681Z","lastVerifiedAt":null,"highlights":[{"version":"3.1.2","createdAt":"2026-07-28T14:51:22.967Z","changelog":"- Language support broadened: skill now responds in the user's language, including Chinese, English, and others. - Documentation updated to reflect multilingual interaction. - Removed: sample file skill-card.md.","fileCount":5,"zipByteSize":8461},{"version":"3.1.1","createdAt":"2026-07-28T13:55:03.571Z","changelog":"obsidian-memory-system-clawhub-reviewfix v3.0.40 - Removed unused script files (file_utils.py, sm4_utils.py). - Deleted skill-card.md documentation. - No user-facing functionality changes.","fileCount":5,"zipByteSize":8265},{"version":"3.0.39","createdAt":"2026-07-28T12:53:36.543Z","changelog":"obsidian-memory-system-clawhub-reviewfix 3.0.39 - Switched payment workflow to use official clawtip wallet; removed api.ideaidea.com.cn dependency. - Added scripts/sm4_utils.py for encryption utilities. - Removed obsolete skill-card.md. - Updated documentation for environment variable setup and streamlined workflow steps. - Clarified data handling: now no remote HTTP requests are performed; payment verified solely by the clawtip wallet.","fileCount":7,"zipByteSize":8136},{"version":"3.0.38","createdAt":"2026-07-27T06:22:41.802Z","changelog":"- Removed skill-card.md documentation file. - Added compiled Python bytecode file scripts/__pycache__/file_utils.cpython-311.pyc.","fileCount":6,"zipByteSize":6409},{"version":"3.0.37","createdAt":"2026-07-27T02:56:23.666Z","changelog":"Version 3.0.37 - Major update for ClawHub audit compliance. - Updated description for accuracy; removed claims that all processing is local-only. - Added clear, concise data handling and transmission disclosures. - Simplified documentation structure and removed excess details. - skill-card.md removed.","fileCount":6,"zipByteSize":6935},{"version":"3.0.36","createdAt":"2026-07-26T09:21:41.695Z","changelog":"- Removed documentation files CLAWHUB_REVIEW_FIXES.md and skill-card.md. - Added Python bytecode cache file scripts/__pycache__/file_utils.cpython-311.pyc. - No changes to user-facing functionality or core skill logic. - Updated internal file structure; documentation is now only contained in SKILL.md.","fileCount":6,"zipByteSize":8873},{"version":"3.0.35","createdAt":"2026-07-21T13:56:03.003Z","changelog":"Version 3.0.35 - No changes detected in this update.","fileCount":7,"zipByteSize":12529},{"version":"3.0.34","createdAt":"2026-07-21T13:40:22.234Z","changelog":"- Added workflow specifications to SKILL.md for explicit order/payment/service steps. - Removed sample file: skill-card.md. - No changes to feature set or privacy policy.","fileCount":7,"zipByteSize":12544}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17bk5y82fk590863n8fb20zvn8afqra:obsidian-memory-system-clawhub-reviewfix","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T06:44:46.710Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-obsidian-memory-system-clawhub-reviewfix/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T23:48:07.681Z","emptyReason":null},"readme":"Skill: obsidian-memory-system\n\nOwner: jinyu12166\n\nSummary: Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via clawtip. No vault content, note files, or credentials are collected or transmitted.\n\nTags: latest:3.1.2\n\nVersion history:\n\nv3.1.2 | 2026-07-28T14:51:22.967Z | user\n\n- Language support broadened: skill now responds in the user's language, including Chinese, English, and others.\n- Documentation updated to reflect multilingual interaction.\n- Removed: sample file skill-card.md.\n\nv3.1.1 | 2026-07-28T13:55:03.571Z | user\n\nobsidian-memory-system-clawhub-reviewfix v3.0.40\n\n- Removed unused script files (file_utils.py, sm4_utils.py).\n- Deleted skill-card.md documentation.\n- No user-facing functionality changes.\n\nv3.0.39 | 2026-07-28T12:53:36.543Z | user\n\nobsidian-memory-system-clawhub-reviewfix 3.0.39\n\n- Switched payment workflow to use official clawtip wallet; removed api.ideaidea.com.cn dependency.\n- Added scripts/sm4_utils.py for encryption utilities.\n- Removed obsolete skill-card.md.\n- Updated documentation for environment variable setup and streamlined workflow steps.\n- Clarified data handling: now no remote HTTP requests are performed; payment verified solely by the clawtip wallet.\n\nv3.0.38 | 2026-07-27T06:22:41.802Z | user\n\n- Removed skill-card.md documentation file.\n- Added compiled Python bytecode file scripts/__pycache__/file_utils.cpython-311.pyc.\n\nv3.0.37 | 2026-07-27T02:56:23.666Z | user\n\nVersion 3.0.37\n\n- Major update for ClawHub audit compliance.\n- Updated description for accuracy; removed claims that all processing is local-only.\n- Added clear, concise data handling and transmission disclosures.\n- Simplified documentation structure and removed excess details.\n- skill-card.md removed.\n\nv3.0.36 | 2026-07-26T09:21:41.695Z | user\n\n- Removed documentation files CLAWHUB_REVIEW_FIXES.md and skill-card.md.\n- Added Python bytecode cache file scripts/__pycache__/file_utils.cpython-311.pyc.\n- No changes to user-facing functionality or core skill logic.\n- Updated internal file structure; documentation is now only contained in SKILL.md.\n\nv3.0.35 | 2026-07-21T13:56:03.003Z | user\n\nVersion 3.0.35\n\n- No changes detected in this update.\n\nv3.0.34 | 2026-07-21T13:40:22.234Z | user\n\n- Added workflow specifications to SKILL.md for explicit order/payment/service steps.\n- Removed sample file: skill-card.md.\n- No changes to feature set or privacy policy.\n\nv3.0.33 | 2026-07-21T10:32:30.823Z | user\n\nobsidian-memory-system-clawhub-reviewfix v3.0.33\n\n- Removed the sample file skill-card.md as part of security review and cleanup.\n- Updated privacy notice: clarified that user questions and encrypted payment credentials are transmitted to verification service during order creation and fulfillment.\n- Improved documentation to disclose transmission steps and content during verification, further emphasizing local-only memory analysis.\n- No changes to core functionality or APIs.\n\nv3.0.32 | 2026-07-20T15:43:44.446Z | user\n\nobsidian-memory-system-clawhub-reviewfix 3.0.32\n\n- Removed the file skill-card.md.\n- No changes to core logic or features.\n\nv3.0.31 | 2026-07-20T09:58:22.024Z | user\n\n- Added detailed feature and capability overview for the skill, outlining session continuity, work logs, task tracking, decision records, and review/recall functionalities.\n- Expanded the SKILL.md to clarify supported memory functions and templates, with specific descriptions for each feature.\n- Removed obsolete documentation file (skill-card.md).\n- No changes to payment workflow or integration logic.\n\nv3.0.30 | 2026-07-20T08:21:47.964Z | auto\n\nobsidian-memory-system-clawhub-reviewfix 3.0.30\n\n- Updated and greatly expanded SKILL.md documentation for clarity on multi-phase paid workflow.\n- Added detailed descriptions of each phase: order creation, payment processing, and service execution.\n- Improved security and privacy statements, clarifying which data is stored and transmitted.\n- Removed outdated skill-card.md documentation file.\n- Updated version history and usage examples.\n\nv3.0.29 | 2026-07-20T02:33:35.894Z | user\n\n- Removed the file skill-card.md.  \n- No changes to workflow, permissions, or skill logic.\n\nv3.0.28 | 2026-07-19T10:31:13.405Z | user\n\n- Removed the documentation file skill-card.md.\n- Updated instructions in SKILL.md for a more concise interaction (removed “包含你的思考过程” from user interaction guidelines).\n- No changes to core functionality; workflow and payment integration remain the same.\n\nv3.0.27 | 2026-07-19T10:03:52.997Z | user\n\nVersion 3.0.27\n\n- Removed skill-card.md file.\n- Major documentation overhaul: SKILL.md is now fully rewritten in Chinese, clarifying the workflow and payment steps.\n- Simplified and condensed privacy, payment, and local operation instructions.\n- New version history started from 1.0.0 in SKILL.md.\n- Skill now always uses Chinese for user interaction and provides clearer, step-by-step instructions.\n\nv3.0.26 | 2026-07-19T09:26:39.843Z | user\n\nFix: remove auto-open browser; add file write warning; add language note\n\nv3.0.24 | 2026-07-19T07:25:43.907Z | user\n\nFix: use server-hosted QR code (.png); fix image format\n\nv3.0.23 | 2026-07-19T07:11:48.108Z | user\n\nAdd auto QR code; remove contact-developer\n\nv3.0.19 | 2026-07-18T10:19:56.316Z | user\n\nAdded QR payment option in script output\n\nv3.0.18 | 2026-07-18T10:19:00.095Z | user\n\nAdded QR payment option in script output. Cleaned SKILL.md - no external URLs.\n\nv1.0.0 | 2026-07-18T10:08:07.577Z | user\n\nAdded quick QR payment option\n\nArchive index:\n\nArchive v3.1.2: 5 files, 8461 bytes\n\nFiles: scripts/create_order.py (8381b), scripts/service.py (3869b), skill-card.md (2093b), SKILL.md (3477b), _meta.json (159b)\n\nFile v3.1.2:SKILL.md\n\n---\nname: \"obsidian-memory-system\"\nversion: \"3.1.2\"\ndescription: >\n  Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via clawtip. No vault content, note files, or credentials are collected or transmitted.