{"id":"7923961c-13f6-4661-958f-4b24894d86c8","entityType":"agent","slug":"clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review","name":"soft-ip-full-lifecycle-zijian","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review","canonicalPath":"/agent/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review","generatedAt":"2026-10-10T05:55:44.300Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-10T02:00:42.040Z","emptyReason":null},"description":"Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Skill: soft-ip-full-lifecycle-zijian Owner: jinyu12166 Summary: Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Tags: latest:3.1.38 Version history: v3.1.38 | 2026-07-","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.8K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s17bk5y82fk590863n8fb20zvn8afqra:soft-ip-full-lifecycle-zijian-clawhub-reviewfix","sourceUrl":"https://clawhub.ai/jinyu12166/soft-ip-full-lifecycle-zijian-clawhub-reviewfix","homepage":"https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jinyu12166/soft-ip-full-lifecycle-zijian-clawhub-reviewfix","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":65,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code docum"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T02:00:42.040Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T02:00:42.040Z","emptyReason":null},"stars":null,"forks":null,"downloads":1788,"packageName":null,"latestVersion":"3.1.38","tractionLabel":"1.8K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T02:00:42.040Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T02:00:42.040Z","lastCrawledAt":"2026-10-10T02:00:42.040Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T02:00:42.040Z","lastVerifiedAt":null,"highlights":[{"version":"3.1.38","createdAt":"2026-07-28T13:47:51.367Z","changelog":"Version 3.1.38 - Inlined file utilities and SM4 encryption code directly into main scripts; removed external utility files. - Updated SKILL.md to document English error messages, service delivery method, and Chinese-language interface. - Expanded description of compliance review steps and data privacy guarantees. - Adjusted permissions: removed network outbound permission. - Minor documentation and configuration updates to clarify usage and dependencies.","fileCount":5,"zipByteSize":9344},{"version":"3.1.37","createdAt":"2026-07-28T12:47:09.893Z","changelog":"**3.2.0 summary: Switch to official clawtip wallet and remove remote API dependencies.** - Now uses official clawtip wallet for payment verification; removed api.ideaidea.com.cn integration. - Added scripts/sm4_utils.py utility module. - Removed obsolete skill-card.md documentation file. - Updated documentation and workflow details to align with clawtip-only processing. - Enhanced environment variable and setup instructions for clarity.","fileCount":7,"zipByteSize":8632},{"version":"3.1.36","createdAt":"2026-07-28T12:02:53.143Z","changelog":"Version 3.2.0 - Switched payment and verification to the official clawtip wallet; removed api.ideaidea.com.cn integration. - Updated workflow and data processing: skill no longer performs remote HTTP requests. - Added scripts/sm4_utils.py for utility support. - Removed obsolete skill-card.md file. - Clarified environment variable requirements for payment and encryption. - Revised documentation and workflow structure for clarity and compliance.","fileCount":7,"zipByteSize":8395},{"version":"3.1.35","createdAt":"2026-07-28T08:19:29.826Z","changelog":"- Removed the skill-card.md file. - Updated scripts/service.py.","fileCount":6,"zipByteSize":7119},{"version":"3.1.34","createdAt":"2026-07-28T03:36:08.699Z","changelog":"- ClawHub audit compliance: removed unsupported SM4 encryption and local-processing claims. - Updated privacy disclosure: clarified accurate AI-delivered result handling; no claim of Chinese-only interaction. - Removed misleading statements about strictly local file analysis. - Documentation files CLAWHUB_REVIEW_FIXES.md and skill-card.md were removed for clarity and compliance. - Version number updated to 3.1.34.","fileCount":6,"zipByteSize":7696},{"version":"3.1.33","createdAt":"2026-07-21T14:00:35.401Z","changelog":"- Workflow now defined directly in SKILL.md via a new workflow section, listing create_order, pay, and service steps. - Removed outdated skill-card.md file for streamlined documentation. - No changes to user functionality, but skill packaging and metadata improved for automation and compliance.","fileCount":7,"zipByteSize":12116},{"version":"3.1.32","createdAt":"2026-07-21T10:29:43.683Z","changelog":"- Removed the skill-card.md file. - Updated SKILL.md to clarify that user questions and encrypted payment credentials are transmitted via HTTPS to the third-party verification service for order creation and fulfillment. - Added user-facing prompts before network operations to further clarify data transmission scope. - Improved privacy and data handling explanations in SKILL.md. - No source code or sensitive document flow changed; documentation and compliance notes have been strengthened.","fileCount":7,"zipByteSize":11934},{"version":"3.1.31","createdAt":"2026-07-20T15:47:27.832Z","changelog":"- Security and compliance update: fully restructured documentation for SkillSpector compliance - Capability descriptions now appear at the top and cross-referenced with related skills (e.g., delivery-pro) - Data handling and privacy disclosure is more detailed and transparent - Explicit affirmation: all materials analyzed on device, no source code or sensitive documents uploaded - Removed redundant skill-card.md file for clarity","fileCount":7,"zipByteSize":11566}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17bk5y82fk590863n8fb20zvn8afqra:soft-ip-full-lifecycle-zijian-clawhub-reviewfix","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T05:55:44.297Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian-clawhub-review/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-10T02:00:42.040Z","emptyReason":null},"readme":"Skill: soft-ip-full-lifecycle-zijian\n\nOwner: jinyu12166\n\nSummary: Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip\n\nTags: latest:3.1.38\n\nVersion history:\n\nv3.1.38 | 2026-07-28T13:47:51.367Z | auto\n\nVersion 3.1.38\n\n- Inlined file utilities and SM4 encryption code directly into main scripts; removed external utility files.\n- Updated SKILL.md to document English error messages, service delivery method, and Chinese-language interface.\n- Expanded description of compliance review steps and data privacy guarantees.\n- Adjusted permissions: removed network outbound permission.\n- Minor documentation and configuration updates to clarify usage and dependencies.\n\nv3.1.37 | 2026-07-28T12:47:09.893Z | user\n\n**3.2.0 summary: Switch to official clawtip wallet and remove remote API dependencies.**\n\n- Now uses official clawtip wallet for payment verification; removed api.ideaidea.com.cn integration.\n- Added scripts/sm4_utils.py utility module.\n- Removed obsolete skill-card.md documentation file.\n- Updated documentation and workflow details to align with clawtip-only processing.\n- Enhanced environment variable and setup instructions for clarity.\n\nv3.1.36 | 2026-07-28T12:02:53.143Z | user\n\nVersion 3.2.0\n\n- Switched payment and verification to the official clawtip wallet; removed api.ideaidea.com.cn integration.\n- Updated workflow and data processing: skill no longer performs remote HTTP requests.\n- Added scripts/sm4_utils.py for utility support.\n- Removed obsolete skill-card.md file.\n- Clarified environment variable requirements for payment and encryption.\n- Revised documentation and workflow structure for clarity and compliance.\n\nv3.1.35 | 2026-07-28T08:19:29.826Z | auto\n\n- Removed the skill-card.md file.\n- Updated scripts/service.py.\n\nv3.1.34 | 2026-07-28T03:36:08.699Z | user\n\n- ClawHub audit compliance: removed unsupported SM4 encryption and local-processing claims.\n- Updated privacy disclosure: clarified accurate AI-delivered result handling; no claim of Chinese-only interaction.\n- Removed misleading statements about strictly local file analysis.\n- Documentation files CLAWHUB_REVIEW_FIXES.md and skill-card.md were removed for clarity and compliance.\n- Version number updated to 3.1.34.\n\nv3.1.33 | 2026-07-21T14:00:35.401Z | user\n\n- Workflow now defined directly in SKILL.md via a new workflow section, listing create_order, pay, and service steps.\n- Removed outdated skill-card.md file for streamlined documentation.\n- No changes to user functionality, but skill packaging and metadata improved for automation and compliance.\n\nv3.1.32 | 2026-07-21T10:29:43.683Z | user\n\n- Removed the skill-card.md file.\n- Updated SKILL.md to clarify that user questions and encrypted payment credentials are transmitted via HTTPS to the third-party verification service for order creation and fulfillment.\n- Added user-facing prompts before network operations to further clarify data transmission scope.\n- Improved privacy and data handling explanations in SKILL.md.\n- No source code or sensitive document flow changed; documentation and compliance notes have been strengthened.\n\nv3.1.31 | 2026-07-20T15:47:27.832Z | user\n\n- Security and compliance update: fully restructured documentation for SkillSpector compliance\n- Capability descriptions now appear at the top and cross-referenced with related skills (e.g., delivery-pro)\n- Data handling and privacy disclosure is more detailed and transparent\n- Explicit affirmation: all materials analyzed on device, no source code or sensitive documents uploaded\n- Removed redundant skill-card.md file for clarity\n\nv3.1.30 | 2026-07-20T09:38:25.684Z | user\n\n- Removed the skill-card.md file.\n- Updated SKILL.md: added version field under metadata and incremented version number to 3.1.30.\n- No changes to core logic or workflow.\n\nv3.1.29 | 2026-07-20T08:38:52.843Z | user\n\n- Improved data privacy explanation and clarified what user data is transmitted and stored locally.\n- Updated description to highlight HTTPS transmission for order creation and explicit local storage of order metadata.\n- Removed the file skill-card.md.\n- Cleaned up metadata: removed obsolete capability payment.process.\n- No functional workflow changes; payment and service execution flows remain the same.\n\nv3.1.28 | 2026-07-20T08:21:08.215Z | user\n\n- Clarified and expanded documentation: added explicit description of the three-phase payment flow and data handling.\n- Updated the skill overview and process to specify HTTPS order creation and local order metadata storage.\n- Refined data privacy section to detail what information is transmitted and stored.\n- Removed permissions for payment.process capability.\n- Deleted unnecessary skill-card.md file for simpler maintenance.