{"id":"2e9ceebf-6de1-4321-9850-8c690abfdeb2","entityType":"agent","slug":"clawhub-jinyu12166-soft-ip-full-lifecycle-zijian","name":"soft-ip-full-lifecycle-zijian","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian","canonicalPath":"/agent/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian","generatedAt":"2026-10-10T01:12:43.570Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T14:48:03.461Z","emptyReason":null},"description":"Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Skill: soft-ip-full-lifecycle-zijian Owner: jinyu12166 Summary: Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Tags: latest:3.1.44 Version history: v3.1.44 | 2026-07-","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.5K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17bk5y82fk590863n8fb20zvn8afqra:soft-ip-full-lifecycle-zijian","sourceUrl":"https://clawhub.ai/jinyu12166/soft-ip-full-lifecycle-zijian","homepage":"https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jinyu12166/soft-ip-full-lifecycle-zijian","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":68,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code docum"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:48:03.461Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:48:03.461Z","emptyReason":null},"stars":null,"forks":null,"downloads":2451,"packageName":null,"latestVersion":"3.1.44","tractionLabel":"2.5K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:48:03.461Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T14:48:03.461Z","lastCrawledAt":"2026-10-09T14:48:03.461Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T14:48:03.461Z","lastVerifiedAt":null,"highlights":[{"version":"3.1.44","createdAt":"2026-07-28T14:57:13.401Z","changelog":"- Inlined utility code from file_utils.py and sm4_utils.py into main scripts; removed associated files. - Updated English error messages for clarity and audit compliance. - Revised permissions in metadata: removed \"network.outbound\", added \"credential.read\". - Refined service delivery: clarified that AI performs compliance assessment directly in dialogue after payment. - Expanded documentation in SKILL.md with clearer data handling and rationale for Chinese locale. - Removed skill-card.md for simplification.","fileCount":5,"zipByteSize":9183},{"version":"3.1.43","createdAt":"2026-07-28T12:46:09.228Z","changelog":"**Major update: Now uses official clawtip wallet for payment; external API calls removed.** - Integrated official clawtip wallet for order payment verification. - Eliminated all transmissions to api.ideaidea.com.cn; no outbound HTTP requests. - Updated workflow and environment variable requirements for clarity. - Added new scripts for SM4 encryption utilities. - Removed the local skill-card.md file.","fileCount":7,"zipByteSize":8546},{"version":"3.1.42","createdAt":"2026-07-28T12:02:12.299Z","changelog":"- Switched to official clawtip wallet for payment verification; removed dependency on api.ideaidea.com.cn. - Updated workflow to match official clawtip integration, reflecting new environment variables and service flow. - Added scripts/sm4_utils.py; removed skill-card.md. - Clarified data handling: no remote HTTP requests from this skill, all payment handled via clawtip. - Updated documentation for workflow, sandbox testing, and environment requirements.","fileCount":7,"zipByteSize":8303},{"version":"3.1.41","createdAt":"2026-07-28T08:20:18.355Z","changelog":"Version 3.1.40 - Removed the file skill-card.md from the skill package. - No changes to service logic or user-facing workflow.","fileCount":6,"zipByteSize":7244},{"version":"3.1.39","createdAt":"2026-07-26T14:04:39.324Z","changelog":"- Removed the file skill-card.md from the project. - No