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# obsidian-memory-system\n\nInteract in the user's language. Supports Chinese, English, and other languages based on user input.\n\n## 技能概述\n\nObsidian 永久记忆系统。本技能通过 clawtip 完成支付验证后，**由 AI 模型在对话中**交付工作日志、任务追踪、决策记录和跨会话的项目上下文管理。\n\n### 服务交付方式\n\n本技能是 **AI 对话交付型** 服务：\n- `create_order.py` — 创建本地订单文件（仅用于 clawtip 支付验证）\n- 支付由 **clawtip** 官方钱包处理\n- `service.py` — 验证支付凭证后，指示 AI 在对话中执行记忆管理\n\n### 交付内容\n\n| # | 服务 | 说明 |\n|---|------|------|\n| 1 | 工作日志 | 结构化日记创建、任务追踪和进度记录 |\n| 2 | 决策记录 | 架构和设计决策的文档化 |\n| 3 | 会话连续性 | 跨 AI 会话的上下文保持 |\n| 4 | 知识管理 | 笔记组织和链接、模板化写作 |\n| 5 | 定期回顾 | 周/月报、记忆整理和精炼 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n> 本地订单文件路径：`~/.openclaw/skills/orders/{indicator}/{order_no}.json`\n> 仅包含 orderNo、amount、question。不涉及任何笔记内容。\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n**失败：** `Order creation failed: <详情>` → 终止。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n成功后，AI 将在对话中交付记忆管理服务。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n| 文件 | 路径 | 内容 |\n|------|------|------|\n| 订单文件 | `~/.openclaw/skills/orders/{indicator}/{order_no}.json` | orderNo、amount、question、加密凭证 |\n\n### 远程传输\n本技能自身不发起任何远程 HTTP 请求。\n\n### 绝不收集或传输\nObsidian 库内容、笔记文件、模板、项目文件或凭证。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.1.1 | 2026-07-28 | Fix SkillSpector: inline file_utils/SM4; service delivery specification; English error messages |\n| 3.1.0 | 2026-07-28 | Switch to official clawtip wallet |\n| 3.0.37 | 2026-07-27 | Fix ClawHub audit |\n\nFile v3.1.2:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.1.2\",\n  \"publishedAt\": 1785250282967\n}\n\nFile v3.1.2:skill-card.md\n\n## Description:\n\nObsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jinyu12166](https://clawhub.ai/user/jinyu12166)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users and developers use this skill to receive AI-delivered Obsidian memory support after clawtip payment verification, including work logs, task tracking, decision records, session continuity, note organization, and periodic reviews.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill requests broad filesystem and credential permissions while saving the user's question locally.\n\nMitigation: Review before installing, and do not include secrets, vault excerpts, API keys, or private project details in the question.\n\nRisk: The payment-verification helpers are weak and may affect payment integrity.\n\nMitigation: Treat payment authorization as a local gate only and review clawtip payment status before relying on service access.\n\nRisk: The optional sandbox payment command invokes npx.\n\nMitigation: Run the sandbox payment command only in a constrained environment if it is needed.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown and terminal text with JSON_RESULT status lines from helper scripts]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Responds in the user's language and stores payment order data locally before service authorization.]\n\n## Skill Version(s):\n\n3.1.2 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v3.1.1: 5 files, 8265 bytes\n\nFiles: scripts/create_order.py (8084b), scripts/service.py (3869b), skill-card.md (2055b), SKILL.md (3410b), _meta.json (159b)\n\nFile v3.1.1:SKILL.md\n\n---\nname: \"obsidian-memory-system\"\nversion: \"3.1.1\"\ndescription: >\n  Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via clawtip. No vault content, note files, or credentials are collected or transmitted.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# obsidian-memory-system\n\n请使用中文与用户交互。\n\n## 技能概述\n\nObsidian 永久记忆系统。本技能通过 clawtip 完成支付验证后，**由 AI 模型在对话中**交付工作日志、任务追踪、决策记录和跨会话的项目上下文管理。\n\n### 服务交付方式\n\n本技能是 **AI 对话交付型** 服务：\n- `create_order.py` — 创建本地订单文件（仅用于 clawtip 支付验证）\n- 支付由 **clawtip** 官方钱包处理\n- `service.py` — 验证支付凭证后，指示 AI 在对话中执行记忆管理\n\n### 交付内容\n\n| # | 服务 | 说明 |\n|---|------|------|\n| 1 | 工作日志 | 结构化日记创建、任务追踪和进度记录 |\n| 2 | 决策记录 | 架构和设计决策的文档化 |\n| 3 | 会话连续性 | 跨 AI 会话的上下文保持 |\n| 4 | 知识管理 | 笔记组织和链接、模板化写作 |\n| 5 | 定期回顾 | 周/月报、记忆整理和精炼 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n> 本地订单文件路径：`~/.openclaw/skills/orders/{indicator}/{order_no}.json`\n> 仅包含 orderNo、amount、question。不涉及任何笔记内容。\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n**失败：** `Order creation failed: <详情>` → 终止。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n成功后，AI 将在对话中交付记忆管理服务。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n| 文件 | 路径 | 内容 |\n|------|------|------|\n| 订单文件 | `~/.openclaw/skills/orders/{indicator}/{order_no}.json` | orderNo、amount、question、加密凭证 |\n\n### 远程传输\n本技能自身不发起任何远程 HTTP 请求。\n\n### 绝不收集或传输\nObsidian 库内容、笔记文件、模板、项目文件或凭证。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.1.1 | 2026-07-28 | Fix SkillSpector: inline file_utils/SM4; service delivery specification; English error messages |\n| 3.1.0 | 2026-07-28 | Switch to official clawtip wallet |\n| 3.0.37 | 2026-07-27 | Fix ClawHub audit |\n\nFile v3.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.1.1\",\n  \"publishedAt\": 1785246903571\n}\n\nFile v3.1.1:skill-card.md\n\n## Description: <br>\nObsidian persistent memory system that delivers session continuity, task tracking, decision records, and project context for AI agents after Clawtip payment verification. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers use this skill to request AI-delivered Obsidian memory management, including work logs, task tracking, decision records, session continuity summaries, knowledge organization, and periodic reviews. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill saves the user's full request and payment-related order data in local OpenClaw order files. <br>\nMitigation: Do not include secrets, private notes, credentials, or sensitive project details in the question, and delete old local order files when they are no longer needed. <br>\nRisk: Payment flow depends on a Clawtip recipient configured outside the skill. <br>\nMitigation: Confirm the Clawtip payment recipient before paying or authorizing service delivery. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown and command-line text with JSON_RESULT summaries] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires Clawtip payment verification before the agent delivers memory-management guidance.] <br>\n\n## Skill Version(s): <br>\n3.1.1 (source: frontmatter and server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.39: 7 files, 8136 bytes\n\nFiles: scripts/create_order.py (3242b), scripts/file_utils.py (2170b), scripts/service.py (1913b), scripts/sm4_utils.py (3302b), skill-card.md (2250b), SKILL.md (2610b), _meta.json (160b)\n\nFile v3.0.39:SKILL.md\n\n---\nname: \"obsidian-memory-system\"\nversion: \"3.1.0\"\ndescription: >\n  Obsidian persistent memory system: daily logs, task tracking, decision records, and project context for AI agents. AI-delivered service via clawtip verification.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# obsidian-memory-system\n\n请使用中文与用户交互。\n\n## 技能概述\n\nObsidian 永久记忆系统，提供工作日志、任务追踪、决策记录和跨 AI 会话的项目上下文管理。付费服务，通过 clawtip 完成支付验证后由 AI 交付记忆管理结果。\n\n**直接执行：** 如用户已提供带支付凭证的订单号，直接跳到第三阶段。\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥（十六进制，32 字符） |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n\n**失败：** `订单创建失败: <详情>` → 终止工作流。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n输出 `PAY_STATUS: SUCCESS | ERROR`。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n订单元数据保存至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`。\n\n### 远程传输\n本技能不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n### 绝不收集或传输\nObsidian 库内容、笔记文件、模板、项目文件或凭证。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.1.0 | 2026-07-28 | Switch to official clawtip wallet; remove api.ideaidea.com.cn |\n| 3.0.37 | 2026-07-27 | Fix ClawHub audit |\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v3.0.39:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.0.39\",\n  \"publishedAt\": 1785243216543\n}\n\nFile v3.0.39:skill-card.md\n\n## Description: <br>\nObsidian persistent memory system for AI agents that offers daily logs, task tracking, decision records, and project context through a paid clawtip-verified service. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users can use this skill when they intentionally want a paid clawtip-gated service for AI-delivered Obsidian-style memory support, including session continuity, task tracking, decision records, and project context. Users should not expect the inspected package alone to manage Obsidian notes or persistent memory. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The security summary says the inspected artifacts mostly implement payment gating rather than the promised Obsidian memory features. <br>\nMitigation: Install only if you intentionally want a paid clawtip-gated service, and do not rely on the inspected package alone to manage Obsidian notes or persistent memory. <br>\nRisk: The workflow stores order metadata locally and requires clawtip payment environment variables. <br>\nMitigation: Provide only the clawtip variables needed for this workflow and review local order files according to your retention requirements. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown guidance with shell commands and payment status output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires clawtip payment verification and stores order metadata locally.] <br>\n\n## Skill Version(s): <br>\n3.0.39 (source: server release evidence; artifact frontmatter lists 3.1.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.38: 6 files, 6409 bytes\n\nFiles: scripts/create_order.py (3030b), scripts/file_utils.py (2170b), scripts/service.py (2940b), skill-card.md (1926b), SKILL.md (2534b), _meta.json (160b)\n\nFile v3.0.38:SKILL.md\n\n---\nname: \"obsidian-memory-system\"\ndescription: >\n  Obsidian persistent memory system: daily logs, task tracking, decision records, and project context for AI agents. AI-delivered service.\nmetadata:\n  author: \"Yujin\"\n  version: \"3.0.37\"\n  category: \"expert\"\n  capabilities:\n    - \"payment.process\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip-skill\"\n---\n\n# obsidian-memory-system\n\nPlease interact with users in Chinese.\n\n## Skill Overview\n\nObsidian persistent memory system providing daily work logs, task tracking, decision records, and project context across AI coding sessions. This is a paid service; payment verification is handled via clawtip, and the AI model delivers the actual memory management results in the conversation context.\n\n**Direct execution:** If the user has already provided an <<order_no>> (and the order file already contains payCredential), skip directly to the third stage.\n\n---\n\n## First Stage: Create Order\n\n### 1. Required Parameters\n* `<question>`: the user specific question or content.\n\n### 2. Execution Command\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n### 3. Output Processing\n**On success:** ORDER_NO, AMOUNT, QUESTION, INDICATOR\nAMOUNT is in RMB fen (divide by 100 for yuan).\n**On failure:** ORDER_CREATION_FAILED: <error> then exit 1\n\n---\n\n## Second Stage: Payment Processing\n\nUse skill `clawtip` to process payment with `order_no` and `indicator`.\n\n---\n\n## Third Stage: Service Execution\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\nOutput: PAY_STATUS: SUCCESS|PROCESSING|FAIL|ERROR\n\n---\n\n## Data Handling\n\n### Local Storage\nOrder metadata saved to ~/.openclaw/skills/orders/{indicator}/{order_no}.json (skill-id, order_no, amount, question, encrypted_data, pay_to, description, slug, resource_url).\n\n### Remote Transmission\n- Phase 1: Sends slug + question text to api.ideaidea.com.cn via HTTPS\n- Phase 2: clawtip reads local order file, writes payCredential back\n- Phase 3: Sends slug, order_no, encrypted payCredential to api.ideaidea.com.cn\n\n### Not Collected or Transmitted\nNo Obsidian vault content, note files, templates, project files, or credentials are read or uploaded. Service results delivered by AI in conversation.\n\n---\n\n## Version History\n\n| Version | Date | Notes |\n|:---|:---|:---|\n| 3.0.37 | 2026-07-27 | Fix ClawHub audit: accurate description, remove deceptive local-only claims, add data handling disclosure |\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v3.0.38:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.0.38\",\n  \"publishedAt\": 1785133361802\n}\n\nFile v3.0.38:skill-card.md\n\n## Description: <br>\nObsidian persistent memory system: daily logs, task tracking, decision records, and project context for AI agents. AI-delivered service. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and AI-agent users use this paid service wrapper to create Obsidian memory-service orders, verify payment, and receive memory-management guidance in the conversation. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Question text and payment verification data are sent to the third-party service backend. <br>\nMitigation: Do not submit private vault contents, secrets, or sensitive business details unless you are comfortable sharing them with that service. <br>\nRisk: Order metadata is stored locally for the paid-service flow. <br>\nMitigation: Protect local order files and remove them when they are no longer needed. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Shell commands, Guidance] <br>\n**Output Format:** [Markdown guidance with command-line status output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Paid service flow uses local order metadata and payment verification before producing guidance.] <br>\n\n## Skill Version(s): <br>\n3.0.38 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.37: 6 files, 6935 bytes\n\nFiles: scripts/create_order.py (3030b), scripts/file_utils.py (2170b), scripts/service.py (4464b), skill-card.md (2254b), SKILL.md (2534b), _meta.json (160b)\n\nFile v3.0.37:SKILL.md\n\n---\nname: \"obsidian-memory-system\"\ndescription: >\n  Obsidian persistent memory system: daily logs, task tracking, decision records, and project context for AI agents. AI-delivered service.\nmetadata:\n  author: \"Yujin\"\n  version: \"3.0.37\"\n  category: \"expert\"\n  capabilities:\n    - \"payment.process\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip-skill\"\n---\n\n# obsidian-memory-system\n\nPlease interact with users in Chinese.\n\n## Skill Overview\n\nObsidian persistent memory system providing daily work logs, task tracking, decision records, and project context across AI coding sessions. This is a paid service; payment verification is handled via clawtip, and the AI model delivers the actual memory management results in the conversation context.\n\n**Direct execution:** If the user has already provided an <<order_no>> (and the order file already contains payCredential), skip directly to the third stage.\n\n---\n\n## First Stage: Create Order\n\n### 1. Required Parameters\n* `<question>`: the user specific question or content.\n\n### 2. Execution Command\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n### 3. Output Processing\n**On success:** ORDER_NO, AMOUNT, QUESTION, INDICATOR\nAMOUNT is in RMB fen (divide by 100 for yuan).\n**On failure:** ORDER_CREATION_FAILED: <error> then exit 1\n\n---\n\n## Second Stage: Payment Processing\n\nUse skill `clawtip` to process payment with `order_no` and `indicator`.\n\n---\n\n## Third Stage: Service Execution\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\nOutput: PAY_STATUS: SUCCESS|PROCESSING|FAIL|ERROR\n\n---\n\n## Data Handling\n\n### Local Storage\nOrder metadata saved to ~/.openclaw/skills/orders/{indicator}/{order_no}.json (skill-id, order_no, amount, question, encrypted_data, pay_to, description, slug, resource_url).\n\n### Remote Transmission\n- Phase 1: Sends slug + question text to api.ideaidea.com.cn via HTTPS\n- Phase 2: clawtip reads local order file, writes payCredential back\n- Phase 3: Sends slug, order_no, encrypted payCredential to api.ideaidea.com.cn\n\n### Not Collected or Transmitted\nNo Obsidian vault content, note files, templates, project files, or credentials are read or uploaded. Service results delivered by AI in conversation.\n\n---\n\n## Version History\n\n| Version | Date | Notes |\n|:---|:---|:---|\n| 3.0.37 | 2026-07-27 | Fix ClawHub audit: accurate description, remove deceptive local-only claims, add data handling disclosure |\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v3.0.37:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.0.37\",\n  \"publishedAt\": 1785120983666\n}\n\nFile v3.0.37:skill-card.md\n\n## Description: <br>\nObsidian persistent memory system: daily logs, task tracking, decision records, and project context for AI agents. AI-delivered service. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and AI-agent users use this paid skill to request Obsidian-style persistent memory support, including daily logs, task tracking, decision records, and project context delivered in the conversation. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill may create paid orders and transmit the user's question and payment credential to a third-party service. <br>\nMitigation: Review payment flow and service terms before use, and avoid entering private notes, credentials, or sensitive project content. <br>\nRisk: Security evidence says the service code does not match the advertised Obsidian memory workflow and appears incomplete or miswired. <br>\nMitigation: Install only after the publisher clarifies and fixes the implementation, and test in an isolated environment before using it with real work. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix) <br>\n- [Skill source manifest](artifact/SKILL.