\n\nv3.1.27 | 2026-07-20T05:27:26.856Z | user\n\n- Removed the skill-card.md file.\n- No other changes were made to the code or documentation.\n\nv3.1.26 | 2026-07-20T02:35:06.727Z | user\n\n- Updated documentation and workflow for order creation, payment processing, and service execution to improve clarity and match clawtip requirements.\n- Added \"question\" parameter to order creation step and revised command usage instructions.\n- Standardized status output formats for service execution and clarified error handling.\n- Removed the skill-card.md file.\n\nv3.1.25 | 2026-07-19T10:29:39.566Z | user\n\n- 增加了 6 个新文件（主要为 scripts 相关的 .pyc 缓存文件）。\n- 移除了文档要求用中文展示思考过程，简化为“请使用中文和用户交互”。\n- 其余功能流程未发生变动。\n\nv3.1.24 | 2026-07-19T10:05:48.201Z | user\n\nVersion 3.1.24\n\n- Removed the skill-card.md file.\n- Updated SKILL.md: streamlined to a fully Chinese, step-by-step workflow focusing on payment and service execution.\n- Clarified order creation and payment process, with detailed command usage and error handling.\n- Added explicit security and data privacy statements.\n- The new documentation presents a concise \"one-order, one-service\" workflow for soft IP draft generation assistance.\n\nv3.1.23 | 2026-07-19T09:26:29.855Z | user\n\nFix: remove auto-open browser; add file write warning; add language note\n\nv3.1.21 | 2026-07-19T07:25:28.305Z | user\n\nFix: use server-hosted QR code (.png); fix image format\n\nv3.1.20 | 2026-07-19T07:11:36.819Z | user\n\nAdd auto QR code; remove contact-developer\n\nv3.0.18 | 2026-07-18T10:20:12.727Z | user\n\nAdded QR payment option in script output\n\nv1.0.0 | 2026-07-18T10:08:08.112Z | user\n\nAdded quick QR payment option\n\nArchive index:\n\nArchive v3.1.38: 5 files, 9344 bytes\n\nFiles: scripts/create_order.py (8173b), scripts/service.py (4377b), skill-card.md (2567b), SKILL.md (4699b), _meta.json (167b)\n\nFile v3.1.38:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\nversion: \"3.2.1\"\ndescription: >\n  Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip. Chinese-language service (中国软件著作权申报所需).\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# soft-ip-full-lifecycle-zijian\n\n**语言说明 / Language:** This skill is designed for Chinese software copyright compliance (中国软件著作权申报), and its user-facing interface is primarily in Chinese. Core metadata and technical documentation are in English for accessibility.\n\n## 技能概述\n\n软件知识产权全生命周期自检与合规审查服务。本技能通过 clawtip 完成支付验证后，**由 AI 模型在对话中**交付合规诊断和材料审查结果。\n\n### 服务交付方式\n\n本技能是 **AI 对话交付型** 服务：\n- `create_order.py` — 创建本地订单文件（仅用于 clawtip 支付验证）\n- 支付由 **clawtip** 官方钱包处理\n- `service.py` — 验证支付凭证后，指示 AI 在对话中执行以下 5 项评估\n\n### 5 项合规评估\n\n| # | 评估项 | 说明 |\n|---|--------|------|\n| 1 | 材料完整性审查 | 对照软著登记要求逐项检查材料是否齐全 |\n| 2 | 源代码文档审计 | 格式验证、页数检查、前/后30页完整性 |\n| 3 | 用户手册合规检查 | 截图格式、功能描述完整性 |\n| 4 | 权利归属验证 | 权属声明、合作协议框架检查 |\n| 5 | 登记就绪评估 | 风险分级（阻塞性 / 建议性 / 参考性），修复建议 |\n\n### 与 delivery-pro 的关系\n\n| 维度 | zijian（本技能，诊断版） | delivery-pro（生成版） |\n|------|------------------------|-----------------------|\n| 用途 | 合规性诊断：识别缺失和问题 | 文档生成：填写全部 8 项申报材料 |\n| 价格 | 190 UT (1.9 元) | 690 UT (6.9 元) |\n| 输出 | 缺失清单 + 问题标注 + 风险评级 | 完整的可提交文档草稿 |\n| 建议顺序 | 先运行：诊断问题，补充材料 | 后运行：基于完善的材料生成文档 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥 |\n\n> 以上环境变量仅用于 clawtip 支付凭证加密，不收集、不传输任何业务数据。\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n> 本地订单文件路径：`~/.openclaw/skills/orders/{indicator}/{order_no}.json`\n> 包含字段：orderNo、amount、question。仅用于支付验证，不涉及任何审查材料。\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n**失败：** `订单创建失败: <详情>` → 终止。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：合规审查\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n成功后，AI 模型将在对话中输出完整的合规评估报告。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n| 文件 | 路径 | 内容 |\n|------|------|------|\n| 订单文件 | `~/.openclaw/skills/orders/{indicator}/{order_no}.json` | orderNo、amount、question、加密凭证 |\n\n### 远程传输\n本技能自身不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n### 绝不收集或传输\n源代码、申报文档、著作权人信息、公司信息或商业秘密。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.2.1 | 2026-07-28 | Fix SkillSpector: inline file_utils/SM4; English error messages; service delivery spec; add permissions; justify Chinese locale |\n| 3.2.0 | 2026-07-28 | Switch to official clawtip wallet |\n| 3.1.34 | 2026-07-28 | Fix ClawHub audit |\n| 3.1.33 | 2026-07-20 | Security review |\n\nFile v3.1.38:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.38\",\n  \"publishedAt\": 1785246471367\n}\n\nFile v3.1.38:skill-card.md\n\n## Description:\n\nSoftware IP self-assessment for Chinese software copyright applications, including material completeness checks, source code documentation audit prompts, user manual review, rights attribution verification, registration readiness assessment, and payment verification through clawtip.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jinyu12166](https://clawhub.ai/user/jinyu12166)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, founders, and software copyright applicants use this skill to receive a Chinese-language readiness review before preparing or submitting Chinese software copyright registration materials. It helps identify missing materials, documentation issues, rights attribution concerns, and remediation steps after local payment authorization.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: User questions are stored locally under the user's home directory and may contain sensitive source code, applicant details, trade secrets, or ownership facts.\n\nMitigation: Keep the initial question minimal and avoid including sensitive materials unless local cleartext storage is acceptable.\n\nRisk: Payment authorization is based on local order and credential files and should not be treated as strong proof of payment.\n\nMitigation: Use this package's payment status only as a local workflow gate and rely on the official clawtip payment flow for payment handling.\n\nRisk: The documented sandbox payment command executes an npx package at runtime.\n\nMitigation: Run the sandbox payment command only in a contained environment after reviewing the package and command arguments.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix)\n- [Publisher profile](https://clawhub.ai/user/jinyu12166)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Conversational assessment report with shell command output and JSON status summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Outputs are primarily Chinese-language compliance review guidance delivered after local order and payment checks.]\n\n## Skill Version(s):\n\n3.1.38 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v3.1.37: 7 files, 8632 bytes\n\nFiles: scripts/create_order.py (3282b), scripts/file_utils.py (2170b), scripts/service.py (2102b), scripts/sm4_utils.py (3302b), skill-card.md (2505b), SKILL.md (3080b), _meta.json (167b)\n\nFile v3.1.37:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\nversion: \"3.2.0\"\ndescription: >\n  Software IP full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. AI-delivered service via clawtip verification.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# soft-ip-full-lifecycle-zijian\n\n## 技能概述\n\n软件知识产权全生命周期自检与合规审查服务。付费服务，通过 clawtip 完成支付验证后由 AI 交付合规诊断和材料审查。\n\n**直接执行：** 如用户已提供带支付凭证的订单号，直接跳到第三阶段。\n\n### 与 delivery-pro 的关系\n\n| 维度 | zijian（本技能，诊断版） | delivery-pro（生成版） |\n|------|------------------------|-----------------------|\n| 用途 | 合规性诊断：识别缺失和问题 | 文档生成：填写全部 8 项申报材料 |\n| 价格 | 190 UT (1.9 元) | 690 UT (6.9 元) |\n| 输出 | 缺失清单 + 问题标注 + 风险评级 | 完整的可提交文档草稿 |\n| 建议顺序 | 先运行：诊断问题，补充材料 | 后运行：基于完善的材料生成文档 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥（十六进制，32 字符） |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n\n**失败：** `订单创建失败: <详情>` → 终止工作流。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n输出 `PAY_STATUS: SUCCESS | ERROR`。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n订单元数据保存至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`。\n\n### 远程传输\n本技能不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.2.0 | 2026-07-28 | Switch to official clawtip wallet; remove api.ideaidea.com.cn |\n| 3.1.34 | 2026-07-28 | Fix ClawHub audit |\n| 3.1.33 | 2026-07-20 | Security review for SkillSpector |\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.37:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.37\",\n  \"publishedAt\": 1785242829893\n}\n\nFile v3.1.37:skill-card.md\n\n## Description: <br>\nSoftware IP full lifecycle self-assessment for Chinese software copyright applications, covering material completeness, compliance verification, and registration readiness after clawtip payment verification. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, software teams, and applicants use this skill to check whether Chinese software copyright application materials are complete, compliant, and ready for registration before moving to document generation or filing. <br>\n\n### Deployment Geography for Use: <br>\nChina <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill asks users to complete a clawtip payment flow before service execution. <br>\nMitigation: Install only if you accept the clawtip-gated workflow and can verify the order, amount, payee configuration, and payment status before relying on the output. <br>\nRisk: The security summary says the artifact mostly implements payment authorization and does not define the promised IP self-assessment service in enough detail. <br>\nMitigation: Confirm the expected review deliverables before use, and treat the result as preliminary guidance that still needs independent legal or filing review. <br>\nRisk: Order and payment metadata are stored under the local OpenClaw orders directory. <br>\nMitigation: Protect local order files and related environment variables, and avoid including sensitive application material unless that local storage behavior is acceptable. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration] <br>\n**Output Format:** [Markdown guidance with command-line status lines and JSON_RESULT summaries] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires clawtip payment verification and local order metadata before the AI-delivered compliance review proceeds.] <br>\n\n## Skill Version(s): <br>\n3.1.37 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.36: 7 files, 8395 bytes\n\nFiles: scripts/create_order.py (2962b), scripts/file_utils.py (2170b), scripts/service.py (2102b), scripts/sm4_utils.py (3302b), skill-card.md (2295b), SKILL.md (3080b), _meta.json (167b)\n\nFile v3.1.36:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\nversion: \"3.2.0\"\ndescription: >\n  Software IP full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. AI-delivered service via clawtip verification.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# soft-ip-full-lifecycle-zijian\n\n## 技能概述\n\n软件知识产权全生命周期自检与合规审查服务。