changes to feature set or documentation content.","fileCount":6,"zipByteSize":8797},{"version":"3.1.38","createdAt":"2026-07-26T10:33:50.843Z","changelog":"- Removed skill-card.md file. - No functional or workflow changes; documentation file only removed in this version.","fileCount":6,"zipByteSize":8853},{"version":"3.1.37","createdAt":"2026-07-26T09:10:55.133Z","changelog":"- Removed CLAWHUB_REVIEW_FIXES.md and skill-card.md documentation files for streamlining. - No changes to the core skill logic or user workflow. - All service features and instructions remain unchanged.","fileCount":6,"zipByteSize":8913},{"version":"3.1.36","createdAt":"2026-07-21T13:59:55.476Z","changelog":"- Removed the redundant skill-card.md file. - Added a structured workflow section to SKILL.md with explicit steps for order creation, payment, and service. - No functional changes to skill logic or user experience.","fileCount":7,"zipByteSize":12168}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17bk5y82fk590863n8fb20zvn8afqra:soft-ip-full-lifecycle-zijian","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T01:12:43.568Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jinyu12166-soft-ip-full-lifecycle-zijian/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T14:48:03.461Z","emptyReason":null},"readme":"Skill: soft-ip-full-lifecycle-zijian\n\nOwner: jinyu12166\n\nSummary: Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip\n\nTags: latest:3.1.44\n\nVersion history:\n\nv3.1.44 | 2026-07-28T14:57:13.401Z | auto\n\n- Inlined utility code from file_utils.py and sm4_utils.py into main scripts; removed associated files.\n- Updated English error messages for clarity and audit compliance.\n- Revised permissions in metadata: removed \"network.outbound\", added \"credential.read\".\n- Refined service delivery: clarified that AI performs compliance assessment directly in dialogue after payment.\n- Expanded documentation in SKILL.md with clearer data handling and rationale for Chinese locale.\n- Removed skill-card.md for simplification.\n\nv3.1.43 | 2026-07-28T12:46:09.228Z | user\n\n**Major update: Now uses official clawtip wallet for payment; external API calls removed.**\n\n- Integrated official clawtip wallet for order payment verification.\n- Eliminated all transmissions to api.ideaidea.com.cn; no outbound HTTP requests.\n- Updated workflow and environment variable requirements for clarity.\n- Added new scripts for SM4 encryption utilities.\n- Removed the local skill-card.md file.\n\nv3.1.42 | 2026-07-28T12:02:12.299Z | user\n\n- Switched to official clawtip wallet for payment verification; removed dependency on api.ideaidea.com.cn.\n- Updated workflow to match official clawtip integration, reflecting new environment variables and service flow.\n- Added scripts/sm4_utils.py; removed skill-card.md.\n- Clarified data handling: no remote HTTP requests from this skill, all payment handled via clawtip.\n- Updated documentation for workflow, sandbox testing, and environment requirements.\n\nv3.1.41 | 2026-07-28T08:20:18.355Z | user\n\nVersion 3.1.40\n\n- Removed the file skill-card.md from the skill package.\n- No changes to service logic or user-facing workflow.\n\nv3.1.39 | 2026-07-26T14:04:39.324Z | user\n\n- Removed the file skill-card.md from the project.\n- No changes to feature set or documentation content.\n\nv3.1.38 | 2026-07-26T10:33:50.843Z | user\n\n- Removed skill-card.md file.\n- No functional or workflow changes; documentation file only removed in this version.\n\nv3.1.37 | 2026-07-26T09:10:55.133Z | user\n\n- Removed CLAWHUB_REVIEW_FIXES.md and skill-card.md documentation files for streamlining.\n- No changes to the core skill logic or user workflow.\n- All service features and instructions remain unchanged.