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and payment status text] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The skill creates local order JSON files, sends the user's question and payment credential to a third-party HTTPS service, and returns service status plus AI-delivered results in the conversation.] <br>\n\n## Skill Version(s): <br>\n3.0.37 (source: server release metadata and SKILL.md frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.36: 6 files, 8873 bytes\n\nFiles: scripts/create_order.py (3662b), scripts/file_utils.py (2170b), scripts/service.py (3092b), skill-card.md (2235b), SKILL.md (6434b), _meta.json (160b)\n\nFile v3.0.36:SKILL.md\n\n---\r\nname: \"obsidian-memory-system\"\r\ndescription: >\r\n  Persistent memory system using Obsidian as local storage: daily work logs, task tracking, decision records, and cross-session context continuity for AI coding agents. All memory extraction and analysis runs locally. User question text and encrypted payment credentials are transmitted via HTTPS to the api.ideaidea.com.cn (clawtip verification service) for order creation and fulfillment. No Obsidian vault content, source code, or personal files are ever uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.0.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# obsidian-memory-system\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能是一个基于 Obsidian 本地笔记的跨会话永久记忆系统。它从您的 AI 编程对话中自动提取关键信息——决策、待办、知识点——沉淀为结构化笔记，让每一次新会话都能继承之前的工作上下文。\r\n\r\n**所有记忆分析在本机完成，数据完全由您掌控。** 身份验证通过 clawtip 第三方服务进行，仅问题描述文本（用于生成服务内容）和订单元数据通过 HTTPS 传输。\r\n\r\n### 核心能力\r\n\r\n**会话连续性**\r\n- 跨编程会话保持上下文连续性，新会话启动时自动加载上一次的关键决策和待办\r\n- 基于 Obsidian 本地笔记存储，无需云同步，数据完全留在本机\r\n- 按项目、日期、主题三维索引，快速定位历史上下文\r\n\r\n**工作日志**\r\n- 自动从对话中提取当日完成、学到、待办、卡点\r\n- 基于标准模板生成结构化工作日记\r\n- 支持按日期范围归档查询和周期性复盘\r\n\r\n**任务跟踪**\r\n- 跨项目管理任务清单，标记优先级、状态和完成时间\r\n- 自动识别对话中提及的\"稍后做\"\"下次处理\"项并记录\r\n- 支持按项目/优先级/状态多维度筛选\r\n\r\n**决策记录**\r\n- 从技术讨论中自动提取决策背景、候选方案、选择理由和影响范围\r\n- 结构化存储，方便未来回溯\"当初为什么这样做\"\r\n- 支持关联相关决策的交叉引用\r\n\r\n**复盘与回忆**\r\n- 对指定时间范围内的日志自动生成结构化复盘\r\n- 快速回忆历史任务、决策和项目上下文\r\n- 支持按关键词、时间、项目名称检索历史记忆\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我记住今天讨论的数据库选型结论\"\r\n- \"回顾一下上周关于支付方案的决策\"\r\n- \"生成昨天的工作日志和今日待办\"\r\n- \"我上次说的那个内存泄漏 bug 后来怎么处理的\"\r\n- \"把这周的所有技术决策整理成一份记录\"\r\n\r\n### 工作原理\r\n\r\n1. **对话分析**：AI 从当前对话中识别关键信息——决策、待办、知识点\r\n2. **结构化提取**：将识别到的信息按类型（工作日志/任务/决策）分类并结构化\r\n3. **本地写入**：通过用户确认后，写入 Obsidian 仓库的对应目录\r\n4. **关联索引**：自动识别与已有记忆的关联，建立交叉引用\r\n\r\n全部四个步骤在本机完成。仅在需要进行身份验证时，通过网络向 clawtip 发送订单标识信息。\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- AI 对话内容在本地分析和提取\r\n- 工作日记、任务清单、决策记录的生成在本地完成\r\n- 记忆的读取、写入、修改、删除均在本地 Obsidian 仓库操作\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 技能仅保存订单元数据（订单号、金额、加密凭证），不保存用户对话内容到订单文件\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- Obsidian 仓库中的任何笔记内容\r\n- 项目源代码或配置文件\r\n- 对话历史或会话内容\r\n- 设备信息或个人身份信息\r\n- 数据库连接信息或 API 密钥\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n- 已配置 Obsidian 仓库路径\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，必须立即终止流程并告知用户。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取记忆服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付记忆管理服务。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.0.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.0.32 | 2026-07-20 | Previous release |\n\nFile v3.0.36:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.0.36\",\n  \"publishedAt\": 1785057701695\n}\n\nFile v3.0.36:skill-card.md\n\n## Description: <br>\nPersistent memory system using Obsidian as local storage for daily work logs, task tracking, decision records, and cross-session context continuity for AI coding agents. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and AI coding-agent users use this skill to capture and recall project memory in a local Obsidian vault, including work logs, tasks, decisions, and context from prior sessions. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The release contacts api.ideaidea.com.cn, sends user question text during order creation, and verifies a local payment credential with the service. <br>\nMitigation: Review the disclosed network flow before installation, avoid sending sensitive question text, and confirm the requested network, credential, and filesystem permissions are acceptable. <br>\nRisk: The packaged artifacts mostly implement payment verification and do not include concrete Obsidian memory functionality. <br>\nMitigation: Confirm the installed artifact provides the expected memory workflow before relying on it for project records or cross-session continuity. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix) <br>\n- [clawtip verification service](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown guidance with shell command outputs and local Obsidian note content] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires clawtip-skill for payment verification before service delivery.] <br>\n\n## Skill Version(s): <br>\n3.0.36 (source: ClawHub release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.35: 7 files, 12529 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6960b), scripts/create_order.py (3584b), scripts/file_utils.py (2170b), scripts/service.py (3079b), skill-card.md (2702b), SKILL.md (6424b), _meta.json (160b)\n\nFile v3.0.35:SKILL.md\n\n---\r\nname: \"obsidian-memory-system\"\r\ndescription: >\r\n  Persistent memory system using Obsidian as local storage: daily work logs, task tracking, decision records, and cross-session context continuity for AI coding agents. All memory extraction and analysis runs locally. User question text and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No Obsidian vault content, source code, or personal files are ever uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.0.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# obsidian-memory-system\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能是一个基于 Obsidian 本地笔记的跨会话永久记忆系统。它从您的 AI 编程对话中自动提取关键信息——决策、待办、知识点——沉淀为结构化笔记，让每一次新会话都能继承之前的工作上下文。\r\n\r\n**所有记忆分析在本机完成，数据完全由您掌控。** 身份验证通过 clawtip 第三方服务进行，仅问题描述文本（用于生成服务内容）和订单元数据通过 HTTPS 传输。\r\n\r\n### 核心能力\r\n\r\n**会话连续性**\r\n- 跨编程会话保持上下文连续性，新会话启动时自动加载上一次的关键决策和待办\r\n- 基于 Obsidian 本地笔记存储，无需云同步，数据完全留在本机\r\n- 按项目、日期、主题三维索引，快速定位历史上下文\r\n\r\n**工作日志**\r\n- 自动从对话中提取当日完成、学到、待办、卡点\r\n- 基于标准模板生成结构化工作日记\r\n- 支持按日期范围归档查询和周期性复盘\r\n\r\n**任务跟踪**\r\n- 跨项目管理任务清单，标记优先级、状态和完成时间\r\n- 自动识别对话中提及的\"稍后做\"\"下次处理\"项并记录\r\n- 支持按项目/优先级/状态多维度筛选\r\n\r\n**决策记录**\r\n- 从技术讨论中自动提取决策背景、候选方案、选择理由和影响范围\r\n- 结构化存储，方便未来回溯\"当初为什么这样做\"\r\n- 支持关联相关决策的交叉引用\r\n\r\n**复盘与回忆**\r\n- 对指定时间范围内的日志自动生成结构化复盘\r\n- 快速回忆历史任务、决策和项目上下文\r\n- 支持按关键词、时间、项目名称检索历史记忆\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我记住今天讨论的数据库选型结论\"\r\n- \"回顾一下上周关于支付方案的决策\"\r\n- \"生成昨天的工作日志和今日待办\"\r\n- \"我上次说的那个内存泄漏 bug 后来怎么处理的\"\r\n- \"把这周的所有技术决策整理成一份记录\"\r\n\r\n### 工作原理\r\n\r\n1. **对话分析**：AI 从当前对话中识别关键信息——决策、待办、知识点\r\n2. **结构化提取**：将识别到的信息按类型（工作日志/任务/决策）分类并结构化\r\n3. **本地写入**：通过用户确认后，写入 Obsidian 仓库的对应目录\r\n4. **关联索引**：自动识别与已有记忆的关联，建立交叉引用\r\n\r\n全部四个步骤在本机完成。仅在需要进行身份验证时，通过网络向 clawtip 发送订单标识信息。\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- AI 对话内容在本地分析和提取\r\n- 工作日记、任务清单、决策记录的生成在本地完成\r\n- 记忆的读取、写入、修改、删除均在本地 Obsidian 仓库操作\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 技能仅保存订单元数据（订单号、金额、加密凭证），不保存用户对话内容到订单文件\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- Obsidian 仓库中的任何笔记内容\r\n- 项目源代码或配置文件\r\n- 对话历史或会话内容\r\n- 设备信息或个人身份信息\r\n- 数据库连接信息或 API 密钥\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n- 已配置 Obsidian 仓库路径\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，必须立即终止流程并告知用户。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取记忆服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付记忆管理服务。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.0.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.0.32 | 2026-07-20 | Previous release |\n\nFile v3.0.35:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.0.35\",\n  \"publishedAt\": 1784642163003\n}\n\nFile v3.0.35:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: obsidian-memory-system\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `obsidian-memory-system` 被 ClawHub/SkillSpector 命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Description-Behavior Mismatch`\n- `Context-Inappropriate Capability`\n- `Intent-Code Divergence`\n- `Missing User Warnings`\n\n这份清单的目标，是把“Obsidian 本地记忆技能”从“像远程支付代理”改成“以本地记忆流程为主、远程支付仅做授权”的审计友好形态。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 允许由环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n这会被审计器解释为：\n\n- 网络目标可被环境变量替换\n- 可以将订单请求发往任意远程服务\n\n#### 修改建议\n\n改成固定域名或白名单校验。\n\n推荐结构：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n如果环境变量存在，只允许白名单 host，通过解析校验后再使用。\n\n#### 问题 B：把用户原始记忆请求持久化到本地\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n对于记忆技能，这个字段风险更高，因为它可能包含：\n\n- 跨项目记忆摘要\n- 用户内部计划\n- 决策记录\n- 偏好信息\n- 私密开发上下文\n\n#### 修改建议\n\n优先级：\n\n1. 最优：不落盘原始请求\n2. 次优：只落盘最小摘要，例如：\n\n```python\n\"local_question_summary\": \"memory-request\"\n```\n\n3. 如果后续执行一定需要原始请求，则在 `service.py` 阶段重新输入，而不是从订单文件读取\n\n#### 问题 C：缺少显式用户提示\n\n`create_order.py` 应该在脚本开头明确告诉用户：\n\n- 这一步会创建本地订单文件\n- 只会把最小支付元数据发往支付服务\n- 不会上传 Obsidian 仓库内容\n\n建议增加：\n\n```python\nprint(\"NOTICE: this step creates a local order file.\")\nprint(\"NOTICE: only minimal payment metadata is sent to the payment service.\")\nprint(\"NOTICE: no Obsidian vault content is uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：描述和行为不一致\n\n当前技能名和文档都强调：\n\n- 读取记忆\n- 写入日志\n- 每日复盘\n\n但 `service.py` 的实际行为只是：\n\n- 读取本地订单文件\n- 发送 `credential` 到远端\n- 接收服务端返回结果\n\n审计器据此判定为：\n\n- `Description-Behavior Mismatch`\n- `Intent-Code Divergence`\n\n#### 修改建议\n\n必须把职责分层写清楚：\n\n1. `create_order.py`：只负责创建支付订单\n2. `service.py`：只负责支付校验和授权结果获取\n3. 