付费服务，通过 clawtip 完成支付验证后由 AI 交付合规诊断和材料审查。\n\n**直接执行：** 如用户已提供带支付凭证的订单号，直接跳到第三阶段。\n\n### 与 delivery-pro 的关系\n\n| 维度 | zijian（本技能，诊断版） | delivery-pro（生成版） |\n|------|------------------------|-----------------------|\n| 用途 | 合规性诊断：识别缺失和问题 | 文档生成：填写全部 8 项申报材料 |\n| 价格 | 190 UT (1.9 元) | 690 UT (6.9 元) |\n| 输出 | 缺失清单 + 问题标注 + 风险评级 | 完整的可提交文档草稿 |\n| 建议顺序 | 先运行：诊断问题，补充材料 | 后运行：基于完善的材料生成文档 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥（十六进制，32 字符） |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n\n**失败：** `订单创建失败: <详情>` → 终止工作流。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n输出 `PAY_STATUS: SUCCESS | ERROR`。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n订单元数据保存至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`。\n\n### 远程传输\n本技能不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.2.0 | 2026-07-28 | Switch to official clawtip wallet; remove api.ideaidea.com.cn |\n| 3.1.34 | 2026-07-28 | Fix ClawHub audit |\n| 3.1.33 | 2026-07-20 | Security review for SkillSpector |\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.36:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.36\",\n  \"publishedAt\": 1785240173143\n}\n\nFile v3.1.36:skill-card.md\n\n## Description: <br>\nSoftware IP full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users use this skill as a paid ClawHub/OpenClaw workflow to create a clawtip order and, after payment verification, request AI-delivered review of material completeness, compliance, and registration readiness for Chinese software copyright applications. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The release may not deliver the complete expert audit workflow described in the skill summary because the security evidence says the artifacts mostly implement payment authorization. <br>\nMitigation: Review the installed skill before use and confirm that the expected self-assessment logic or service delivery path exists before relying on the paid workflow. <br>\nRisk: The skill stores order metadata locally and uses payment credentials as part of the authorization flow. <br>\nMitigation: Use a trusted OpenClaw environment, protect local order files, and verify clawtip payment status before proceeding with any review work. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, shell commands, configuration, JSON] <br>\n**Output Format:** [Markdown instructions with shell commands and JSON-style status lines] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires clawtip and local order metadata stored under the user's OpenClaw orders directory.] <br>\n\n## Skill Version(s): <br>\n3.1.36 (source: server release metadata; artifact frontmatter and changelog state 3.2.0) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.35: 6 files, 7119 bytes\n\nFiles: scripts/create_order.py (3384b), scripts/file_utils.py (2170b), scripts/service.py (2800b), skill-card.md (2073b), SKILL.md (3949b), _meta.json (167b)\n\nFile v3.1.35:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\ndescription: >\n  Software IP full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. AI-delivered service. Question text and order metadata are transmitted via HTTPS to api.ideaidea.com.cn for order creation and fulfillment. No source code or project files are uploaded.\nmetadata:\n  author: \"Yujin\"\n  version: \"3.1.34\"\n  category: \"expert\"\n  capabilities:\n    - \"payment.process\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip-skill\"\n---\n\n# soft-ip-full-lifecycle-zijian\n\n## Skill Overview\n\nSoftware IP full lifecycle self-assessment and compliance review service. This is a paid service; payment verification is handled via clawtip, and the AI model delivers compliance diagnosis and material review in the conversation context.\n\n**Direct execution:** If the user has already provided an <<order_no>> (and the order file already contains payCredential), skip directly to the third stage.\n\n### Relationship with soft-ip-full-lifecycle-delivery-pro\n\n| | zijian (this skill, diagnostic edition) | delivery-pro (generation edition) |\n|---|---|---|\n| Purpose | Compliance diagnosis: identify gaps and issues | Document generation and delivery: fill out all 8 application materials |\n| Price | 190 UT (1.9 yuan) | 690 UT (6.9 yuan) |\n| Output | Gap checklist + issue annotations + risk grading | Complete submission-ready document drafts |\n| Suggested order | Run first: diagnose issues and supplement materials | Run after: generate documents based on supplemented materials |\n\n**Recommended: run this skill first for compliance review, then use delivery-pro for document generation.**\n\n### Capabilities\n\n- Material completeness review: checklist against copyright registration requirements\n- Source code documentation compliance: format validation, 30-page requirement check\n- User manual audit: screenshot format, feature description completeness\n- Rights attribution check: ownership declarations, collaboration agreements\n- Registration readiness audit: risk grading (blocking/advisory/informational)\n\n---\n\n## First Stage: Create Order\n\n### 1. Required Parameters\n* `<question>`: the user specific question or content.\n\n### 2. Execution Command\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n### 3. Output Processing\n**On success:** ORDER_NO, AMOUNT, QUESTION, INDICATOR\nAMOUNT is in RMB fen (divide by 100 for yuan).\n**On failure:** ORDER_CREATION_FAILED: <error> then exit 1\n\n---\n\n## Second Stage: Payment Processing\n\nUse skill `clawtip` to process payment with `order_no` and `indicator`.\n\n---\n\n## Third Stage: Service Execution\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\nOutput: PAY_STATUS: SUCCESS|PROCESSING|FAIL|ERROR\n\n---\n\n## Data Handling\n\n### Local Storage\nOrder metadata saved to ~/.openclaw/skills/orders/{indicator}/{order_no}.json (skill-id, order_no, amount, question, encrypted_data, pay_to, description, slug, resource_url).\n\n### Remote Transmission\n- Phase 1: Sends slug + question text to api.ideaidea.com.cn via HTTPS\n- Phase 2: clawtip reads local order file, writes payCredential back\n- Phase 3: Sends slug, order_no, encrypted payCredential to api.ideaidea.com.cn\n\n### Not Collected or Transmitted\nNo source code, application documents, company information, contract files, trade secrets, or personal identity information is read or uploaded. Service results delivered by AI in conversation.\n\n---\n\n## Version History\n\n| Version | Date | Notes |\n|:---|:---|:---|\n| 3.1.34 | 2026-07-28 | Fix ClawHub audit: remove false SM4 claims, accurate AI-delivered disclosure, remove Chinese-only policy, remove false local-processing claims |\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance |\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.35:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.35\",\n  \"publishedAt\": 1785226769826\n}\n\nFile v3.1.35:skill-card.md\n\n## Description: <br>\nSoftware IP full lifecycle self-assessment for material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, founders, and software teams use this skill to assess Chinese software copyright application readiness, identify missing materials or compliance issues, and decide whether to proceed to document generation. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Question text and payment credential/order data are sent to api.ideaidea.com.cn over HTTPS, and order metadata is stored locally under the OpenClaw orders directory. <br>\nMitigation: Avoid including source code, legal documents, trade secrets, personal identity information, or other sensitive material in the question unless the user accepts sending that text to the service provider. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix) <br>\n- [Artifact skill definition](artifact/SKILL.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Conversational Markdown plus helper-script command output for order creation and payment verification.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Paid service flow; service results are delivered in the conversation after order creation and payment verification.] <br>\n\n## Skill Version(s): <br>\n3.1.35 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.34: 6 files, 7696 bytes\n\nFiles: scripts/create_order.py (3384b), scripts/file_utils.py (2170b), scripts/service.py (4453b), skill-card.md (2449b), SKILL.md (3949b), _meta.json (167b)\n\nFile v3.1.34:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\ndescription: >\n  Software IP full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. AI-delivered service. Question text and order metadata are transmitted via HTTPS to api.ideaidea.com.cn for order creation and fulfillment. No source code or project files are uploaded.\nmetadata:\n  author: \"Yujin\"\n  version: \"3.1.34\"\n  category: \"expert\"\n  capabilities:\n    - \"payment.process\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip-skill\"\n---\n\n# soft-ip-full-lifecycle-zijian\n\n## Skill Overview\n\nSoftware IP full lifecycle self-assessment and compliance review service. This is a paid service; payment verification is handled via clawtip, and the AI model delivers compliance diagnosis and material review in the conversation context.\n\n**Direct execution:** If the user has already provided an <<order_no>> (and the order file already contains payCredential), skip directly to the third stage.\n\n### Relationship with soft-ip-full-lifecycle-delivery-pro\n\n| | zijian (this skill, diagnostic edition) | delivery-pro (generation edition) |\n|---|---|---|\n| Purpose | Compliance diagnosis: identify gaps and issues | Document generation and delivery: fill out all 8 application materials |\n| Price | 190 UT (1.9 yuan) | 690 UT (6.9 yuan) |\n| Output | Gap checklist + issue annotations + risk grading | Complete submission-ready document drafts |\n| Suggested order | Run first: diagnose issues and supplement materials | Run after: generate documents based on supplemented materials |\n\n**Recommended: run this skill first for compliance review, then use delivery-pro for document generation.**\n\n### Capabilities\n\n- Material completeness review: checklist against copyright registration requirements\n- Source code documentation compliance: format validation, 30-page requirement check\n- User manual audit: screenshot format, feature description completeness\n- Rights attribution check: ownership declarations, collaboration agreements\n- Registration readiness audit: risk grading (blocking/advisory/informational)\n\n---\n\n## First Stage: Create Order\n\n### 1. Required Parameters\n* `<question>`: the user specific question or content.\n\n### 2. Execution Command\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n### 3. Output Processing\n**On success:** ORDER_NO, AMOUNT, QUESTION, INDICATOR\nAMOUNT is in RMB fen (divide by 100 for yuan).