\n\nv3.1.36 | 2026-07-21T13:59:55.476Z | user\n\n- Removed the redundant skill-card.md file.\n- Added a structured workflow section to SKILL.md with explicit steps for order creation, payment, and service.\n- No functional changes to skill logic or user experience.\n\nv3.1.35 | 2026-07-21T13:43:45.058Z | user\n\n- Removed the skill-card.md file.\n- No changes to skill behavior or end-user features.\n- Workflow metadata added to SKILL.md for clearer process definition.\n\nv3.1.34 | 2026-07-21T10:29:07.045Z | user\n\n- Removed the file skill-card.md from the project.\n- Updated privacy and data processing sections to specify that encrypted payment credentials are transmitted to the third-party verification service during both order creation and fulfillment.\n- Clarified that, before running order creation and service scripts, a notification about transmitted data will be displayed.\n- No user-facing functional changes to core skill logic or workflow.\n- Version number in SKILL.md remains 3.1.33; no content or version update to skill logic itself.\n\nv3.1.33 | 2026-07-20T15:44:26.945Z | user\n\n- Restructured documentation for SkillSpector compliance: separated core capabilities, usage instructions, and data handling sections.\n- Added explicit privacy and data transmission disclosures, clarifying all soft-IP materials and documents are only read and processed locally.\n- Clarified relationship to the soft-ip-full-lifecycle-delivery-pro skill and recommended workflow steps.\n- Updated usage instructions and security details; removed the old skill-card.md file.\n\nv3.1.32 | 2026-07-20T09:37:24.282Z | user\n\n- Removed documentation file skill-card.md.\n- Added scripts/__pycache__/file_utils.cpython-311.pyc (compiled bytecode).\n- No changes to functionality or major flow.\n- Internal cleanup; documentation updated through file removals only.\n\nv3.1.31 | 2026-07-20T08:38:00.010Z | user\n\n- Expanded documentation of full payment and service workflow with phase descriptions in Chinese and English.\n- Added sections clarifying data handling practices (transmitted, stored locally, not collected).\n- Updated description to highlight storage of order metadata under ~/.openclaw/skills/orders/.\n- Removed the sample file skill-card.md.\n- No functional script or logic changes.\n\nv3.1.30 | 2026-07-20T08:17:46.071Z | user\n\n- Updated skill description and documentation for clarity on the three-phase payment flow and local data processing.\n- Added detailed data handling and privacy section; explicitly outlined data transmission and local storage paths.\n- Removed the \"capabilities\" field from metadata.\n- No logic or workflow changes.\n- Deleted the redundant skill-card.md file.\n\nv3.1.29 | 2026-07-20T05:32:08.571Z | user\n\n- Removed the file skill-card.md.\n- No changes to the core workflow or functionality.\n\nv3.1.28 | 2026-07-20T02:32:08.521Z | user\n\n- Major rewrite of documentation for clarity and structure, including fully updated workflow steps and output formats.\n- Added explicit support for user question parameter at order creation.\n- Refined output processing details for each stage, including error handling and standardized messages.\n- Updated instructions for payment integration using clawtip, emphasizing local order file use.\n- Security and metadata handling clarified.\n- Removed obsolete file: skill-card.md.\n\nv3.1.27 | 2026-07-19T10:30:18.385Z | user\n\n- 新增 6 个 pyc 缓存文件至 scripts/__pycache__ 目录。\n- 文档去除所有思考过程相关内容，使用户交互更简洁。\n- 其余功能及流程未做调整。\n\nv3.1.26 | 2026-07-19T10:04:59.686Z | user\n\nNo significant functional changes in this version.\n\n- Documentation updated: clarified workflow steps, payment handling, and execution stages.