真正的 Obsidian 读写逻辑：支付成功后，由技能后续本地步骤执行\n\n也就是说，文档和脚本命名要强调：\n\n- `service.py` 不是“memory execution engine”\n- 它只是“payment verification and service authorization step”\n\n#### 问题 B：发送 `credential` 到远端前没有用户提示\n\n建议在请求前增加：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification only.\")\nprint(\"NOTICE: no Obsidian vault content is uploaded during credential verification.\")\n```\n\n#### 问题 C：仍从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会继续强化“本地长期保存敏感记忆请求”的风险判断。\n\n#### 修改建议\n\n改成两种方案之一：\n\n1. `service.py` 不再读取用户原始请求，只做支付验证并拿授权结果\n2. 后续真正执行 Obsidian 动作时，再让用户重新确认或重新输入操作类型\n\n换句话说：\n\n- 支付闭环和本地记忆执行要拆开\n- 不要把它们绑在同一个订单 JSON 上\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：长期持久化风险\n\n订单文件目录本身问题不大，但对“记忆技能”来说，审计器会把它理解为：\n\n- 长期保存用户请求\n- 保存后可能被其他任务复用\n- 造成间接数据暴露\n\n#### 修改建议\n\n1. 订单 JSON 只保存最小必要字段\n2. 不保存记忆原文\n3. 在注释和文档中明确说明：\n   - 不保存 Obsidian 笔记正文\n   - 不保存仓库扫描结果\n   - 仅保存支付流程所需元数据\n\n可选增强：\n\n- 增加清理说明\n- 增加 TTL 清理脚本\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：技能描述过度承诺\n\n当前文案容易让审计器理解成：\n\n- 技能本身会自动读取本地 Obsidian 仓库\n- 自动写开发日志\n- 自动做每日复盘\n- 同时还依赖远程支付与远程返回\n\n于是被判：\n\n- 上下文能力过重\n- 能力边界不清\n\n#### 修改建议\n\n把文案拆成两个层级：\n\n1. **支付授权层**\n   - create order\n   - payment\n   - authorization result\n\n2. **本地执行层**\n   - 在支付成功后，本地按用户确认执行 Obsidian 读取/写入/复盘\n\n必须明确写：\n\n- Remote service is used only for payment and authorization.\n- Obsidian vault read/write happens locally after user confirmation.\n- No vault content is uploaded to the remote payment service.\n\n#### 问题 B：减少“自动化”措辞\n\n少用：\n\n- 自动读取整个记忆库\n- 自动执行后续任务\n- 自动沉淀长期记忆\n\n改成：\n\n- 在当前步骤按用户确认读取必要文件\n- 本地执行指定的记忆操作\n- 每一步都由用户触发\n\n#### 问题 C：加强用户告知\n\n在 `SKILL.md` 中明确增加：\n\n1. 本地订单文件会保存订单元数据\n2. 不上传 Obsidian 仓库正文\n3. 支付验证阶段仅发送最小支付信息和支付凭证\n4. 任何本地记忆读取/写入都在支付成功后、本地执行\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 收紧 `SERVER_URL`\n   - 增加 NOTICE\n\n2. 再改 `service.py`\n   - 不再承担“记忆执行”语义\n   - 只做支付校验和授权结果获取\n   - 去掉对本地原始请求的依赖\n\n3. 再改 `SKILL.md`\n   - 改写为“本地记忆执行 + 远程支付授权”双层结构\n   - 消除描述与行为不一致\n\n4. 最后发 ClawHub 新 patch 版本\n\n## 关键设计原则\n\n对这个技能，最重要的不是“减少联网”，而是：\n\n- 让联网行为只承担支付授权\n- 让 Obsidian 能力只承担本地执行\n- 让本地敏感请求不再长期保存\n- 让文档描述和代码行为一致\n\n## 备注\n\n当前这版被打中，不是因为 ClawHub 认为“不能做付费记忆技能”，而是因为：\n\n- 代码看起来像“用记忆技能名义进行远程请求”\n- 同时本地又长期保存了记忆原文\n\n下一版只要把这两个点拆开，风险就会明显下降。\n\nFile v3.0.35:skill-card.md\n\n## Description: <br>\nProvides a Chinese-language Obsidian-based memory workflow for AI coding agents, with local note generation and third-party payment verification that sends user question text and encrypted payment credentials over HTTPS. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and AI coding agent users use this skill to preserve cross-session context by turning conversations into local Obsidian work logs, task lists, decision records, retrospectives, and historical lookups. The skill also uses a third-party payment authorization flow before service delivery. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Question text may contain private project details or sensitive memory content and is uploaded to the remote service and saved locally in an order file. <br>\nMitigation: Use only minimal, non-sensitive question text and do not include secrets, private project details, or sensitive memory content. <br>\nRisk: The skill depends on payment verification, credential read permission, and local order-file retention outside the Obsidian vault. <br>\nMitigation: Install only after accepting those requirements, and review retained order files after payment or service completion. <br>\nRisk: The server security summary says the handling of question text and local order files is broader and less consistently disclosed than users would expect. <br>\nMitigation: Review the skill carefully before installing and confirm the documented data handling matches the intended use. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Files, Shell commands, Configuration guidance] <br>\n**Output Format:** [Markdown notes, status text, and shell command outputs] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Writes local Obsidian memory artifacts and local order metadata; payment authorization uses a third-party service before memory service delivery.] <br>\n\n## Skill Version(s): <br>\n3.0.35 (source: server release evidence, changelog source: user) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.34: 7 files, 12544 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6960b), scripts/create_order.py (3584b), scripts/file_utils.py (2170b), scripts/service.py (3089b), skill-card.md (2754b), SKILL.md (6424b), _meta.json (160b)\n\nFile v3.0.34:SKILL.md\n\n---\r\nname: \"obsidian-memory-system\"\r\ndescription: >\r\n  Persistent memory system using Obsidian as local storage: daily work logs, task tracking, decision records, and cross-session context continuity for AI coding agents. All memory extraction and analysis runs locally. User question text and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No Obsidian vault content, source code, or personal files are ever uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.0.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# obsidian-memory-system\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能是一个基于 Obsidian 本地笔记的跨会话永久记忆系统。它从您的 AI 编程对话中自动提取关键信息——决策、待办、知识点——沉淀为结构化笔记，让每一次新会话都能继承之前的工作上下文。\r\n\r\n**所有记忆分析在本机完成，数据完全由您掌控。** 身份验证通过 clawtip 第三方服务进行，仅问题描述文本（用于生成服务内容）和订单元数据通过 HTTPS 传输。\r\n\r\n### 核心能力\r\n\r\n**会话连续性**\r\n- 跨编程会话保持上下文连续性，新会话启动时自动加载上一次的关键决策和待办\r\n- 基于 Obsidian 本地笔记存储，无需云同步，数据完全留在本机\r\n- 按项目、日期、主题三维索引，快速定位历史上下文\r\n\r\n**工作日志**\r\n- 自动从对话中提取当日完成、学到、待办、卡点\r\n- 基于标准模板生成结构化工作日记\r\n- 支持按日期范围归档查询和周期性复盘\r\n\r\n**任务跟踪**\r\n- 跨项目管理任务清单，标记优先级、状态和完成时间\r\n- 自动识别对话中提及的\"稍后做\"\"下次处理\"项并记录\r\n- 支持按项目/优先级/状态多维度筛选\r\n\r\n**决策记录**\r\n- 从技术讨论中自动提取决策背景、候选方案、选择理由和影响范围\r\n- 结构化存储，方便未来回溯\"当初为什么这样做\"\r\n- 支持关联相关决策的交叉引用\r\n\r\n**复盘与回忆**\r\n- 对指定时间范围内的日志自动生成结构化复盘\r\n- 快速回忆历史任务、决策和项目上下文\r\n- 支持按关键词、时间、项目名称检索历史记忆\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我记住今天讨论的数据库选型结论\"\r\n- \"回顾一下上周关于支付方案的决策\"\r\n- \"生成昨天的工作日志和今日待办\"\r\n- \"我上次说的那个内存泄漏 bug 后来怎么处理的\"\r\n- \"把这周的所有技术决策整理成一份记录\"\r\n\r\n### 工作原理\r\n\r\n1. **对话分析**：AI 从当前对话中识别关键信息——决策、待办、知识点\r\n2. **结构化提取**：将识别到的信息按类型（工作日志/任务/决策）分类并结构化\r\n3. **本地写入**：通过用户确认后，写入 Obsidian 仓库的对应目录\r\n4. **关联索引**：自动识别与已有记忆的关联，建立交叉引用\r\n\r\n全部四个步骤在本机完成。仅在需要进行身份验证时，通过网络向 clawtip 发送订单标识信息。\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- AI 对话内容在本地分析和提取\r\n- 工作日记、任务清单、决策记录的生成在本地完成\r\n- 记忆的读取、写入、修改、删除均在本地 Obsidian 仓库操作\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 技能仅保存订单元数据（订单号、金额、加密凭证），不保存用户对话内容到订单文件\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- Obsidian 仓库中的任何笔记内容\r\n- 项目源代码或配置文件\r\n- 对话历史或会话内容\r\n- 设备信息或个人身份信息\r\n- 数据库连接信息或 API 密钥\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n- 已配置 Obsidian 仓库路径\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，必须立即终止流程并告知用户。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取记忆服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付记忆管理服务。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.0.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.0.32 | 2026-07-20 | Previous release |\n\nFile v3.0.34:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.0.34\",\n  \"publishedAt\": 1784641222234\n}\n\nFile v3.0.34:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: obsidian-memory-system\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `obsidian-memory-system` 被 ClawHub/SkillSpector 命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Description-Behavior Mismatch`\n- `Context-Inappropriate Capability`\n- `Intent-Code Divergence`\n- `Missing User Warnings`\n\n这份清单的目标，是把“Obsidian 本地记忆技能”从“像远程支付代理”改成“以本地记忆流程为主、远程支付仅做授权”的审计友好形态。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 允许由环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n这会被审计器解释为：\n\n- 网络目标可被环境变量替换\n- 可以将订单请求发往任意远程服务\n\n#### 修改建议\n\n改成固定域名或白名单校验。\n\n推荐结构：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n如果环境变量存在，只允许白名单 host，通过解析校验后再使用。\n\n#### 问题 B：把用户原始记忆请求持久化到本地\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n对于记忆技能，这个字段风险更高，因为它可能包含：\n\n- 跨项目记忆摘要\n- 用户内部计划\n- 决策记录\n- 偏好信息\n- 私密开发上下文\n\n#### 修改建议\n\n优先级：\n\n1. 最优：不落盘原始请求\n2. 次优：只落盘最小摘要，例如：\n\n```python\n\"local_question_summary\": \"memory-request\"\n```\n\n3. 如果后续执行一定需要原始请求，则在 `service.py` 阶段重新输入，而不是从订单文件读取\n\n#### 问题 C：缺少显式用户提示\n\n`create_order.py` 应该在脚本开头明确告诉用户：\n\n- 这一步会创建本地订单文件\n- 只会把最小支付元数据发往支付服务\n- 不会上传 Obsidian 仓库内容\n\n建议增加：\n\n```python\nprint(\"NOTICE: this step creates a local order file.\")\nprint(\"NOTICE: only minimal payment metadata is sent to the payment service.\")\nprint(\"NOTICE: no Obsidian vault content is uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：描述和行为不一致\n\n当前技能名和文档都强调：\n\n- 读取记忆\n- 写入日志\n- 每日复盘\n\n但 `service.py` 的实际行为只是：\n\n- 读取本地订单文件\n- 发送 `credential` 到远端\n- 接收服务端返回结果\n\n审计器据此判定为：\n\n- `Description-Behavior Mismatch`\n- `Intent-Code Divergence`\n\n#### 修改建议\n\n必须把职责分层写清楚：\n\n1. `create_order.py`：只负责创建支付订单\n2. `service.py`：只负责支付校验和授权结果获取\n3. 真正的 Obsidian 读写逻辑：支付成功后，由技能后续本地步骤执行\n\n也就是说，文档和脚本命名要强调：\n\n- `service.py` 不是“memory execution engine”\n- 它只是“payment verification and service authorization step”\n\n#### 问题 B：发送 `credential` 到远端前没有用户提示\n\n建议在请求前增加：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification only.