\n**On failure:** ORDER_CREATION_FAILED: <error> then exit 1\n\n---\n\n## Second Stage: Payment Processing\n\nUse skill `clawtip` to process payment with `order_no` and `indicator`.\n\n---\n\n## Third Stage: Service Execution\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\nOutput: PAY_STATUS: SUCCESS|PROCESSING|FAIL|ERROR\n\n---\n\n## Data Handling\n\n### Local Storage\nOrder metadata saved to ~/.openclaw/skills/orders/{indicator}/{order_no}.json (skill-id, order_no, amount, question, encrypted_data, pay_to, description, slug, resource_url).\n\n### Remote Transmission\n- Phase 1: Sends slug + question text to api.ideaidea.com.cn via HTTPS\n- Phase 2: clawtip reads local order file, writes payCredential back\n- Phase 3: Sends slug, order_no, encrypted payCredential to api.ideaidea.com.cn\n\n### Not Collected or Transmitted\nNo source code, application documents, company information, contract files, trade secrets, or personal identity information is read or uploaded. Service results delivered by AI in conversation.\n\n---\n\n## Version History\n\n| Version | Date | Notes |\n|:---|:---|:---|\n| 3.1.34 | 2026-07-28 | Fix ClawHub audit: remove false SM4 claims, accurate AI-delivered disclosure, remove Chinese-only policy, remove false local-processing claims |\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance |\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.34:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.34\",\n  \"publishedAt\": 1785209768699\n}\n\nFile v3.1.34:skill-card.md\n\n## Description: <br>\nSoftware IP full lifecycle self-assessment for Chinese software copyright applications, covering material completeness review, compliance verification, registration readiness audit, paid order creation, and AI-delivered service results. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, software teams, and applicants preparing Chinese software copyright registration materials use this skill to start a paid self-assessment and receive AI-delivered guidance on completeness, compliance gaps, and registration readiness. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Paid fulfillment may not match the advertised software copyright review or may fail because required analysis scripts are absent. <br>\nMitigation: Do not rely on the paid assessment until the publisher explains and fixes the post-payment service implementation. <br>\nRisk: Question text, order metadata, and payment credentials are transmitted to api.ideaidea.com.cn, and order metadata is written to local order files. <br>\nMitigation: Share only consultation text intended for the service, avoid source code or sensitive legal documents, and inspect local order files before reuse. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Markdown and terminal status text, including order number, amount, payment status, and AI-delivered review guidance.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Paid fulfillment depends on an order number and payment credential; security evidence reports that the fulfillment implementation may not deliver the advertised review.] <br>\n\n## Skill Version(s): <br>\n3.1.34 (source: release evidence and SKILL.md frontmatter) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.33: 7 files, 12116 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6176b), scripts/create_order.py (3688b), scripts/file_utils.py (2170b), scripts/service.py (3155b), skill-card.md (2492b), SKILL.md (6156b), _meta.json (167b)\n\nFile v3.1.33:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. User questions and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No source code, project files, or sensitive legal documents are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.1.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供软件著作权申报材料的自检与合规审查服务。它帮助您在中国版权保护中心申报软著之前，系统性地检查申请材料的完整性与合规性，降低因材料问题导致的补正或驳回风险。\r\n\r\n**所有材料分析在本机完成，您的源代码和申报文档绝不会上传。** 身份验证通过 clawtip 第三方服务进行。\r\n\r\n### 核心能力\r\n\r\n**材料完整性审查**\r\n- 对照软著申报要求逐项核查材料齐备情况\r\n- 标识缺失项（申请表、源代码文档、用户手册、权利归属证明等）\r\n- 生成缺失材料清单及补交优先级建议\r\n\r\n**源代码文档合规检查**\r\n- 检查源代码文档的格式规范性（页眉、页码、行号等）\r\n- 验证前后各 30 页的完整性要求\r\n- 审查代码与软件的对应关系一致性\r\n\r\n**用户手册/说明书审核**\r\n- 检查操作手册的截图格式与清晰度要求\r\n- 验证功能描述的完整性与技术准确性\r\n- 审查版本号、软件名称的一致性\r\n\r\n**权利归属与合规性检查**\r\n- 检查著作权归属声明的完整性与合法性\r\n- 验证合作开发/委托开发协议的存在性与有效性\r\n- 审查职务作品、法人作品的权属说明\r\n\r\n**登记就绪审计**\r\n- 综合判断软著申报的当前就绪状态\r\n- 按风险等级分类问题（阻断性/建议性/提示性）\r\n- 输出可提交性评估与补正建议\r\n\r\n### 与其他技能的关系\r\n\r\n- **本技能定位**：材料诊断与合规审查（告诉您问题在哪、缺什么）\r\n- **soft-ip-full-lifecycle-delivery-pro**（另行安装）：全量文档生成与填写辅助（帮您把 8 份申报材料填好）\r\n- 建议先使用本技能完成诊断，再使用 delivery-pro 进行文档生成\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我检查一下软著申报材料还缺什么\"\r\n- \"我准备了源代码文档，看看格式符不符合要求\"\r\n- \"这份用户手册的截图清晰度够不够过审\"\r\n- \"我的软件是合作开发的，权利归属怎么写\"\r\n- \"提交前帮我做个全面的登记就绪审计\"\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 软著材料的分析与审核由 AI 在本地完成\r\n- 合规检查清单与补正建议在本地生成\r\n- 所有文件读取、格式检查均在本机完成\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- 您的软件源代码（源码仅在本地读取分析）\r\n- 软著申报文档内容（仅在本地审核）\r\n- 公司信息、合同文件、商业机密\r\n- 个人身份信息或联系信息\r\n\r\n每次网络请求前，脚本会明确打印将要传输的数据范围。\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n**所需参数：** `<question>` — 您的软著相关咨询内容。\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nQUESTION=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，输出 `订单创建失败: <错误详情>`，须立即终止流程。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取自检服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付软著材料自检与合规审查结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added cross-reference to delivery-pro, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.33:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.33\",\n  \"publishedAt\": 1784642435401\n}\n\nFile v3.1.33:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: soft-ip-full-lifecycle-zijian\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `soft-ip-full-lifecycle-zijian` 被 ClawHub 标记为 `Needs review`，主要命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Missing User Warnings`\n\n这个清单的目标不是保证 100% 自动放行，而是把最容易触发审计器的点压下来。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 可通过环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n审计器会把它理解成：\n\n- 外发目标可变\n- 可将订单或凭证发往任意地址\n\n#### 修改建议\n\n改成“固定地址”或“白名单校验后才允许使用”。\n\n推荐方案：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n然后校验 `CLAWTIP_SERVER_URL` 的 host，不在白名单就回退到默认值。\n\n#### 问题 B：把原始请求写入本地订单文件\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n软著技能里这个字段通常包含：\n\n- 本地项目路径\n- 项目名\n- 申报目标\n- 用户补充说明\n\n这会被审计器视为“把潜在敏感信息持久化到磁盘”。\n\n#### 修改建议\n\n优先级从高到低：\n\n1. 最优：不要落盘原始 `question`\n2. 次优：只保存摘要，例如：\n\n```python\n\"local_question_summary\": \"software-ip-request\"\n```\n\n3. 如果后续执行必须依赖原始输入，则在 `service.py` 阶段重新要求用户输入，而不是从订单 JSON 回读\n\n#### 问题 C：缺少显式提示\n\n当前脚本虽然最小化上送数据，但对用户没有明确提示：\n\n- 会访问远端支付服务\n- 会在本地保存订单文件\n- 不会上传源码正文\n\n#### 修改建议\n\n在脚本开始输出简短提示，例如：\n\n```python\nprint(\"NOTICE: this step creates a local order file and sends only minimal payment metadata to the payment service.\")\nprint(\"NOTICE: project source files are not uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：发送 `credential` 到远端前没有用户可见提示\n\n当前逻辑会直接把：\n\n- `slug`\n- `orderNo`\n- `credential`\n\n发到远端。\n\n这对支付闭环是必要的，但审计器会视作：\n\n- secret 外发\n- 缺少显式告知\n\n#### 修改建议\n\n在发请求前输出明确说明：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification and fulfillment authorization only.\")\nprint(\"NOTICE: project source files are not uploaded in service verification.\")\n```\n\n#### 问题 B：从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会放大审计器对“本地敏感数据持久化”的判断。\n\n#### 修改建议\n\n改成以下两种之一：\n\n1. 不再依赖本地订单文件保存原始请求，执行时重新输入：\n\n```bash\npython3 scripts/service.py \"<order_no>\" \"<project_path_or_request>\"\n```\n\n2. 或只读取最小摘要，不读取用户原文\n\n#### 问题 C：错误信息里不要暗示会处理完整项目数据\n\n现在文案虽然不算严重，但建议进一步收紧，避免“自动处理整个项目”的感觉。\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：订单文件落在固定用户目录\n\n当前目录：\n\n- Windows: `~/openclaw/skills/orders/{indicator}/`\n- Linux/macOS: `~/.openclaw/skills/orders/{indicator}/`\n\n这个本身不是漏洞，但会被审计器理解为：\n\n- 长期持久化\n- 本地状态残留\n\n#### 修改建议\n\n保留目录结构可以，但要加两点：\n\n1. 在 `save_order` 前只保存最小字段\n2. 在文档中说明这些文件仅用于支付流程，且不保存源码正文\n\n可选增强：\n\n- 增加 TTL / 清理命令\n- 增加注释说明为什么只接受 `indicator` 和 `order_no`\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：能力描述过重\n\n当前文案容易让审计器理解成：\n\n- 自动扫描项目\n- 自动生成 8 份材料\n- 自动推进完整申报流程\n\n这会触发：\n\n- `Excessive Agency`\n- `MCP Tool Poisoning`\n\n#### 修改建议\n\n把措辞统一改成“受限辅助”。\n\n推荐表达：\n\n- “Only generate draft markdown materials after user confirmation.”\n- “Do not submit anything to any official platform.”\n- “Read only the files necessary for the current step.”\n- “Require explicit user confirmation before each document draft.”\n\n#### 问题 B：强化用户确认边界\n\n需要在 `SKILL.md` 里更显眼地写：\n\n1. 只生成草稿\n2. 不自动提交\n3. 不自动上传源码\n4. 每份文档生成前需要用户确认\n5. 支付验证只发送最小元数据和支付凭证\n\n#### 问题 C：补充本地持久化说明\n\n需要明确写：\n\n- 本地订单文件会保存订单元数据\n- 不保存源码正文\n- 如包含项目路径，属于用户本地可见信息，仅用于本地流程衔接\n\n如果你准备彻底规避审计，最好直接移除项目路径落盘。\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 加白名单 URL 校验\n   - 加用户提示\n\n2. 再改 `service.py`\n   - 不再从订单 JSON 读取原始请求\n   - 改成执行时重新传入，或只读摘要\n   - 加发送 `credential` 的提示\n\n3. 再改 `SKILL.md`\n   - 收紧能力描述\n   - 强调用户确认和最小化上送\n\n4. 最后再发 ClawHub 新版本\n   - patch 版本递增\n   - 重新等待审核\n\n## 建议的下一版目标\n\n目标不是“零提示”，而是把结论从：\n\n- `Critical` / `High`\n\n压到：\n\n- 仅人工复核\n- 或更少的中低风险提示\n\n## 备注\n\n`obsidian-memory-system` 之所以更容易过，是因为它的本地持久化和项目路径语义更轻。  \n`soft-ip-full-lifecycle-zijian` 天然更像“读取本地项目后生成材料”，所以必须主动收紧本地存储、外发目标和文案边界。\n\nFile v3.1.33:skill-card.md\n\n## Description: <br>\nSoftware intellectual property full lifecycle self-assessment for Chinese software copyright applications, covering material completeness review, compliance verification, and registration readiness audit while using a third-party clawtip flow for order creation and payment verification. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers use this skill to assess whether Chinese software copyright application materials are complete, consistent, and ready for registration review. It provides local review guidance and uses a paid verification workflow before service fulfillment. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The consultation question, order number, and encrypted payment credential are sent to api.ideaidea.com.cn for paid verification and fulfillment. <br>\nMitigation: Use the skill only when that third-party verification flow is acceptable, and avoid entering confidential source code, contract text, or sensitive company details in the question field. <br>\nRisk: Order metadata is cached in a local order JSON file after the payment flow. <br>\nMitigation: Delete the local order JSON after payment and service completion when continued local retention is not needed. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix) <br>\n- [ClawHub publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [Third-party verification service](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with shell command snippets and JSON-like status output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Chinese-language interaction; service access depends on clawtip payment verification.] <br>\n\n## Skill Version(s): <br>\n3.1.33 (source: evidence release, SKILL.md frontmatter, and version history) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.32: 7 files, 11934 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6176b), scripts/create_order.py (3424b), scripts/file_utils.py (2170b), scripts/service.py (2783b), skill-card.md (2568b), SKILL.md (5845b), _meta.json (167b)\n\nFile v3.1.32:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. User questions and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No source code, project files, or sensitive legal documents are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.1.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供软件著作权申报材料的自检与合规审查服务。它帮助您在中国版权保护中心申报软著之前，系统性地检查申请材料的完整性与合规性，降低因材料问题导致的补正或驳回风险。\r\n\r\n**所有材料分析在本机完成，您的源代码和申报文档绝不会上传。** 身份验证通过 clawtip 第三方服务进行。\r\n\r\n### 核心能力\r\n\r\n**材料完整性审查**\r\n- 对照软著申报要求逐项核查材料齐备情况\r\n- 标识缺失项（申请表、源代码文档、用户手册、权利归属证明等）\r\n- 生成缺失材料清单及补交优先级建议\r\n\r\n**源代码文档合规检查**\r\n- 检查源代码文档的格式规范性（页眉、页码、行号等）\r\n- 验证前后各 30 页的完整性要求\r\n- 审查代码与软件的对应关系一致性\r\n\r\n**用户手册/说明书审核**\r\n- 检查操作手册的截图格式与清晰度要求\r\n- 验证功能描述的完整性与技术准确性\r\n- 审查版本号、软件名称的一致性\r\n\r\n**权利归属与合规性检查**\r\n- 检查著作权归属声明的完整性与合法性\r\n- 验证合作开发/委托开发协议的存在性与有效性\r\n- 审查职务作品、法人作品的权属说明\r\n\r\n**登记就绪审计**\r\n- 综合判断软著申报的当前就绪状态\r\n- 按风险等级分类问题（阻断性/建议性/提示性）\r\n- 输出可提交性评估与补正建议\r\n\r\n### 与其他技能的关系\r\n\r\n- **本技能定位**：材料诊断与合规审查（告诉您问题在哪、缺什么）\r\n- **soft-ip-full-lifecycle-delivery-pro**（另行安装）：全量文档生成与填写辅助（帮您把 8 份申报材料填好）\r\n- 建议先使用本技能完成诊断，再使用 delivery-pro 进行文档生成\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我检查一下软著申报材料还缺什么\"\r\n- \"我准备了源代码文档，看看格式符不符合要求\"\r\n- \"这份用户手册的截图清晰度够不够过审\"\r\n- \"我的软件是合作开发的，权利归属怎么写\"\r\n- \"提交前帮我做个全面的登记就绪审计\"\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 软著材料的分析与审核由 AI 在本地完成\r\n- 合规检查清单与补正建议在本地生成\r\n- 所有文件读取、格式检查均在本机完成\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- 您的软件源代码（源码仅在本地读取分析）\r\n- 软著申报文档内容（仅在本地审核）\r\n- 公司信息、合同文件、商业机密\r\n- 个人身份信息或联系信息\r\n\r\n每次网络请求前，脚本会明确打印将要传输的数据范围。\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n**所需参数：** `<question>` — 您的软著相关咨询内容。\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nQUESTION=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，输出 `订单创建失败: <错误详情>`，须立即终止流程。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取自检服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付软著材料自检与合规审查结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added cross-reference to delivery-pro, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.32:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.32\",\n  \"publishedAt\": 1784629783683\n}\n\nFile v3.1.32:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: soft-ip-full-lifecycle-zijian\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `soft-ip-full-lifecycle-zijian` 被 ClawHub 标记为 `Needs review`，主要命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Missing User Warnings`\n\n这个清单的目标不是保证 100% 自动放行，而是把最容易触发审计器的点压下来。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 可通过环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n审计器会把它理解成：\n\n- 外发目标可变\n- 可将订单或凭证发往任意地址\n\n#### 修改建议\n\n改成“固定地址”或“白名单校验后才允许使用”。\n\n推荐方案：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n然后校验 `CLAWTIP_SERVER_URL` 的 host，不在白名单就回退到默认值。\n\n#### 问题 B：把原始请求写入本地订单文件\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n软著技能里这个字段通常包含：\n\n- 本地项目路径\n- 项目名\n- 申报目标\n- 用户补充说明\n\n这会被审计器视为“把潜在敏感信息持久化到磁盘”。\n\n#### 修改建议\n\n优先级从高到低：\n\n1. 最优：不要落盘原始 `question`\n2. 次优：只保存摘要，例如：\n\n```python\n\"local_question_summary\": \"software-ip-request\"\n```\n\n3. 如果后续执行必须依赖原始输入，则在 `service.py` 阶段重新要求用户输入，而不是从订单 JSON 回读\n\n#### 问题 C：缺少显式提示\n\n当前脚本虽然最小化上送数据，但对用户没有明确提示：\n\n- 会访问远端支付服务\n- 会在本地保存订单文件\n- 不会上传源码正文\n\n#### 修改建议\n\n在脚本开始输出简短提示，例如：\n\n```python\nprint(\"NOTICE: this step creates a local order file and sends only minimal payment metadata to the payment service.\")\nprint(\"NOTICE: project source files are not uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：发送 `credential` 到远端前没有用户可见提示\n\n当前逻辑会直接把：\n\n- `slug`\n- `orderNo`\n- `credential`\n\n发到远端。\n\n这对支付闭环是必要的，但审计器会视作：\n\n- secret 外发\n- 缺少显式告知\n\n#### 修改建议\n\n在发请求前输出明确说明：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification and fulfillment authorization only.\")\nprint(\"NOTICE: project source files are not uploaded in service verification.\")\n```\n\n#### 问题 B：从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会放大审计器对“本地敏感数据持久化”的判断。\n\n#### 修改建议\n\n改成以下两种之一：\n\n1. 不再依赖本地订单文件保存原始请求，执行时重新输入：\n\n```bash\npython3 scripts/service.py \"<order_no>\" \"<project_path_or_request>\"\n```\n\n2. 或只读取最小摘要，不读取用户原文\n\n#### 问题 C：错误信息里不要暗示会处理完整项目数据\n\n现在文案虽然不算严重，但建议进一步收紧，避免“自动处理整个项目”的感觉。\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：订单文件落在固定用户目录\n\n当前目录：\n\n- Windows: `~/openclaw/skills/orders/{indicator}/`\n- Linux/macOS: `~/.openclaw/skills/orders/{indicator}/`\n\n这个本身不是漏洞，但会被审计器理解为：\n\n- 长期持久化\n- 本地状态残留\n\n#### 修改建议\n\n保留目录结构可以，但要加两点：\n\n1. 在 `save_order` 前只保存最小字段\n2. 在文档中说明这些文件仅用于支付流程，且不保存源码正文\n\n可选增强：\n\n- 增加 TTL / 清理命令\n- 增加注释说明为什么只接受 `indicator` 和 `order_no`\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：能力描述过重\n\n当前文案容易让审计器理解成：\n\n- 自动扫描项目\n- 自动生成 8 份材料\n- 自动推进完整申报流程\n\n这会触发：\n\n- `Excessive Agency`\n- `MCP Tool Poisoning`\n\n#### 修改建议\n\n把措辞统一改成“受限辅助”。\n\n推荐表达：\n\n- “Only generate draft markdown materials after user confirmation.”\n- “Do not submit anything to any official platform.”\n- “Read only the files necessary for the current step.”\n- “Require explicit user confirmation before each document draft.”\n\n#### 问题 B：强化用户确认边界\n\n需要在 `SKILL.md` 里更显眼地写：\n\n1. 只生成草稿\n2. 不自动提交\n3. 不自动上传源码\n4. 每份文档生成前需要用户确认\n5. 支付验证只发送最小元数据和支付凭证\n\n#### 问题 C：补充本地持久化说明\n\n需要明确写：\n\n- 本地订单文件会保存订单元数据\n- 不保存源码正文\n- 如包含项目路径，属于用户本地可见信息，仅用于本地流程衔接\n\n如果你准备彻底规避审计，最好直接移除项目路径落盘。\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 加白名单 URL 校验\n   - 加用户提示\n\n2. 再改 `service.py`\n   - 不再从订单 JSON 读取原始请求\n   - 改成执行时重新传入，或只读摘要\n   - 加发送 `credential` 的提示\n\n3. 再改 `SKILL.md`\n   - 收紧能力描述\n   - 强调用户确认和最小化上送\n\n4. 最后再发 ClawHub 新版本\n   - patch 版本递增\n   - 重新等待审核\n\n## 建议的下一版目标\n\n目标不是“零提示”，而是把结论从：\n\n- `Critical` / `High`\n\n压到：\n\n- 仅人工复核\n- 或更少的中低风险提示\n\n## 备注\n\n`obsidian-memory-system` 之所以更容易过，是因为它的本地持久化和项目路径语义更轻。  \n`soft-ip-full-lifecycle-zijian` 天然更像“读取本地项目后生成材料”，所以必须主动收紧本地存储、外发目标和文案边界。\n\nFile v3.1.32:skill-card.md\n\n## Description: <br>\nSoftware intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users preparing Chinese software copyright applications use this skill to review material completeness, document format readiness, ownership notes, and registration risks before submission. The skill provides local self-assessment guidance while using a third-party service for order creation and payment verification. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Consultation questions and encrypted payment credentials are sent to api.ideaidea.com.cn, and order records are stored locally. <br>\nMitigation: Proceed only after reviewing that data flow, keep confidential source code and legal details out of the question text, and delete local order files after use. <br>\nRisk: The security scanner marked the release suspicious because data transmission and storage are broader than the privacy wording consistently explains. <br>\nMitigation: Review the skill's prompts and data handling disclosures before deployment and confirm users see the transmission notices before network operations. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [Third-party verification service endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance] <br>\n**Output Format:** [Chinese Markdown guidance with command output from helper scripts] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include material gap lists, compliance observations, readiness assessment, remediation guidance, order identifiers, and payment verification status.] <br>\n\n## Skill Version(s): <br>\n3.1.32 (source: server release metadata; artifact frontmatter reports 3.1.33) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.31: 7 files, 11566 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6176b), scripts/create_order.py (3016b), scripts/file_utils.py (2170b), scripts/service.py (2432b), skill-card.md (2589b), SKILL.md (5495b), _meta.json (167b)\n\nFile v3.1.31:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\ndescription: >\n  Software intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. User questions are transmitted via HTTPS to the clawtip third-party verification service for order creation; order metadata is stored locally. No source code, project files, or sensitive legal documents are uploaded.\nmetadata:\n  author: \"Yujin\"\n  version: \"3.1.33\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip-skill\"\n---\n\n# soft-ip-full-lifecycle-zijian\n\nPlease interact with users in Chinese (使用中文与用户交互).\n\n## 功能概述\n\n本技能提供软件著作权申报材料的自检与合规审查服务。它帮助您在中国版权保护中心申报软著之前，系统性地检查申请材料的完整性与合规性，降低因材料问题导致的补正或驳回风险。\n\n**所有材料分析在本机完成，您的源代码和申报文档绝不会上传。** 身份验证通过 clawtip 第三方服务进行。\n\n### 核心能力\n\n**材料完整性审查**\n- 对照软著申报要求逐项核查材料齐备情况\n- 标识缺失项（申请表、源代码文档、用户手册、权利归属证明等）\n- 生成缺失材料清单及补交优先级建议\n\n**源代码文档合规检查**\n- 检查源代码文档的格式规范性（页眉、页码、行号等）\n- 验证前后各 30 页的完整性要求\n- 审查代码与软件的对应关系一致性\n\n**用户手册/说明书审核**\n- 检查操作手册的截图格式与清晰度要求\n- 验证功能描述的完整性与技术准确性\n- 审查版本号、软件名称的一致性\n\n**权利归属与合规性检查**\n- 检查著作权归属声明的完整性与合法性\n- 验证合作开发/委托开发协议的存在性与有效性\n- 审查职务作品、法人作品的权属说明\n\n**登记就绪审计**\n- 综合判断软著申报的当前就绪状态\n- 按风险等级分类问题（阻断性/建议性/提示性）\n- 输出可提交性评估与补正建议\n\n### 与其他技能的关系\n\n- **本技能定位**：材料诊断与合规审查（告诉您问题在哪、缺什么）\n- **soft-ip-full-lifecycle-delivery-pro**（另行安装）：全量文档生成与填写辅助（帮您把 8 份申报材料填好）\n- 建议先使用本技能完成诊断，再使用 delivery-pro 进行文档生成\n\n### 使用场景示例\n\n- \"帮我检查一下软著申报材料还缺什么\"\n- \"我准备了源代码文档，看看格式符不符合要求\"\n- \"这份用户手册的截图清晰度够不够过审\"\n- \"我的软件是合作开发的，权利归属怎么写\"\n- \"提交前帮我做个全面的登记就绪审计\"\n\n---\n\n## 数据处理与隐私说明\n\n本技能严格遵守数据最小化与透明传输原则：\n\n### 本地处理（数据始终不离开本机）\n- 软著材料的分析与审核由 AI 在本地完成\n- 合规检查清单与补正建议在本地生成\n- 所有文件读取、格式检查均在本机完成\n\n### 远程传输（仅身份验证阶段）\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\n- **传输协议**：HTTPS + SM4 国密加密\n- **传输时机**：仅在订单创建和履约验证时发生\n\n### 本地存储\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\n- 支付完成后建议可随时手动清理订单文件\n\n### 绝不收集或传输\n- 您的软件源代码（源码仅在本地读取分析）\n- 软著申报文档内容（仅在本地审核）\n- 公司信息、合同文件、商业机密\n- 个人身份信息或联系信息\n\n每次网络请求前，脚本会明确打印将要传输的数据范围。\n\n---\n\n## 如何开始使用\n\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\n\n### 前置条件\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\n\n### 第一阶段：创建验证订单\n\n**所需参数：** `<question>` — 您的软著相关咨询内容。\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n**成功时**输出：\n```\nORDER_NO=<value>\nAMOUNT=<value>\nQUESTION=<value>\nINDICATOR=<value>\n```\n\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\n\n**失败时**以代码 1 退出，输出 `订单创建失败: <错误详情>`，须立即终止流程。