\n- Expanded and simplified Chinese descriptions for user guidance.\n- Added explicit error handling instructions during order creation.\n- Clarified permission requirements and local/remote data boundaries.\n- Version history initialized at 1.0.0 with release date.\n\nv3.1.25 | 2026-07-19T09:32:21.886Z | user\n\n- Added Python bytecode files for scripts/create_order.py and scripts/file_utils.py (for Python 3.8 and 3.11).\n- Added Python bytecode files for scripts/service.py (for Python 3.8 and 3.11).\n- Removed the file skill-card.md.\n- Minor SKILL.md update: Added a note in the introduction confirming the skill is designed for Chinese-speaking users.\n\nv3.1.22 | 2026-07-19T07:37:39.845Z | user\n\n- Added six compiled Python cache files for scripts (e.g., create_order.pyc, file_utils.pyc, service.pyc) under scripts/__pycache__.\n- Removed the skill-card.md file.\n- No changes to the main SKILL.md content or workflow.\n\nv3.0.19 | 2026-07-18T10:34:30.859Z | user\n\nRemoved hardcoded QR URLs from scripts\n\nv3.1.19 | 2026-07-18T10:29:09.072Z | auto\n\nVersion 3.1.19\n\n- No file changes detected for this release.\n- Functionality, workflow, and documentation remain unchanged from the previous version.\n\nv3.0.18 | 2026-07-18T10:23:15.878Z | user\n\nAdded QR payment option in script output\n\nv3.0.17 | 2026-07-18T09:53:07.347Z | auto\n\n**Added alternate QR code payment option and improved payment instructions.**\n\n- Introduced WeChat and Alipay QR code payment support for users without a ClawTip account.\n- Updated instructions to prompt users about ClawTip wallet availability and guide them to the relevant payment method.\n- Provided QR image links and clear steps for out-of-band payment confirmation.\n- Removed skill-card.md file (deprecated/outdated content).\n\nv3.0.16 | 2026-07-18T04:13:33.745Z | auto\n\nVersion 3.0.16\n\n- Added explicit prerequisite notice: Clawtip-skill must be installed and configured before proceeding with order creation or payment steps.\n- Updated documentation to reflect the requirement for Clawtip-skill for payment processing.\n- Removed skill-card.md from the package.\n\nv3.0.15 | 2026-07-17T07:19:09.018Z | user\n\n- Removed the file: skill-card.md.\n- No other functional or workflow changes in this version.\n\nv3.0.13 | 2026-07-17T01:53:49.951Z | auto\n\nNo changes detected in this version.\n\n- Version 3.0.13 introduces no file or documentation updates.\n\nv3.0.12 | 2026-07-17T01:43:12.038Z | auto\n\nReview-fix v2 release.\n\n- Hardcoded SERVER_URL with no environment variable fallback for increased security.\n- Added explicit NOTICE prints for user awareness.\n- Updated SKILL.md security disclaimer for clearer documentation.\n\nv3.0.11 | 2026-07-17T01:30:43.835Z | auto\n\n- Fixed payment server URL to api.ideaidea.com.cn.\n- Removed interactive input() to enhance agent compatibility.\n- Cleaned up remote and local execution rules according to review findings.\n- Updated privacy notice to clarify network data scope.\n- Removed obsolete documentation and made markdown outputs more modular.\n\nv3.0.10 | 2026-07-16T14:24:17.645Z | auto\n\n- 依赖技能由 `mangogen-user-guide` 更换为 `ecosystem-quickstart`，首次使用引导流程同步更新\n- 技能描述修改，部分中文字符显示异常，出现乱码（如“请求”，“阶段”，“阶段”变为“请�?”，“执�?”等）\n- 调整部分文案使表达更准确，保持服务流程与依赖说明一致\n- `requires` 字段仅保留所需依赖，移除旧文档依赖\n- 其他内容未作结构性调整，主要流程和规则未变\n\nv3.0.9 | 2026-07-16T14:19:32.572Z | user\n\nAdd requires hint for clawtip-skill and user guide\n\nv3.0.8 | 2026-07-16T10:35:21.356Z | auto\n\nsoft-ip-full-lifecycle-zijian v3.0.8\n\n- 优化 SKILL.md 文档流程与说明，无功能和接口变更。\n- 修正与简化部分文档描述，删除冗余字段。\n- 保持服务执行与支付流程无修改，完善用户指引语句。\n- 未改动服务脚本主逻辑，仅维护文档清晰度与合规性。\n\nv3.0.7 | 2026-07-16T09:21:19.016Z | auto\n\nsoft-ip-full-lifecycle-zijian v3.0.7\n\n- Updated scripts/create_order.py and scripts/service.py to improve order creation and service execution.