\")\nprint(\"NOTICE: no Obsidian vault content is uploaded during credential verification.\")\n```\n\n#### 问题 C：仍从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会继续强化“本地长期保存敏感记忆请求”的风险判断。\n\n#### 修改建议\n\n改成两种方案之一：\n\n1. `service.py` 不再读取用户原始请求，只做支付验证并拿授权结果\n2. 后续真正执行 Obsidian 动作时，再让用户重新确认或重新输入操作类型\n\n换句话说：\n\n- 支付闭环和本地记忆执行要拆开\n- 不要把它们绑在同一个订单 JSON 上\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：长期持久化风险\n\n订单文件目录本身问题不大，但对“记忆技能”来说，审计器会把它理解为：\n\n- 长期保存用户请求\n- 保存后可能被其他任务复用\n- 造成间接数据暴露\n\n#### 修改建议\n\n1. 订单 JSON 只保存最小必要字段\n2. 不保存记忆原文\n3. 在注释和文档中明确说明：\n   - 不保存 Obsidian 笔记正文\n   - 不保存仓库扫描结果\n   - 仅保存支付流程所需元数据\n\n可选增强：\n\n- 增加清理说明\n- 增加 TTL 清理脚本\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：技能描述过度承诺\n\n当前文案容易让审计器理解成：\n\n- 技能本身会自动读取本地 Obsidian 仓库\n- 自动写开发日志\n- 自动做每日复盘\n- 同时还依赖远程支付与远程返回\n\n于是被判：\n\n- 上下文能力过重\n- 能力边界不清\n\n#### 修改建议\n\n把文案拆成两个层级：\n\n1. **支付授权层**\n   - create order\n   - payment\n   - authorization result\n\n2. **本地执行层**\n   - 在支付成功后，本地按用户确认执行 Obsidian 读取/写入/复盘\n\n必须明确写：\n\n- Remote service is used only for payment and authorization.\n- Obsidian vault read/write happens locally after user confirmation.\n- No vault content is uploaded to the remote payment service.\n\n#### 问题 B：减少“自动化”措辞\n\n少用：\n\n- 自动读取整个记忆库\n- 自动执行后续任务\n- 自动沉淀长期记忆\n\n改成：\n\n- 在当前步骤按用户确认读取必要文件\n- 本地执行指定的记忆操作\n- 每一步都由用户触发\n\n#### 问题 C：加强用户告知\n\n在 `SKILL.md` 中明确增加：\n\n1. 本地订单文件会保存订单元数据\n2. 不上传 Obsidian 仓库正文\n3. 支付验证阶段仅发送最小支付信息和支付凭证\n4. 任何本地记忆读取/写入都在支付成功后、本地执行\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 收紧 `SERVER_URL`\n   - 增加 NOTICE\n\n2. 再改 `service.py`\n   - 不再承担“记忆执行”语义\n   - 只做支付校验和授权结果获取\n   - 去掉对本地原始请求的依赖\n\n3. 再改 `SKILL.md`\n   - 改写为“本地记忆执行 + 远程支付授权”双层结构\n   - 消除描述与行为不一致\n\n4. 最后发 ClawHub 新 patch 版本\n\n## 关键设计原则\n\n对这个技能，最重要的不是“减少联网”，而是：\n\n- 让联网行为只承担支付授权\n- 让 Obsidian 能力只承担本地执行\n- 让本地敏感请求不再长期保存\n- 让文档描述和代码行为一致\n\n## 备注\n\n当前这版被打中，不是因为 ClawHub 认为“不能做付费记忆技能”，而是因为：\n\n- 代码看起来像“用记忆技能名义进行远程请求”\n- 同时本地又长期保存了记忆原文\n\n下一版只要把这两个点拆开，风险就会明显下降。\n\nFile v3.0.34:skill-card.md\n\n## Description: <br>\nPersistent memory system for AI coding agents that uses Obsidian for local work logs, task tracking, decision records, and cross-session context while using a third-party Clawtip service for order creation and authorization. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and AI coding agent users use this skill to maintain local Obsidian-based memory across sessions, including work logs, tasks, decision records, and project context. The skill also supports a third-party payment and authorization flow before delivering the memory workflow. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: User question text may be sent to api.ideaidea.com.cn and saved under the local OpenClaw orders directory. <br>\nMitigation: Do not include secrets, source excerpts, private notes, or sensitive project details in the question unless the publisher updates the notices, storage behavior, and encryption claims to match the implementation. <br>\nRisk: Documentation and notices may understate the handling of user question text by saying only order metadata is handled. <br>\nMitigation: Review the skill before installing and confirm that the transmitted and stored data matches the published privacy notices for the release. <br>\nRisk: The authorization flow sends encrypted payment credentials to a third-party service. <br>\nMitigation: Run the payment and authorization scripts only when the expected service endpoint is acceptable for the deployment environment. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [Third-party authorization service](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and local Obsidian note content] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May read and write local filesystem content and may require network authorization through the Clawtip service.] <br>\n\n## Skill Version(s): <br>\n3.0.34 (source: server release evidence; artifact frontmatter reports 3.0.33) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.33: 7 files, 12176 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6960b), scripts/create_order.py (3110b), scripts/file_utils.py (2170b), scripts/service.py (2784b), skill-card.md (2833b), SKILL.md (6100b), _meta.json (160b)\n\nFile v3.0.33:SKILL.md\n\n---\r\nname: \"obsidian-memory-system\"\r\ndescription: >\r\n  Persistent memory system using Obsidian as local storage: daily work logs, task tracking, decision records, and cross-session context continuity for AI coding agents. All memory extraction and analysis runs locally. User question text and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No Obsidian vault content, source code, or personal files are ever uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.0.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n---\r\n\r\n# obsidian-memory-system\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能是一个基于 Obsidian 本地笔记的跨会话永久记忆系统。它从您的 AI 编程对话中自动提取关键信息——决策、待办、知识点——沉淀为结构化笔记，让每一次新会话都能继承之前的工作上下文。\r\n\r\n**所有记忆分析在本机完成，数据完全由您掌控。** 身份验证通过 clawtip 第三方服务进行，仅问题描述文本（用于生成服务内容）和订单元数据通过 HTTPS 传输。\r\n\r\n### 核心能力\r\n\r\n**会话连续性**\r\n- 跨编程会话保持上下文连续性，新会话启动时自动加载上一次的关键决策和待办\r\n- 基于 Obsidian 本地笔记存储，无需云同步，数据完全留在本机\r\n- 按项目、日期、主题三维索引，快速定位历史上下文\r\n\r\n**工作日志**\r\n- 自动从对话中提取当日完成、学到、待办、卡点\r\n- 基于标准模板生成结构化工作日记\r\n- 支持按日期范围归档查询和周期性复盘\r\n\r\n**任务跟踪**\r\n- 跨项目管理任务清单，标记优先级、状态和完成时间\r\n- 自动识别对话中提及的\"稍后做\"\"下次处理\"项并记录\r\n- 支持按项目/优先级/状态多维度筛选\r\n\r\n**决策记录**\r\n- 从技术讨论中自动提取决策背景、候选方案、选择理由和影响范围\r\n- 结构化存储，方便未来回溯\"当初为什么这样做\"\r\n- 支持关联相关决策的交叉引用\r\n\r\n**复盘与回忆**\r\n- 对指定时间范围内的日志自动生成结构化复盘\r\n- 快速回忆历史任务、决策和项目上下文\r\n- 支持按关键词、时间、项目名称检索历史记忆\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我记住今天讨论的数据库选型结论\"\r\n- \"回顾一下上周关于支付方案的决策\"\r\n- \"生成昨天的工作日志和今日待办\"\r\n- \"我上次说的那个内存泄漏 bug 后来怎么处理的\"\r\n- \"把这周的所有技术决策整理成一份记录\"\r\n\r\n### 工作原理\r\n\r\n1. **对话分析**：AI 从当前对话中识别关键信息——决策、待办、知识点\r\n2. **结构化提取**：将识别到的信息按类型（工作日志/任务/决策）分类并结构化\r\n3. **本地写入**：通过用户确认后，写入 Obsidian 仓库的对应目录\r\n4. **关联索引**：自动识别与已有记忆的关联，建立交叉引用\r\n\r\n全部四个步骤在本机完成。仅在需要进行身份验证时，通过网络向 clawtip 发送订单标识信息。\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- AI 对话内容在本地分析和提取\r\n- 工作日记、任务清单、决策记录的生成在本地完成\r\n- 记忆的读取、写入、修改、删除均在本地 Obsidian 仓库操作\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 技能仅保存订单元数据（订单号、金额、加密凭证），不保存用户对话内容到订单文件\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- Obsidian 仓库中的任何笔记内容\r\n- 项目源代码或配置文件\r\n- 对话历史或会话内容\r\n- 设备信息或个人身份信息\r\n- 数据库连接信息或 API 密钥\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n- 已配置 Obsidian 仓库路径\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n```bash\r\npython3 scripts/create_order.py\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，必须立即终止流程并告知用户。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取记忆服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付记忆管理服务。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.0.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.0.32 | 2026-07-20 | Previous release |\n\nFile v3.0.33:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.0.33\",\n  \"publishedAt\": 1784629950823\n}\n\nFile v3.0.33:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: obsidian-memory-system\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `obsidian-memory-system` 被 ClawHub/SkillSpector 命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Description-Behavior Mismatch`\n- `Context-Inappropriate Capability`\n- `Intent-Code Divergence`\n- `Missing User Warnings`\n\n这份清单的目标，是把“Obsidian 本地记忆技能”从“像远程支付代理”改成“以本地记忆流程为主、远程支付仅做授权”的审计友好形态。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 允许由环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n这会被审计器解释为：\n\n- 网络目标可被环境变量替换\n- 可以将订单请求发往任意远程服务\n\n#### 修改建议\n\n改成固定域名或白名单校验。\n\n推荐结构：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n如果环境变量存在，只允许白名单 host，通过解析校验后再使用。\n\n#### 问题 B：把用户原始记忆请求持久化到本地\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n对于记忆技能，这个字段风险更高，因为它可能包含：\n\n- 跨项目记忆摘要\n- 用户内部计划\n- 决策记录\n- 偏好信息\n- 私密开发上下文\n\n#### 修改建议\n\n优先级：\n\n1. 最优：不落盘原始请求\n2. 次优：只落盘最小摘要，例如：\n\n```python\n\"local_question_summary\": \"memory-request\"\n```\n\n3. 如果后续执行一定需要原始请求，则在 `service.py` 阶段重新输入，而不是从订单文件读取\n\n#### 问题 C：缺少显式用户提示\n\n`create_order.py` 应该在脚本开头明确告诉用户：\n\n- 这一步会创建本地订单文件\n- 只会把最小支付元数据发往支付服务\n- 不会上传 Obsidian 仓库内容\n\n建议增加：\n\n```python\nprint(\"NOTICE: this step creates a local order file.\")\nprint(\"NOTICE: only minimal payment metadata is sent to the payment service.\")\nprint(\"NOTICE: no Obsidian vault content is uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：描述和行为不一致\n\n当前技能名和文档都强调：\n\n- 读取记忆\n- 写入日志\n- 每日复盘\n\n但 `service.py` 的实际行为只是：\n\n- 读取本地订单文件\n- 发送 `credential` 到远端\n- 接收服务端返回结果\n\n审计器据此判定为：\n\n- `Description-Behavior Mismatch`\n- `Intent-Code Divergence`\n\n#### 修改建议\n\n必须把职责分层写清楚：\n\n1. `create_order.py`：只负责创建支付订单\n2. `service.py`：只负责支付校验和授权结果获取\n3. 真正的 Obsidian 读写逻辑：支付成功后，由技能后续本地步骤执行\n\n也就是说，文档和脚本命名要强调：\n\n- `service.py` 不是“memory execution engine”\n- 它只是“payment verification and service authorization step”\n\n#### 问题 B：发送 `credential` 到远端前没有用户提示\n\n建议在请求前增加：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification only.\")\nprint(\"NOTICE: no Obsidian vault content is uploaded during credential verification.