\n\n### 第二阶段：身份验证\n\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\n\n### 第三阶段：获取自检服务\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付软著材料自检与合规审查结果。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:---|:---|:---|\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added cross-reference to delivery-pro, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.31:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.31\",\n  \"publishedAt\": 1784562447832\n}\n\nFile v3.1.31:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: soft-ip-full-lifecycle-zijian\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `soft-ip-full-lifecycle-zijian` 被 ClawHub 标记为 `Needs review`，主要命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Missing User Warnings`\n\n这个清单的目标不是保证 100% 自动放行，而是把最容易触发审计器的点压下来。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 可通过环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n审计器会把它理解成：\n\n- 外发目标可变\n- 可将订单或凭证发往任意地址\n\n#### 修改建议\n\n改成“固定地址”或“白名单校验后才允许使用”。\n\n推荐方案：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n然后校验 `CLAWTIP_SERVER_URL` 的 host，不在白名单就回退到默认值。\n\n#### 问题 B：把原始请求写入本地订单文件\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n软著技能里这个字段通常包含：\n\n- 本地项目路径\n- 项目名\n- 申报目标\n- 用户补充说明\n\n这会被审计器视为“把潜在敏感信息持久化到磁盘”。\n\n#### 修改建议\n\n优先级从高到低：\n\n1. 最优：不要落盘原始 `question`\n2. 次优：只保存摘要，例如：\n\n```python\n\"local_question_summary\": \"software-ip-request\"\n```\n\n3. 如果后续执行必须依赖原始输入，则在 `service.py` 阶段重新要求用户输入，而不是从订单 JSON 回读\n\n#### 问题 C：缺少显式提示\n\n当前脚本虽然最小化上送数据，但对用户没有明确提示：\n\n- 会访问远端支付服务\n- 会在本地保存订单文件\n- 不会上传源码正文\n\n#### 修改建议\n\n在脚本开始输出简短提示，例如：\n\n```python\nprint(\"NOTICE: this step creates a local order file and sends only minimal payment metadata to the payment service.\")\nprint(\"NOTICE: project source files are not uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：发送 `credential` 到远端前没有用户可见提示\n\n当前逻辑会直接把：\n\n- `slug`\n- `orderNo`\n- `credential`\n\n发到远端。\n\n这对支付闭环是必要的，但审计器会视作：\n\n- secret 外发\n- 缺少显式告知\n\n#### 修改建议\n\n在发请求前输出明确说明：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification and fulfillment authorization only.\")\nprint(\"NOTICE: project source files are not uploaded in service verification.\")\n```\n\n#### 问题 B：从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会放大审计器对“本地敏感数据持久化”的判断。\n\n#### 修改建议\n\n改成以下两种之一：\n\n1. 不再依赖本地订单文件保存原始请求，执行时重新输入：\n\n```bash\npython3 scripts/service.py \"<order_no>\" \"<project_path_or_request>\"\n```\n\n2. 或只读取最小摘要，不读取用户原文\n\n#### 问题 C：错误信息里不要暗示会处理完整项目数据\n\n现在文案虽然不算严重，但建议进一步收紧，避免“自动处理整个项目”的感觉。\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：订单文件落在固定用户目录\n\n当前目录：\n\n- Windows: `~/openclaw/skills/orders/{indicator}/`\n- Linux/macOS: `~/.openclaw/skills/orders/{indicator}/`\n\n这个本身不是漏洞，但会被审计器理解为：\n\n- 长期持久化\n- 本地状态残留\n\n#### 修改建议\n\n保留目录结构可以，但要加两点：\n\n1. 在 `save_order` 前只保存最小字段\n2. 在文档中说明这些文件仅用于支付流程，且不保存源码正文\n\n可选增强：\n\n- 增加 TTL / 清理命令\n- 增加注释说明为什么只接受 `indicator` 和 `order_no`\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：能力描述过重\n\n当前文案容易让审计器理解成：\n\n- 自动扫描项目\n- 自动生成 8 份材料\n- 自动推进完整申报流程\n\n这会触发：\n\n- `Excessive Agency`\n- `MCP Tool Poisoning`\n\n#### 修改建议\n\n把措辞统一改成“受限辅助”。\n\n推荐表达：\n\n- “Only generate draft markdown materials after user confirmation.”\n- “Do not submit anything to any official platform.”\n- “Read only the files necessary for the current step.”\n- “Require explicit user confirmation before each document draft.”\n\n#### 问题 B：强化用户确认边界\n\n需要在 `SKILL.md` 里更显眼地写：\n\n1. 只生成草稿\n2. 不自动提交\n3. 不自动上传源码\n4. 每份文档生成前需要用户确认\n5. 支付验证只发送最小元数据和支付凭证\n\n#### 问题 C：补充本地持久化说明\n\n需要明确写：\n\n- 本地订单文件会保存订单元数据\n- 不保存源码正文\n- 如包含项目路径，属于用户本地可见信息，仅用于本地流程衔接\n\n如果你准备彻底规避审计，最好直接移除项目路径落盘。\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 加白名单 URL 校验\n   - 加用户提示\n\n2. 再改 `service.py`\n   - 不再从订单 JSON 读取原始请求\n   - 改成执行时重新传入，或只读摘要\n   - 加发送 `credential` 的提示\n\n3. 再改 `SKILL.md`\n   - 收紧能力描述\n   - 强调用户确认和最小化上送\n\n4. 最后再发 ClawHub 新版本\n   - patch 版本递增\n   - 重新等待审核\n\n## 建议的下一版目标\n\n目标不是“零提示”，而是把结论从：\n\n- `Critical` / `High`\n\n压到：\n\n- 仅人工复核\n- 或更少的中低风险提示\n\n## 备注\n\n`obsidian-memory-system` 之所以更容易过，是因为它的本地持久化和项目路径语义更轻。  \n`soft-ip-full-lifecycle-zijian` 天然更像“读取本地项目后生成材料”，所以必须主动收紧本地存储、外发目标和文案边界。\n\nFile v3.1.31:skill-card.md\n\n## Description: <br>\nSoftware intellectual property full lifecycle self-assessment for Chinese software copyright applications, covering material completeness, compliance verification, and registration readiness while using a third-party verification service for order creation. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, software teams, and applicants preparing Chinese software copyright submissions use this skill to assess whether application materials are complete, consistent, and ready for registration review. It supports local self-assessment and payment-gated authorization before the agent provides guidance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The full initial user question may be sent to api.ideaidea.com.cn and saved in a local order file. <br>\nMitigation: Do not include company secrets, source details, personal data, or legal document content in the initial question unless that transfer and local storage are acceptable. <br>\nRisk: Local order metadata can remain on disk after use. <br>\nMitigation: Clear the local order files after use when the question or payment metadata is sensitive. <br>\nRisk: The security verdict is suspicious because disclosure around the third-party service and local storage may be incomplete for a legal/IP workflow. <br>\nMitigation: Review the skill before installation and confirm the third-party verification flow is acceptable for the intended environment. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix) <br>\n- [Third-party verification service endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, shell commands] <br>\n**Output Format:** [Markdown guidance with inline shell command examples and status text from helper scripts] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Normal use may create local order metadata files for the payment and authorization flow.] <br>\n\n## Skill Version(s): <br>\n3.1.31 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.30: 7 files, 11088 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6176b), scripts/create_order.py (3060b), scripts/file_utils.py (2170b), scripts/service.py (2476b), skill-card.md (2534b), SKILL.md (5091b), _meta.json (167b)\n\nFile v3.1.30:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software IP full lifecycle self-assessment: material review, compliance check, registration readiness audit. 此为付费技能，使用 clawtip 三阶段支付流程（创建订单 → 支付验证 → 服务交付）。用户提问会通过 HTTPS 发送至服务端用于订单创建，订单元数据保存至本地 ~/.openclaw/skills/orders/ 目录。\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.1.30\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## Skill Overview\r\n\r\nSoftware intellectual property full lifecycle self-assessment service providing material review, compliance verification, and registration readiness audit.\r\n\r\n本技能为**付费服务**，采用 clawtip 三阶段支付流程：\r\n\r\n1. **Phase 1 — 创建订单**：将提问通过 HTTPS 发送至服务端，返回订单号并将订单元数据（含提问摘要）保存至本地 ~/.openclaw/skills/orders/ 目录\r\n2. **Phase 2 — 支付处理**：通过 clawtip 完成支付验证，支付凭证自动写入本地订单文件\r\n3. **Phase 3 — 服务执行**：验证支付后返回软著材料自检与合规审查结果\r\n\r\n用户提问仅用于本次服务的订单生成与履约验证，不会持久化存储或用于其他目的。\r\n\r\n**Direct execution:** If the user has already provided an <<order_no>> (and the order file already contains payCredential), skip directly to the third stage and skip the first two stages.\r\n\r\n---\r\n\r\n## First Stage: Create Order\r\n\r\nIf this is the first interaction and the user has not yet paid, you must first create an order before initiating payment.\r\n\r\n### 1. Required Parameters\r\n* `<question>`: the user's specific question or content.\r\n\r\n### 2. Execution Command\r\n\r\nExecute the order creation script using the following command. Replace `<...>` placeholders with actual values.\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n### 3. Output Processing\r\n\r\n**On success**, the script prints the following key-value pairs to stdout:\r\n\r\n    ORDER_NO=<value>\r\n    AMOUNT=<value>\r\n    QUESTION=<value>\r\n    INDICATOR=<value>\r\n\r\nExtract ORDER_NO and INDICATOR and proceed to the second stage.\r\n\r\n> [!NOTE]\r\n> AMOUNT is in RMB fen. When displaying to the user, divide by 100 and present in yuan.\r\n\r\n**On failure**, the script exits with code 1 and prints:\r\n\r\n    订单创建失败: <error detail>\r\n\r\n> [!CAUTION]\r\n> If the script exits with non-zero code, **immediately terminate the entire workflow** and inform the user of the failure.\r\n\r\n---\r\n\r\n## Second Stage: Payment Processing\r\n\r\nAfter obtaining ORDER_NO and INDICATOR from the first stage, initiate the payment request.\r\n\r\n**Operation:** Use skill `clawtip` to process payment and obtain payment credentials. If this skill does not exist, install it first.\r\n\r\n**Parameters required by `clawtip`:**\r\n\r\n    {\r\n      \"order_no\": \"<ORDER_NO from first stage>\",\r\n      \"indicator\": \"<INDICATOR from first stage>\"\r\n    }\r\n\r\n> [!NOTE]\r\n> All order details (skill-id, order_no, amount, question, description, slug, resource_url etc.) have already been written to a local JSON file by the first stage script. `clawtip` automatically locates and reads the file based on order_no and indicator.\r\n\r\n**Goal:** Wait for payment success and obtain payCredential, which will be automatically written to the order file.\r\n\r\n---\r\n\r\n## Third Stage: Service Execution\r\n\r\nAfter successful payment and obtaining payCredential, resume interaction and execute the service script.\r\n\r\n### 1. Required Parameters\r\n* `<order_no>`: the order number generated in the first stage.\r\n\r\n> [!NOTE]\r\n> payCredential and question do not need to be passed via command line. The script reads them automatically from the order JSON file.\r\n\r\n### 2. Execution Command\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n### 3. Output Processing\r\n\r\n**After execution:**\r\n\r\n1. Extract the PAY_STATUS value (format: `PAY_STATUS: <value>`).\r\n2. If PAY_STATUS is ERROR, extract ERROR_INFO and inform the user.\r\n\r\n| Field | Enum | Output Format |\r\n|-------|------|---------------|\r\n| PAY_STATUS | SUCCESS, PROCESSING, FAIL, ERROR | `PAY_STATUS: SUCCESS` |\r\n| ERROR_INFO | N/A | `ERROR_INFO: <reason>` |\r\n\r\n---\r\n\r\n## Data Handling\r\n\r\n- **Transmitted**: skill slug, order number, user question, encrypted payment data via HTTPS to `https://api.ideaidea.com.cn`\r\n- **Stored locally**: order metadata (order_no, amount, question, payCredential) to `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- **Not collected**: source code, database credentials, API keys, personal files, project content\r\n\r\n\r\n---\r\n\r\n## Version History\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard: add question parameter, standardize output |\r\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v3.1.30:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.30\",\n  \"publishedAt\": 1784540305684\n}\n\nFile v3.1.30:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: soft-ip-full-lifecycle-zijian\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `soft-ip-full-lifecycle-zijian` 被 ClawHub 标记为 `Needs review`，主要命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Missing User Warnings`\n\n这个清单的目标不是保证 100% 自动放行，而是把最容易触发审计器的点压下来。