\n- No user-facing workflow or documentation changes detected.\n- No impact to the structured output or main service process.\n\nv3.0.6 | 2026-07-16T08:06:40.426Z | auto\n\n**重大更新：全面重构服务说明与本地隐私合规，完善中文流程文档。**\n\n- 完全用中文重写服务流程与合规说明，对用户交互和本地隐私处理进行详细规范。\n- 明确划分“订单创建”“支付处理”“服务执行”三大阶段，强化错误处理和终止条件。\n- 增强用户提示与自检规则，详细禁止使用AI套话、模糊表述与模板语句。\n- 新增详细事实采集表格与复核节点，强调每份文档必须经申请人人工校验。\n- 拆解并细化8份输出Markdown草稿的生成逻辑及内容合规标准。\n- 移除 skill-card.md，所有官方说明以 SKILL.md 为唯一权威。\n\nv3.0.5 | 2026-07-14T07:51:11.613Z | auto\n\n- Removed the skill-card.md file.\n- Updated scripts/service.py (contents not detailed).\n- No changes to the overall workflow or functionality described in SKILL.md.\n- Minor cleanup of repository documentation.\n\nv3.0.4 | 2026-07-14T06:59:50.061Z | auto\n\n- Removed the skill-card.md file.\n- Updated scripts/create_order.py.\n- No changes to user-facing workflow or documented usage.\n- Documentation and main process remain consistent with previous version.\n\nv3.0.2 | 2026-07-14T04:42:53.114Z | auto\n\nVersion 3.0.2\n\n- Payment and draft workflow now strictly separates remote authorization and local processing.\n- Remote endpoint is used only for order creation, payment credential check, and authorization status—no project data or drafts are uploaded.\n- All scans and draft generation are performed locally and only after explicit user confirmation.\n- Added CLAWHUB_REVIEW_FIXES.md, removed skill-card.md, and updated workflow description in SKILL.md for clarity and privacy.\n- Local review is required before proceeding at each step; automated submission to platforms is not supported.\n\nv2.0.2 | 2026-07-14T03:52:26.917Z | auto\n\nVersion 2.0.2\n\n- 安全合规优化：移除审核敏感指令，补充隐私说明，切换服务为 HTTPS，并增加本地订单路径校验。\n- 文档结构优化：修订 SKILL.md，删除 skill-card.md，完善订单处理和输出流程描述。\n- 维护与兼容：同步 scripts 目录内 create_order.py 与 service.py 的实现细节，确保流程更严谨。\n- 规范输出：进一步细化流程控制，强调出错时流程强制终止及清晰告知用户。\n- 细节修订：标准化合规节点、人工复核与自检要求，提升操作指引实用性和易懂性。\n\nv3.0.1 | 2026-07-13T16:16:34.236Z | auto\n\nVersion 3.0.1\n\n- 安全审核修复：移除推理过程指令，确保对用户的引导更简明合规。\n- 补充隐私说明，明确项目和源码信息在本地处理、不传输到支付服务。\n- 切换所有后端服务访问至 HTTPS，提升数据安全性。\n- 增加本地订单路径有效性校验，防止路径伪造或错误访问。\n- 移除 skill-card.md 文件，精简资源。\n\nv1.0.0 | 2026-07-13T11:42:36.371Z | auto\n\nsoft-ip-full-lifecycle-zijian v1.0.0\n\n- 首次发布软著申报材料辅助整理服务技能。\n- 基于实际开发事实，生成 8 份结构化软著申报 Markdown 草稿。\n- 明确分为订单创建、支付处理和服务执行三大阶段，需支付验证后执行服务。\n- 详细要求全过程仅用中文交互，并严格依照事实、禁止 AI 套话。\n- 每个阶段失败时及时通报用户并终止后续流程，保障合规性和人工复核节点。\n\nArchive index:\n\nArchive v3.1.44: 5 files, 9183 bytes\n\nFiles: scripts/create_order.py (8173b), scripts/service.py (4377b), skill-card.md (2227b), SKILL.md (4699b), _meta.json (149b)\n\nFile v3.1.44:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\nversion: \"3.2.1\"\ndescription: >\n  Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip. Chinese-language service (中国软件著作权申报所需).\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# soft-ip-full-lifecycle-zijian\n\n**语言说明 / Language:** This skill is designed for Chinese software copyright compliance (中国软件著作权申报), and its user-facing interface is primarily in Chinese. Core metadata and technical documentation are in English for accessibility.\n\n## 技能概述\n\n软件知识产权全生命周期自检与合规审查服务。本技能通过 clawtip 完成支付验证后，**由 AI 模型在对话中**交付合规诊断和材料审查结果。\n\n### 服务交付方式\n\n本技能是 **AI 对话交付型** 服务：\n- `create_order.py` — 创建本地订单文件（仅用于 clawtip 支付验证）\n- 支付由 **clawtip** 官方钱包处理\n- `service.py` — 验证支付凭证后，指示 AI 在对话中执行以下 5 项评估\n\n### 5 项合规评估\n\n| # | 评估项 | 说明 |\n|---|--------|------|\n| 1 | 材料完整性审查 | 对照软著登记要求逐项检查材料是否齐全 |\n| 2 | 源代码文档审计 | 格式验证、页数检查、前/后30页完整性 |\n| 3 | 用户手册合规检查 | 截图格式、功能描述完整性 |\n| 4 | 权利归属验证 | 权属声明、合作协议框架检查 |\n| 5 | 登记就绪评估 | 风险分级（阻塞性 / 建议性 / 参考性），修复建议 |\n\n### 与 delivery-pro 的关系\n\n| 维度 | zijian（本技能，诊断版） | delivery-pro（生成版） |\n|------|------------------------|-----------------------|\n| 用途 | 合规性诊断：识别缺失和问题 | 文档生成：填写全部 8 项申报材料 |\n| 价格 | 190 UT (1.9 元) | 690 UT (6.9 元) |\n| 输出 | 缺失清单 + 问题标注 + 风险评级 | 完整的可提交文档草稿 |\n| 建议顺序 | 先运行：诊断问题，补充材料 | 后运行：基于完善的材料生成文档 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥 |\n\n> 以上环境变量仅用于 clawtip 支付凭证加密，不收集、不传输任何业务数据。