\")\n```\n\n#### 问题 C：仍从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会继续强化“本地长期保存敏感记忆请求”的风险判断。\n\n#### 修改建议\n\n改成两种方案之一：\n\n1. `service.py` 不再读取用户原始请求，只做支付验证并拿授权结果\n2. 后续真正执行 Obsidian 动作时，再让用户重新确认或重新输入操作类型\n\n换句话说：\n\n- 支付闭环和本地记忆执行要拆开\n- 不要把它们绑在同一个订单 JSON 上\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：长期持久化风险\n\n订单文件目录本身问题不大，但对“记忆技能”来说，审计器会把它理解为：\n\n- 长期保存用户请求\n- 保存后可能被其他任务复用\n- 造成间接数据暴露\n\n#### 修改建议\n\n1. 订单 JSON 只保存最小必要字段\n2. 不保存记忆原文\n3. 在注释和文档中明确说明：\n   - 不保存 Obsidian 笔记正文\n   - 不保存仓库扫描结果\n   - 仅保存支付流程所需元数据\n\n可选增强：\n\n- 增加清理说明\n- 增加 TTL 清理脚本\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：技能描述过度承诺\n\n当前文案容易让审计器理解成：\n\n- 技能本身会自动读取本地 Obsidian 仓库\n- 自动写开发日志\n- 自动做每日复盘\n- 同时还依赖远程支付与远程返回\n\n于是被判：\n\n- 上下文能力过重\n- 能力边界不清\n\n#### 修改建议\n\n把文案拆成两个层级：\n\n1. **支付授权层**\n   - create order\n   - payment\n   - authorization result\n\n2. **本地执行层**\n   - 在支付成功后，本地按用户确认执行 Obsidian 读取/写入/复盘\n\n必须明确写：\n\n- Remote service is used only for payment and authorization.\n- Obsidian vault read/write happens locally after user confirmation.\n- No vault content is uploaded to the remote payment service.\n\n#### 问题 B：减少“自动化”措辞\n\n少用：\n\n- 自动读取整个记忆库\n- 自动执行后续任务\n- 自动沉淀长期记忆\n\n改成：\n\n- 在当前步骤按用户确认读取必要文件\n- 本地执行指定的记忆操作\n- 每一步都由用户触发\n\n#### 问题 C：加强用户告知\n\n在 `SKILL.md` 中明确增加：\n\n1. 本地订单文件会保存订单元数据\n2. 不上传 Obsidian 仓库正文\n3. 支付验证阶段仅发送最小支付信息和支付凭证\n4. 任何本地记忆读取/写入都在支付成功后、本地执行\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 收紧 `SERVER_URL`\n   - 增加 NOTICE\n\n2. 再改 `service.py`\n   - 不再承担“记忆执行”语义\n   - 只做支付校验和授权结果获取\n   - 去掉对本地原始请求的依赖\n\n3. 再改 `SKILL.md`\n   - 改写为“本地记忆执行 + 远程支付授权”双层结构\n   - 消除描述与行为不一致\n\n4. 最后发 ClawHub 新 patch 版本\n\n## 关键设计原则\n\n对这个技能，最重要的不是“减少联网”，而是：\n\n- 让联网行为只承担支付授权\n- 让 Obsidian 能力只承担本地执行\n- 让本地敏感请求不再长期保存\n- 让文档描述和代码行为一致\n\n## 备注\n\n当前这版被打中，不是因为 ClawHub 认为“不能做付费记忆技能”，而是因为：\n\n- 代码看起来像“用记忆技能名义进行远程请求”\n- 同时本地又长期保存了记忆原文\n\n下一版只要把这两个点拆开，风险就会明显下降。\n\nFile v3.0.33:skill-card.md\n\n## Description: <br>\nPersistent memory system that uses Obsidian as local storage for work logs, task tracking, decision records, and cross-session context continuity for AI coding agents. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and AI coding agent users use this skill to preserve local project memory in Obsidian, including daily work logs, tasks, technical decisions, and later recall. Payment and authorization use a third-party clawtip verification flow before local memory service delivery. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill requests filesystem read/write, credential access, persistent local memory storage, and network calls to api.ideaidea.com.cn. <br>\nMitigation: Configure it only for the intended Obsidian vault, review the skill before installation, avoid highly sensitive notes unless the publisher and clawtip flow are trusted, and keep local memory operations scoped to user-confirmed tasks. <br>\nRisk: Payment authorization sends user question text or order metadata and encrypted payment credentials to a third-party verification service. <br>\nMitigation: Use the skill only when that third-party verification flow is acceptable, avoid entering sensitive question text during order creation, and inspect the payment scripts before running them. <br>\nRisk: The inspected evidence describes SM4 encryption, but the security review treats that encryption claim as unverified. <br>\nMitigation: Do not rely on the SM4 claim as the only protection for sensitive data; treat HTTPS transport and data minimization as the practical safeguards. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix) <br>\n- [clawtip verification service endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and local Obsidian note updates] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires an intended Obsidian vault and clawtip-based order verification; local order metadata may be stored under the user's OpenClaw orders directory.] <br>\n\n## Skill Version(s): <br>\n3.0.33 (source: server release evidence and SKILL.md frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.0.32: 7 files, 11716 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6960b), scripts/create_order.py (3038b), scripts/file_utils.py (2170b), scripts/service.py (2440b), skill-card.md (2496b), SKILL.md (5651b), _meta.json (160b)\n\nFile v3.0.32:SKILL.md\n\n---\nname: \"obsidian-memory-system\"\ndescription: >\n  Persistent memory system using Obsidian as local storage: daily work logs, task tracking, decision records, and cross-session context continuity for AI coding agents. All memory extraction and analysis runs locally; only order metadata (slug, orderNo) is transmitted via HTTPS to the clawtip third-party verification service. No Obsidian vault content, source code, or personal files are ever uploaded.\nmetadata:\n  author: \"Yujin\"\n  version: \"3.0.33\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip-skill\"\n---\n\n# obsidian-memory-system\n\nPlease interact with users in Chinese (使用中文与用户交互).\n\n## 功能概述\n\n本技能是一个基于 Obsidian 本地笔记的跨会话永久记忆系统。它从您的 AI 编程对话中自动提取关键信息——决策、待办、知识点——沉淀为结构化笔记，让每一次新会话都能继承之前的工作上下文。\n\n**所有记忆分析在本机完成，数据完全由您掌控。** 身份验证通过 clawtip 第三方服务进行，仅传输订单标识信息。\n\n### 核心能力\n\n**会话连续性**\n- 跨编程会话保持上下文连续性，新会话启动时自动加载上一次的关键决策和待办\n- 基于 Obsidian 本地笔记存储，无需云同步，数据完全留在本机\n- 按项目、日期、主题三维索引，快速定位历史上下文\n\n**工作日志**\n- 自动从对话中提取当日完成、学到、待办、卡点\n- 基于标准模板生成结构化工作日记\n- 支持按日期范围归档查询和周期性复盘\n\n**任务跟踪**\n- 跨项目管理任务清单，标记优先级、状态和完成时间\n- 自动识别对话中提及的\"稍后做\"\"下次处理\"项并记录\n- 支持按项目/优先级/状态多维度筛选\n\n**决策记录**\n- 从技术讨论中自动提取决策背景、候选方案、选择理由和影响范围\n- 结构化存储，方便未来回溯\"当初为什么这样做\"\n- 支持关联相关决策的交叉引用\n\n**复盘与回忆**\n- 对指定时间范围内的日志自动生成结构化复盘\n- 快速回忆历史任务、决策和项目上下文\n- 支持按关键词、时间、项目名称检索历史记忆\n\n### 使用场景示例\n\n- \"帮我记住今天讨论的数据库选型结论\"\n- \"回顾一下上周关于支付方案的决策\"\n- \"生成昨天的工作日志和今日待办\"\n- \"我上次说的那个内存泄漏 bug 后来怎么处理的\"\n- \"把这周的所有技术决策整理成一份记录\"\n\n### 工作原理\n\n1. **对话分析**：AI 从当前对话中识别关键信息——决策、待办、知识点\n2. **结构化提取**：将识别到的信息按类型（工作日志/任务/决策）分类并结构化\n3. **本地写入**：通过用户确认后，写入 Obsidian 仓库的对应目录\n4. **关联索引**：自动识别与已有记忆的关联，建立交叉引用\n\n全部四个步骤在本机完成。仅在需要进行身份验证时，通过网络向 clawtip 发送订单标识信息。\n\n---\n\n## 数据处理与隐私说明\n\n本技能严格遵守数据最小化与透明传输原则：\n\n### 本地处理（数据始终不离开本机）\n- AI 对话内容在本地分析和提取\n- 工作日记、任务清单、决策记录的生成在本地完成\n- 记忆的读取、写入、修改、删除均在本地 Obsidian 仓库操作\n\n### 远程传输（仅身份验证阶段）\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\n- **传输协议**：HTTPS + SM4 国密加密\n- **传输时机**：仅在订单创建和履约验证时发生\n\n### 本地存储\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\n- 技能仅保存订单元数据（订单号、金额、加密凭证），不保存用户对话内容到订单文件\n- 支付完成后建议可随时手动清理订单文件\n\n### 绝不收集或传输\n- Obsidian 仓库中的任何笔记内容\n- 项目源代码或配置文件\n- 对话历史或会话内容\n- 设备信息或个人身份信息\n- 数据库连接信息或 API 密钥\n\n---\n\n## 如何开始使用\n\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\n\n### 前置条件\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\n- 已配置 Obsidian 仓库路径\n\n### 第一阶段：创建验证订单\n\n```bash\npython3 scripts/create_order.py\n```\n\n**成功时**输出：\n```\nORDER_NO=<value>\nAMOUNT=<value>\nINDICATOR=<value>\n```\n\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\n\n**失败时**以代码 1 退出，必须立即终止流程并告知用户。\n\n### 第二阶段：身份验证\n\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\n\n### 第三阶段：获取记忆服务\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付记忆管理服务。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:---|:---|:---|\n| 3.0.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\n| 3.0.32 | 2026-07-20 | Previous release |\n\nFile v3.0.32:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.0.32\",\n  \"publishedAt\": 1784562224446\n}\n\nFile v3.0.32:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: obsidian-memory-system\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `obsidian-memory-system` 被 ClawHub/SkillSpector 命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Description-Behavior Mismatch`\n- `Context-Inappropriate Capability`\n- `Intent-Code Divergence`\n- `Missing User Warnings`\n\n这份清单的目标，是把“Obsidian 本地记忆技能”从“像远程支付代理”改成“以本地记忆流程为主、远程支付仅做授权”的审计友好形态。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 允许由环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n这会被审计器解释为：\n\n- 网络目标可被环境变量替换\n- 可以将订单请求发往任意远程服务\n\n#### 修改建议\n\n改成固定域名或白名单校验。\n\n推荐结构：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n如果环境变量存在，只允许白名单 host，通过解析校验后再使用。\n\n#### 问题 B：把用户原始记忆请求持久化到本地\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n对于记忆技能，这个字段风险更高，因为它可能包含：\n\n- 跨项目记忆摘要\n- 用户内部计划\n- 决策记录\n- 偏好信息\n- 私密开发上下文\n\n#### 修改建议\n\n优先级：\n\n1. 最优：不落盘原始请求\n2. 次优：只落盘最小摘要，例如：\n\n```python\n\"local_question_summary\": \"memory-request\"\n```\n\n3. 如果后续执行一定需要原始请求，则在 `service.py` 阶段重新输入，而不是从订单文件读取\n\n#### 问题 C：缺少显式用户提示\n\n`create_order.py` 应该在脚本开头明确告诉用户：\n\n- 这一步会创建本地订单文件\n- 只会把最小支付元数据发往支付服务\n- 不会上传 Obsidian 仓库内容\n\n建议增加：\n\n```python\nprint(\"NOTICE: this step creates a local order file.\")\nprint(\"NOTICE: only minimal payment metadata is sent to the payment service.\")\nprint(\"NOTICE: no Obsidian vault content is uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：描述和行为不一致\n\n当前技能名和文档都强调：\n\n- 读取记忆\n- 写入日志\n- 每日复盘\n\n但 `service.py` 的实际行为只是：\n\n- 读取本地订单文件\n- 发送 `credential` 到远端\n- 接收服务端返回结果\n\n审计器据此判定为：\n\n- `Description-Behavior Mismatch`\n- `Intent-Code Divergence`\n\n#### 修改建议\n\n必须把职责分层写清楚：\n\n1. `create_order.py`：只负责创建支付订单\n2. `service.py`：只负责支付校验和授权结果获取\n3. 