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 可通过环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n审计器会把它理解成：\n\n- 外发目标可变\n- 可将订单或凭证发往任意地址\n\n#### 修改建议\n\n改成“固定地址”或“白名单校验后才允许使用”。\n\n推荐方案：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n然后校验 `CLAWTIP_SERVER_URL` 的 host，不在白名单就回退到默认值。\n\n#### 问题 B：把原始请求写入本地订单文件\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n软著技能里这个字段通常包含：\n\n- 本地项目路径\n- 项目名\n- 申报目标\n- 用户补充说明\n\n这会被审计器视为“把潜在敏感信息持久化到磁盘”。\n\n#### 修改建议\n\n优先级从高到低：\n\n1. 最优：不要落盘原始 `question`\n2. 次优：只保存摘要，例如：\n\n```python\n\"local_question_summary\": \"software-ip-request\"\n```\n\n3. 如果后续执行必须依赖原始输入，则在 `service.py` 阶段重新要求用户输入，而不是从订单 JSON 回读\n\n#### 问题 C：缺少显式提示\n\n当前脚本虽然最小化上送数据，但对用户没有明确提示：\n\n- 会访问远端支付服务\n- 会在本地保存订单文件\n- 不会上传源码正文\n\n#### 修改建议\n\n在脚本开始输出简短提示，例如：\n\n```python\nprint(\"NOTICE: this step creates a local order file and sends only minimal payment metadata to the payment service.\")\nprint(\"NOTICE: project source files are not uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：发送 `credential` 到远端前没有用户可见提示\n\n当前逻辑会直接把：\n\n- `slug`\n- `orderNo`\n- `credential`\n\n发到远端。\n\n这对支付闭环是必要的，但审计器会视作：\n\n- secret 外发\n- 缺少显式告知\n\n#### 修改建议\n\n在发请求前输出明确说明：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification and fulfillment authorization only.\")\nprint(\"NOTICE: project source files are not uploaded in service verification.\")\n```\n\n#### 问题 B：从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会放大审计器对“本地敏感数据持久化”的判断。\n\n#### 修改建议\n\n改成以下两种之一：\n\n1. 不再依赖本地订单文件保存原始请求，执行时重新输入：\n\n```bash\npython3 scripts/service.py \"<order_no>\" \"<project_path_or_request>\"\n```\n\n2. 或只读取最小摘要，不读取用户原文\n\n#### 问题 C：错误信息里不要暗示会处理完整项目数据\n\n现在文案虽然不算严重，但建议进一步收紧，避免“自动处理整个项目”的感觉。\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：订单文件落在固定用户目录\n\n当前目录：\n\n- Windows: `~/openclaw/skills/orders/{indicator}/`\n- Linux/macOS: `~/.openclaw/skills/orders/{indicator}/`\n\n这个本身不是漏洞，但会被审计器理解为：\n\n- 长期持久化\n- 本地状态残留\n\n#### 修改建议\n\n保留目录结构可以，但要加两点：\n\n1. 在 `save_order` 前只保存最小字段\n2. 在文档中说明这些文件仅用于支付流程，且不保存源码正文\n\n可选增强：\n\n- 增加 TTL / 清理命令\n- 增加注释说明为什么只接受 `indicator` 和 `order_no`\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：能力描述过重\n\n当前文案容易让审计器理解成：\n\n- 自动扫描项目\n- 自动生成 8 份材料\n- 自动推进完整申报流程\n\n这会触发：\n\n- `Excessive Agency`\n- `MCP Tool Poisoning`\n\n#### 修改建议\n\n把措辞统一改成“受限辅助”。\n\n推荐表达：\n\n- “Only generate draft markdown materials after user confirmation.”\n- “Do not submit anything to any official platform.”\n- “Read only the files necessary for the current step.”\n- “Require explicit user confirmation before each document draft.”\n\n#### 问题 B：强化用户确认边界\n\n需要在 `SKILL.md` 里更显眼地写：\n\n1. 只生成草稿\n2. 不自动提交\n3. 不自动上传源码\n4. 每份文档生成前需要用户确认\n5. 支付验证只发送最小元数据和支付凭证\n\n#### 问题 C：补充本地持久化说明\n\n需要明确写：\n\n- 本地订单文件会保存订单元数据\n- 不保存源码正文\n- 如包含项目路径，属于用户本地可见信息，仅用于本地流程衔接\n\n如果你准备彻底规避审计，最好直接移除项目路径落盘。\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 加白名单 URL 校验\n   - 加用户提示\n\n2. 再改 `service.py`\n   - 不再从订单 JSON 读取原始请求\n   - 改成执行时重新传入，或只读摘要\n   - 加发送 `credential` 的提示\n\n3. 再改 `SKILL.md`\n   - 收紧能力描述\n   - 强调用户确认和最小化上送\n\n4. 最后再发 ClawHub 新版本\n   - patch 版本递增\n   - 重新等待审核\n\n## 建议的下一版目标\n\n目标不是“零提示”，而是把结论从：\n\n- `Critical` / `High`\n\n压到：\n\n- 仅人工复核\n- 或更少的中低风险提示\n\n## 备注\n\n`obsidian-memory-system` 之所以更容易过，是因为它的本地持久化和项目路径语义更轻。  \n`soft-ip-full-lifecycle-zijian` 天然更像“读取本地项目后生成材料”，所以必须主动收紧本地存储、外发目标和文案边界。\n\nFile v3.1.30:skill-card.md\n\n## Description: <br>\nSoftware IP full lifecycle self-assessment for material review, compliance checks, and registration readiness audits, delivered through a paid three-stage order, payment verification, and service workflow. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, software teams, and IP applicants use this skill to request a paid self-assessment of software copyright registration materials, compliance readiness, and documentation gaps. The workflow creates an order, verifies payment, and returns service authorization or status information before delivery. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The workflow sends the user's question text and payment credential to api.ideaidea.com.cn and stores order data locally. <br>\nMitigation: Users should avoid including source code, secrets, or highly confidential IP details in the initial question unless they accept that handling. <br>\nRisk: Local order files include payment metadata and may persist after the workflow completes. <br>\nMitigation: The publisher should clarify retention and deletion behavior, and users should review local OpenClaw order files when handling sensitive matters. <br>\nRisk: The final paid assessment result depends on remote authorization after payment verification. <br>\nMitigation: The publisher should make delivery behavior and failure handling clear before users rely on the service for registration decisions. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance] <br>\n**Output Format:** [Markdown with inline shell commands and payment status fields] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Chinese-language interaction; uses order number, payment indicator, and PAY_STATUS fields to coordinate the paid workflow.] <br>\n\n## Skill Version(s): <br>\n3.1.30 (source: server release evidence and SKILL.md metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.29: 7 files, 10880 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6176b), scripts/create_order.py (2982b), scripts/file_utils.py (2170b), scripts/service.py (2398b), skill-card.md (2497b), SKILL.md (5070b), _meta.json (167b)\n\nFile v3.1.29:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software IP full lifecycle self-assessment: material review, compliance check, registration readiness audit. 此为付费技能，使用 clawtip 三阶段支付流程（创建订单 → 支付验证 → 服务交付）。用户提问会通过 HTTPS 发送至服务端用于订单创建，订单元数据保存至本地 ~/.openclaw/skills/orders/ 目录。\r\nmetadata:\r\n  author: \"Yujin\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## Skill Overview\r\n\r\nSoftware intellectual property full lifecycle self-assessment service providing material review, compliance verification, and registration readiness audit.\r\n\r\n本技能为**付费服务**，采用 clawtip 三阶段支付流程：\r\n\r\n1. **Phase 1 — 创建订单**：将提问通过 HTTPS 发送至服务端，返回订单号并将订单元数据（含提问摘要）保存至本地 ~/.openclaw/skills/orders/ 目录\r\n2. **Phase 2 — 支付处理**：通过 clawtip 完成支付验证，支付凭证自动写入本地订单文件\r\n3. **Phase 3 — 服务执行**：验证支付后返回软著材料自检与合规审查结果\r\n\r\n用户提问仅用于本次服务的订单生成与履约验证，不会持久化存储或用于其他目的。\r\n\r\n**Direct execution:** If the user has already provided an <<order_no>> (and the order file already contains payCredential), skip directly to the third stage and skip the first two stages.\r\n\r\n---\r\n\r\n## First Stage: Create Order\r\n\r\nIf this is the first interaction and the user has not yet paid, you must first create an order before initiating payment.\r\n\r\n### 1. Required Parameters\r\n* `<question>`: the user's specific question or content.\r\n\r\n### 2. Execution Command\r\n\r\nExecute the order creation script using the following command. Replace `<...>` placeholders with actual values.\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n### 3. Output Processing\r\n\r\n**On success**, the script prints the following key-value pairs to stdout:\r\n\r\n    ORDER_NO=<value>\r\n    AMOUNT=<value>\r\n    QUESTION=<value>\r\n    INDICATOR=<value>\r\n\r\nExtract ORDER_NO and INDICATOR and proceed to the second stage.\r\n\r\n> [!NOTE]\r\n> AMOUNT is in RMB fen. When displaying to the user, divide by 100 and present in yuan.\r\n\r\n**On failure**, the script exits with code 1 and prints:\r\n\r\n    订单创建失败: <error detail>\r\n\r\n> [!CAUTION]\r\n> If the script exits with non-zero code, **immediately terminate the entire workflow** and inform the user of the failure.\r\n\r\n---\r\n\r\n## Second Stage: Payment Processing\r\n\r\nAfter obtaining ORDER_NO and INDICATOR from the first stage, initiate the payment request.\r\n\r\n**Operation:** Use skill `clawtip` to process payment and obtain payment credentials. If this skill does not exist, install it first.\r\n\r\n**Parameters required by `clawtip`:**\r\n\r\n    {\r\n      \"order_no\": \"<ORDER_NO from first stage>\",\r\n      \"indicator\": \"<INDICATOR from first stage>\"\r\n    }\r\n\r\n> [!NOTE]\r\n> All order details (skill-id, order_no, amount, question, description, slug, resource_url etc.) have already been written to a local JSON file by the first stage script. `clawtip` automatically locates and reads the file based on order_no and indicator.\r\n\r\n**Goal:** Wait for payment success and obtain payCredential, which will be automatically written to the order file.\r\n\r\n---\r\n\r\n## Third Stage: Service Execution\r\n\r\nAfter successful payment and obtaining payCredential, resume interaction and execute the service script.\r\n\r\n### 1. Required Parameters\r\n* `<order_no>`: the order number generated in the first stage.\r\n\r\n> [!NOTE]\r\n> payCredential and question do not need to be passed via command line. The script reads them automatically from the order JSON file.\r\n\r\n### 2. Execution Command\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n### 3. Output Processing\r\n\r\n**After execution:**\r\n\r\n1. Extract the PAY_STATUS value (format: `PAY_STATUS: <value>`).\r\n2. If PAY_STATUS is ERROR, extract ERROR_INFO and inform the user.\r\n\r\n| Field | Enum | Output Format |\r\n|-------|------|---------------|\r\n| PAY_STATUS | SUCCESS, PROCESSING, FAIL, ERROR | `PAY_STATUS: SUCCESS` |\r\n| ERROR_INFO | N/A | `ERROR_INFO: <reason>` |\r\n\r\n---\r\n\r\n## Data Handling\r\n\r\n- **Transmitted**: skill slug, order number, user question, encrypted payment data via HTTPS to `https://api.ideaidea.com.cn`\r\n- **Stored locally**: order metadata (order_no, amount, question, payCredential) to `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- **Not collected**: source code, database credentials, API keys, personal files, project content\r\n\r\n\r\n---\r\n\r\n## Version History\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 1.0.1 | 2026-07-20 | Fix payment flow to match clawtip standard: add question parameter, standardize output |\r\n| 1.0.0 | 2026-07-19 | Initial release |\n\nFile v3.1.29:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.29\",\n  \"publishedAt\": 1784536732843\n}\n\nFile v3.1.29:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: soft-ip-full-lifecycle-zijian\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `soft-ip-full-lifecycle-zijian` 被 ClawHub 标记为 `Needs review`，主要命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Missing User Warnings`\n\n这个清单的目标不是保证 100% 自动放行，而是把最容易触发审计器的点压下来。