\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n> 本地订单文件路径：`~/.openclaw/skills/orders/{indicator}/{order_no}.json`\n> 包含字段：orderNo、amount、question。仅用于支付验证，不涉及任何审查材料。\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n**失败：** `订单创建失败: <详情>` → 终止。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：合规审查\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n成功后，AI 模型将在对话中输出完整的合规评估报告。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n| 文件 | 路径 | 内容 |\n|------|------|------|\n| 订单文件 | `~/.openclaw/skills/orders/{indicator}/{order_no}.json` | orderNo、amount、question、加密凭证 |\n\n### 远程传输\n本技能自身不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n### 绝不收集或传输\n源代码、申报文档、著作权人信息、公司信息或商业秘密。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.2.1 | 2026-07-28 | Fix SkillSpector: inline file_utils/SM4; English error messages; service delivery spec; add permissions; justify Chinese locale |\n| 3.2.0 | 2026-07-28 | Switch to official clawtip wallet |\n| 3.1.34 | 2026-07-28 | Fix ClawHub audit |\n| 3.1.33 | 2026-07-20 | Security review |\n\nFile v3.1.44:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.44\",\n  \"publishedAt\": 1785250633401\n}\n\nFile v3.1.44:skill-card.md\n\n## Description:\n\nSoftware IP self-assessment skill that delivers Chinese software copyright application compliance review after clawtip payment verification.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jinyu12166](https://clawhub.ai/user/jinyu12166)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal developers, software teams, and applicants preparing Chinese software copyright registration use this skill to check material completeness, source-code documentation, user manuals, rights attribution, and registration readiness.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Local order files may persist the user's question and payment metadata.\n\nMitigation: Avoid submitting source code, applicant identity details, trade secrets, or complete legal materials in the question, and remove local order files when they are no longer needed.\n\nRisk: Payment verification is weak if local credential fields are trusted without signed credential validation.\n\nMitigation: Verify the clawtip tooling provenance and require signed credential validation before relying on payment status for sensitive or high-value use.\n\nRisk: The service produces compliance guidance that may affect software copyright filings.\n\nMitigation: Treat the output as self-assessment guidance and have qualified legal or IP reviewers check filing decisions before submission.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Plain text and Markdown guidance with shell command output and JSON_RESULT status lines]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires clawtip payment verification before the AI-delivered compliance review proceeds.]\n\n## Skill Version(s):\n\n3.1.44 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v3.1.43: 7 files, 8546 bytes\n\nFiles: scripts/create_order.py (3282b), scripts/file_utils.py (2170b), scripts/service.py (2102b), scripts/sm4_utils.py (3302b), skill-card.md (2365b), SKILL.md (3080b), _meta.json (149b)\n\nFile v3.1.43:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\nversion: \"3.2.0\"\ndescription: >\n  Software IP full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. AI-delivered service via clawtip verification.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# soft-ip-full-lifecycle-zijian\n\n## 技能概述\n\n软件知识产权全生命周期自检与合规审查服务。