真正的 Obsidian 读写逻辑：支付成功后，由技能后续本地步骤执行\n\n也就是说，文档和脚本命名要强调：\n\n- `service.py` 不是“memory execution engine”\n- 它只是“payment verification and service authorization step”\n\n#### 问题 B：发送 `credential` 到远端前没有用户提示\n\n建议在请求前增加：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification only.\")\nprint(\"NOTICE: no Obsidian vault content is uploaded during credential verification.\")\n```\n\n#### 问题 C：仍从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会继续强化“本地长期保存敏感记忆请求”的风险判断。\n\n#### 修改建议\n\n改成两种方案之一：\n\n1. `service.py` 不再读取用户原始请求，只做支付验证并拿授权结果\n2. 后续真正执行 Obsidian 动作时，再让用户重新确认或重新输入操作类型\n\n换句话说：\n\n- 支付闭环和本地记忆执行要拆开\n- 不要把它们绑在同一个订单 JSON 上\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：长期持久化风险\n\n订单文件目录本身问题不大，但对“记忆技能”来说，审计器会把它理解为：\n\n- 长期保存用户请求\n- 保存后可能被其他任务复用\n- 造成间接数据暴露\n\n#### 修改建议\n\n1. 订单 JSON 只保存最小必要字段\n2. 不保存记忆原文\n3. 在注释和文档中明确说明：\n   - 不保存 Obsidian 笔记正文\n   - 不保存仓库扫描结果\n   - 仅保存支付流程所需元数据\n\n可选增强：\n\n- 增加清理说明\n- 增加 TTL 清理脚本\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：技能描述过度承诺\n\n当前文案容易让审计器理解成：\n\n- 技能本身会自动读取本地 Obsidian 仓库\n- 自动写开发日志\n- 自动做每日复盘\n- 同时还依赖远程支付与远程返回\n\n于是被判：\n\n- 上下文能力过重\n- 能力边界不清\n\n#### 修改建议\n\n把文案拆成两个层级：\n\n1. **支付授权层**\n   - create order\n   - payment\n   - authorization result\n\n2. **本地执行层**\n   - 在支付成功后，本地按用户确认执行 Obsidian 读取/写入/复盘\n\n必须明确写：\n\n- Remote service is used only for payment and authorization.\n- Obsidian vault read/write happens locally after user confirmation.\n- No vault content is uploaded to the remote payment service.\n\n#### 问题 B：减少“自动化”措辞\n\n少用：\n\n- 自动读取整个记忆库\n- 自动执行后续任务\n- 自动沉淀长期记忆\n\n改成：\n\n- 在当前步骤按用户确认读取必要文件\n- 本地执行指定的记忆操作\n- 每一步都由用户触发\n\n#### 问题 C：加强用户告知\n\n在 `SKILL.md` 中明确增加：\n\n1. 本地订单文件会保存订单元数据\n2. 不上传 Obsidian 仓库正文\n3. 支付验证阶段仅发送最小支付信息和支付凭证\n4. 任何本地记忆读取/写入都在支付成功后、本地执行\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 收紧 `SERVER_URL`\n   - 增加 NOTICE\n\n2. 再改 `service.py`\n   - 不再承担“记忆执行”语义\n   - 只做支付校验和授权结果获取\n   - 去掉对本地原始请求的依赖\n\n3. 再改 `SKILL.md`\n   - 改写为“本地记忆执行 + 远程支付授权”双层结构\n   - 消除描述与行为不一致\n\n4. 最后发 ClawHub 新 patch 版本\n\n## 关键设计原则\n\n对这个技能，最重要的不是“减少联网”，而是：\n\n- 让联网行为只承担支付授权\n- 让 Obsidian 能力只承担本地执行\n- 让本地敏感请求不再长期保存\n- 让文档描述和代码行为一致\n\n## 备注\n\n当前这版被打中，不是因为 ClawHub 认为“不能做付费记忆技能”，而是因为：\n\n- 代码看起来像“用记忆技能名义进行远程请求”\n- 同时本地又长期保存了记忆原文\n\n下一版只要把这两个点拆开，风险就会明显下降。\n\nFile v3.0.32:skill-card.md\n\n## Description: <br>\nPersistent memory system using Obsidian as local storage for daily work logs, task tracking, decision records, and cross-session context continuity, with local memory processing and remote payment verification. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and AI coding-agent users use this skill to maintain local Obsidian-based memory across sessions, including work logs, tasks, decisions, reviews, and recall. The release also includes a payment and authorization flow before the local memory workflow is used. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill requests broad local file read/write access for Obsidian memory operations. <br>\nMitigation: Configure a narrow Obsidian vault or path and avoid using the skill on sensitive vaults until file scoping is clearer. <br>\nRisk: The payment flow sends a local payment credential to https://api.ideaidea.com.cn. <br>\nMitigation: Install only if this remote verification flow is acceptable, confirm the endpoint before use, and avoid entering unrelated secrets into the order flow. <br>\nRisk: Local order files may persist after payment verification. <br>\nMitigation: Delete local order files when no longer needed. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [Payment verification endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and generated local Obsidian note content] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May read and write local Obsidian vault files after user confirmation and may create local payment order metadata files.] <br>\n\n## Skill Version(s): <br>\n3.0.32 (source: server release metadata; artifact frontmatter lists 3.0.33) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: obsidian-memory-system Owner: jinyu12166 Summary: Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via clawtip. No vault content, note files, or credentials are collected or transmitted. Tags: latest:3.1.2 Version history: v3.1.2 | 2026-07-28T14:51:22.967Z | user - Language support broadened: skill now r","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"openclaw skills install clawtip"},{"language":"bash","snippet":"python3 scripts/create_order.py \"<question>\""},{"language":"bash","snippet":"npx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12"},{"language":"bash","snippet":"python3 scripts/service.py \"<order_no>\""},{"language":"bash","snippet":"openclaw skills install clawtip"},{"language":"bash","snippet":"python3 scripts/create_order.py \"<question>\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: \"obsidian-memory-system\"\nversion: \"3.1.2\"\ndescription: >\n  Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via clawtip. No vault content, note files, or credentials are collected or transmitted.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# obsidian-memory-system\n\nInteract in the user's language. Supports Chinese, English, and other languages based on user input.\n\n## 技能概述\n\nObsidian 永久记忆系统。本技能通过 clawtip 完成支付验证后，**由 AI 模型在对话中**交付工作日志、任务追踪、决策记录和跨会话的项目上下文管理。\n\n### 服务交付方式\n\n本技能是 **AI 对话交付型** 服务：\n- `create_order.py` — 创建本地订单文件（仅用于 clawtip 支付验证）\n- 支付由 **clawtip** 官方钱包处理\n- `service.py` — 验证支付凭证后，指示 AI 在对话中执行记忆管理\n\n### 交付内容\n\n| # | 服务 | 说明 |\n|---|------|------|\n| 1 | 工作日志 | 结构化日记创建、任务追踪和进度记录 |\n| 2 | 决策记录 | 架构和设计决策的文档化 |\n| 3 | 会话连续性 | 跨 AI 会话的上下文保持 |\n| 4 | 知识管理 | 笔记组织和链接、模板化写作 |\n| 5 | 定期回顾 | 周/月报、记忆整理和精炼 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n> 本地订单文件路径：`~/.openclaw/skills/orders/{indicator}/{order_no}.json`\n> 仅包含 orderNo、amount、question。不涉及任何笔记内容。\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n**失败：** `Order creation failed: <详情>` → 终止。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n成功后，AI 将在对话中交付记忆管理服务。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n| 文件 | 路径 | 内容 |\n|------|------|------|\n| 订单文件 | `~/.openclaw/skills/orders/{indicator}/{order_no}.json` | orderNo、amount、question、加密凭证 |\n\n### 远程传输\n本技能自身不发起任何远程 HTTP 请求。\n\n### 绝不收集或传输\nObsidian 库内容、笔记文件、模板、项目文件或凭证。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.1.1 | 2026-07-28 | Fix SkillSpector: inline file_utils/SM4; service delivery specification; English error messages |\n| 3.1.0 | 2026-07-28 | Switch to official clawtip wallet |\n| 3.0.37 | 2026-07-27 | Fix ClawHub audit |"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"obsidian-memory-system-clawhub-reviewfix\",\n  \"version\": \"3.1.2\",\n  \"publishedAt\": 1785250282967\n}"},{"path":"skill-card.md","content":"## Description:\n\nObsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jinyu12166](https://clawhub.ai/user/jinyu12166)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users and developers use this skill to receive AI-delivered Obsidian memory support after clawtip payment verification, including work logs, task tracking, decision records, session continuity, note organization, and periodic reviews.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill requests broad filesystem and credential permissions while saving the user's question locally.\n\nMitigation: Review before installing, and do not include secrets, vault excerpts, API keys, or private project details in the question.\n\nRisk: The payment-verification helpers are weak and may affect payment integrity.\n\nMitigation: Treat payment authorization as a local gate only and review clawtip payment status before relying on service access.\n\nRisk: The optional sandbox payment command invokes npx.\n\nMitigation: Run the sandbox payment command only in a constrained environment if it is needed.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/jinyu12166/skills/obsidian-memory-system-clawhub-reviewfix)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Markdown and terminal text with JSON_RESULT status lines from helper scripts]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Responds in the user's language and stores payment order data locally before service authorization.]\n\n## Skill Version(s):\n\n3.1.2 (source: frontmatter and server release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via clawtip. No vault content, note files, or credentials are collected or transmitted. Skill: obsidian-memory-system Owner: jinyu12166 Summary: Obsidian persistent memory system: AI-delivered session continuity, task tracking, decision records, and project context for AI agents. Payment verification via clawtip. No vault content, note files, or credentials are collected or transmitted. Tags: latest:3.1.2 Version history: v3.1.2 | 2026-07-28T14:51:22.967Z | user - Language support broadened: skill now r","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1125,"uniquenessScore":48,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T23:48:07.681Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T23:48:07.681Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T06:44:46.712Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}