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 可通过环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n审计器会把它理解成：\n\n- 外发目标可变\n- 可将订单或凭证发往任意地址\n\n#### 修改建议\n\n改成“固定地址”或“白名单校验后才允许使用”。\n\n推荐方案：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n然后校验 `CLAWTIP_SERVER_URL` 的 host，不在白名单就回退到默认值。\n\n#### 问题 B：把原始请求写入本地订单文件\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n软著技能里这个字段通常包含：\n\n- 本地项目路径\n- 项目名\n- 申报目标\n- 用户补充说明\n\n这会被审计器视为“把潜在敏感信息持久化到磁盘”。\n\n#### 修改建议\n\n优先级从高到低：\n\n1. 最优：不要落盘原始 `question`\n2. 次优：只保存摘要，例如：\n\n```python\n\"local_question_summary\": \"software-ip-request\"\n```\n\n3. 如果后续执行必须依赖原始输入，则在 `service.py` 阶段重新要求用户输入，而不是从订单 JSON 回读\n\n#### 问题 C：缺少显式提示\n\n当前脚本虽然最小化上送数据，但对用户没有明确提示：\n\n- 会访问远端支付服务\n- 会在本地保存订单文件\n- 不会上传源码正文\n\n#### 修改建议\n\n在脚本开始输出简短提示，例如：\n\n```python\nprint(\"NOTICE: this step creates a local order file and sends only minimal payment metadata to the payment service.\")\nprint(\"NOTICE: project source files are not uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：发送 `credential` 到远端前没有用户可见提示\n\n当前逻辑会直接把：\n\n- `slug`\n- `orderNo`\n- `credential`\n\n发到远端。\n\n这对支付闭环是必要的，但审计器会视作：\n\n- secret 外发\n- 缺少显式告知\n\n#### 修改建议\n\n在发请求前输出明确说明：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification and fulfillment authorization only.\")\nprint(\"NOTICE: project source files are not uploaded in service verification.\")\n```\n\n#### 问题 B：从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会放大审计器对“本地敏感数据持久化”的判断。\n\n#### 修改建议\n\n改成以下两种之一：\n\n1. 不再依赖本地订单文件保存原始请求，执行时重新输入：\n\n```bash\npython3 scripts/service.py \"<order_no>\" \"<project_path_or_request>\"\n```\n\n2. 或只读取最小摘要，不读取用户原文\n\n#### 问题 C：错误信息里不要暗示会处理完整项目数据\n\n现在文案虽然不算严重，但建议进一步收紧，避免“自动处理整个项目”的感觉。\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：订单文件落在固定用户目录\n\n当前目录：\n\n- Windows: `~/openclaw/skills/orders/{indicator}/`\n- Linux/macOS: `~/.openclaw/skills/orders/{indicator}/`\n\n这个本身不是漏洞，但会被审计器理解为：\n\n- 长期持久化\n- 本地状态残留\n\n#### 修改建议\n\n保留目录结构可以，但要加两点：\n\n1. 在 `save_order` 前只保存最小字段\n2. 在文档中说明这些文件仅用于支付流程，且不保存源码正文\n\n可选增强：\n\n- 增加 TTL / 清理命令\n- 增加注释说明为什么只接受 `indicator` 和 `order_no`\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：能力描述过重\n\n当前文案容易让审计器理解成：\n\n- 自动扫描项目\n- 自动生成 8 份材料\n- 自动推进完整申报流程\n\n这会触发：\n\n- `Excessive Agency`\n- `MCP Tool Poisoning`\n\n#### 修改建议\n\n把措辞统一改成“受限辅助”。\n\n推荐表达：\n\n- “Only generate draft markdown materials after user confirmation.”\n- “Do not submit anything to any official platform.”\n- “Read only the files necessary for the current step.”\n- “Require explicit user confirmation before each document draft.”\n\n#### 问题 B：强化用户确认边界\n\n需要在 `SKILL.md` 里更显眼地写：\n\n1. 只生成草稿\n2. 不自动提交\n3. 不自动上传源码\n4. 每份文档生成前需要用户确认\n5. 支付验证只发送最小元数据和支付凭证\n\n#### 问题 C：补充本地持久化说明\n\n需要明确写：\n\n- 本地订单文件会保存订单元数据\n- 不保存源码正文\n- 如包含项目路径，属于用户本地可见信息，仅用于本地流程衔接\n\n如果你准备彻底规避审计，最好直接移除项目路径落盘。\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 加白名单 URL 校验\n   - 加用户提示\n\n2. 再改 `service.py`\n   - 不再从订单 JSON 读取原始请求\n   - 改成执行时重新传入，或只读摘要\n   - 加发送 `credential` 的提示\n\n3. 再改 `SKILL.md`\n   - 收紧能力描述\n   - 强调用户确认和最小化上送\n\n4. 最后再发 ClawHub 新版本\n   - patch 版本递增\n   - 重新等待审核\n\n## 建议的下一版目标\n\n目标不是“零提示”，而是把结论从：\n\n- `Critical` / `High`\n\n压到：\n\n- 仅人工复核\n- 或更少的中低风险提示\n\n## 备注\n\n`obsidian-memory-system` 之所以更容易过，是因为它的本地持久化和项目路径语义更轻。  \n`soft-ip-full-lifecycle-zijian` 天然更像“读取本地项目后生成材料”，所以必须主动收紧本地存储、外发目标和文案边界。\n\nFile v3.1.29:skill-card.md\n\n## Description: <br>\nSoftware IP full lifecycle self-assessment for material review, compliance checks, and registration readiness audit, delivered through a paid ClawHub flow that sends the user question over HTTPS for order creation and stores order metadata locally. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers use this skill to obtain a Chinese-language paid self-assessment for software intellectual property materials, compliance readiness, and registration preparation. The workflow creates a service order, verifies payment through clawtip, and returns service authorization status before fulfillment. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill sends the user question and payment credential or order data to api.ideaidea.com.cn and stores full order metadata locally. <br>\nMitigation: Avoid confidential source details, credentials, or sensitive business facts in the question, and delete local order files after use when retention is not needed. <br>\nRisk: The security review notes that the scripts do not visibly produce the advertised assessment result beyond payment verification. <br>\nMitigation: Confirm the delivered result before relying on it for registration decisions and review any generated assessment manually. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [Service endpoint domain](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Chinese markdown guidance with inline shell commands and key-value or status output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Paid workflow; order creation and payment verification use remote HTTPS calls and local order JSON files.] <br>\n\n## Skill Version(s): <br>\n3.1.29 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: soft-ip-full-lifecycle-zijian Owner: jinyu12166 Summary: Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Tags: latest:3.1.38 Version history: v3.1.38 | 2026-07-","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"openclaw skills install clawtip"},{"language":"bash","snippet":"python3 scripts/create_order.py \"<question>\""},{"language":"bash","snippet":"npx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12"},{"language":"bash","snippet":"python3 scripts/service.py \"<order_no>\""},{"language":"bash","snippet":"openclaw skills install clawtip"},{"language":"bash","snippet":"python3 scripts/create_order.py \"<question>\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: \"soft-ip-full-lifecycle-zijian\"\nversion: \"3.2.1\"\ndescription: >\n  Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip. Chinese-language service (中国软件著作权申报所需).\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# soft-ip-full-lifecycle-zijian\n\n**语言说明 / Language:** This skill is designed for Chinese software copyright compliance (中国软件著作权申报), and its user-facing interface is primarily in Chinese. Core metadata and technical documentation are in English for accessibility.\n\n## 技能概述\n\n软件知识产权全生命周期自检与合规审查服务。本技能通过 clawtip 完成支付验证后，**由 AI 模型在对话中**交付合规诊断和材料审查结果。\n\n### 服务交付方式\n\n本技能是 **AI 对话交付型** 服务：\n- `create_order.py` — 创建本地订单文件（仅用于 clawtip 支付验证）\n- 支付由 **clawtip** 官方钱包处理\n- `service.py` — 验证支付凭证后，指示 AI 在对话中执行以下 5 项评估\n\n### 5 项合规评估\n\n| # | 评估项 | 说明 |\n|---|--------|------|\n| 1 | 材料完整性审查 | 对照软著登记要求逐项检查材料是否齐全 |\n| 2 | 源代码文档审计 | 格式验证、页数检查、前/后30页完整性 |\n| 3 | 用户手册合规检查 | 截图格式、功能描述完整性 |\n| 4 | 权利归属验证 | 权属声明、合作协议框架检查 |\n| 5 | 登记就绪评估 | 风险分级（阻塞性 / 建议性 / 参考性），修复建议 |\n\n### 与 delivery-pro 的关系\n\n| 维度 | zijian（本技能，诊断版） | delivery-pro（生成版） |\n|------|------------------------|-----------------------|\n| 用途 | 合规性诊断：识别缺失和问题 | 文档生成：填写全部 8 项申报材料 |\n| 价格 | 190 UT (1.9 元) | 690 UT (6.9 元) |\n| 输出 | 缺失清单 + 问题标注 + 风险评级 | 完整的可提交文档草稿 |\n| 建议顺序 | 先运行：诊断问题，补充材料 | 后运行：基于完善的材料生成文档 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥 |\n\n> 以上环境变量仅用于 clawtip 支付凭证加密，不收集、不传输任何业务数据。\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n> 本地订单文件路径：`~/.openclaw/skills/orders/{indicator}/{order_no}.json`\n> 包含字段：orderNo、amount、question。仅用于支付验证，不涉及任何审查材料。\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n**失败：** `订单创建失败: <详情>` → 终止。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：合规审查\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n成功后，AI 模型将在对话中输出完整的合规评估报告。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n| 文件 | 路径 | 内容 |\n|------|------|------|\n| 订单文件 | `~/.openclaw/skills/orders/{indicator}/{order_no}.json` | orderNo、amount、question、加密凭证 |\n\n### 远程传输\n本技能自身不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n### 绝不收集或传输\n源代码、申"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian-clawhub-reviewfix\",\n  \"version\": \"3.1.38\",\n  \"publishedAt\": 1785246471367\n}"},{"path":"skill-card.md","content":"## Description:\n\nSoftware IP self-assessment for Chinese software copyright applications, including material completeness checks, source code documentation audit prompts, user manual review, rights attribution verification, registration readiness assessment, and payment verification through clawtip.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jinyu12166](https://clawhub.ai/user/jinyu12166)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, founders, and software copyright applicants use this skill to receive a Chinese-language readiness review before preparing or submitting Chinese software copyright registration materials. It helps identify missing materials, documentation issues, rights attribution concerns, and remediation steps after local payment authorization.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: User questions are stored locally under the user's home directory and may contain sensitive source code, applicant details, trade secrets, or ownership facts.\n\nMitigation: Keep the initial question minimal and avoid including sensitive materials unless local cleartext storage is acceptable.\n\nRisk: Payment authorization is based on local order and credential files and should not be treated as strong proof of payment.\n\nMitigation: Use this package's payment status only as a local workflow gate and rely on the official clawtip payment flow for payment handling.\n\nRisk: The documented sandbox payment command executes an npx package at runtime.\n\nMitigation: Run the sandbox payment command only in a contained environment after reviewing the package and command arguments.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian-clawhub-reviewfix)\n- [Publisher profile](https://clawhub.ai/user/jinyu12166)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance]\n\n**Output Format:** [Conversational assessment report with shell command output and JSON status summaries]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Outputs are primarily Chinese-language compliance review guidance delivered after local order and payment checks.]\n\n## Skill Version(s):\n\n3.1.38 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Skill: soft-ip-full-lifecycle-zijian Owner: jinyu12166 Summary: Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Tags: latest:3.1.38 Version history: v3.1.38 | 2026-07-","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1358,"uniquenessScore":45,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T02:00:42.040Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T02:00:42.040Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T05:55:44.300Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}