付费服务，通过 clawtip 完成支付验证后由 AI 交付合规诊断和材料审查。\n\n**直接执行：** 如用户已提供带支付凭证的订单号，直接跳到第三阶段。\n\n### 与 delivery-pro 的关系\n\n| 维度 | zijian（本技能，诊断版） | delivery-pro（生成版） |\n|------|------------------------|-----------------------|\n| 用途 | 合规性诊断：识别缺失和问题 | 文档生成：填写全部 8 项申报材料 |\n| 价格 | 190 UT (1.9 元) | 690 UT (6.9 元) |\n| 输出 | 缺失清单 + 问题标注 + 风险评级 | 完整的可提交文档草稿 |\n| 建议顺序 | 先运行：诊断问题，补充材料 | 后运行：基于完善的材料生成文档 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥（十六进制，32 字符） |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n\n**失败：** `订单创建失败: <详情>` → 终止工作流。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n输出 `PAY_STATUS: SUCCESS | ERROR`。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n订单元数据保存至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`。\n\n### 远程传输\n本技能不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.2.0 | 2026-07-28 | Switch to official clawtip wallet; remove api.ideaidea.com.cn |\n| 3.1.34 | 2026-07-28 | Fix ClawHub audit |\n| 3.1.33 | 2026-07-20 | Security review for SkillSpector |\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.43:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.43\",\n  \"publishedAt\": 1785242769228\n}\n\nFile v3.1.43:skill-card.md\n\n## Description: <br>\nSoftware IP full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications, delivered through clawtip payment verification. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users use this skill to create and verify a paid clawtip order for a Chinese software copyright readiness review. After payment verification, the skill is intended to support AI-guided review of material completeness, compliance issues, and registration readiness. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The security evidence says the artifacts do not define the promised software copyright assessment service after payment. <br>\nMitigation: Review before installing or using commercially, and require clear post-payment assessment instructions or deliverable logic before relying on the skill for a complete self-assessment. <br>\nRisk: The skill handles paid order creation, local payment credentials, and local order metadata. <br>\nMitigation: Use only with a trusted clawtip setup, review required environment variables before execution, and inspect locally stored order files for sensitive data handling expectations. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Shell commands, JSON, Files, Guidance] <br>\n**Output Format:** [Plain text and command output with JSON_RESULT lines; intended service guidance may be delivered as agent text after payment verification.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Creates and reads local order metadata under the user's OpenClaw skills order directory.] <br>\n\n## Skill Version(s): <br>\n3.1.43 (source: server release evidence and target metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.42: 7 files, 8303 bytes\n\nFiles: scripts/create_order.py (2962b), scripts/file_utils.py (2170b), scripts/service.py (2102b), scripts/sm4_utils.py (3302b), skill-card.md (2122b), SKILL.md (3080b), _meta.json (149b)\n\nFile v3.1.42:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\nversion: \"3.2.0\"\ndescription: >\n  Software IP full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. AI-delivered service via clawtip verification.\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# soft-ip-full-lifecycle-zijian\n\n## 技能概述\n\n软件知识产权全生命周期自检与合规审查服务。付费服务，通过 clawtip 完成支付验证后由 AI 交付合规诊断和材料审查。\n\n**直接执行：** 如用户已提供带支付凭证的订单号，直接跳到第三阶段。\n\n### 与 delivery-pro 的关系\n\n| 维度 | zijian（本技能，诊断版） | delivery-pro（生成版） |\n|------|------------------------|-----------------------|\n| 用途 | 合规性诊断：识别缺失和问题 | 文档生成：填写全部 8 项申报材料 |\n| 价格 | 190 UT (1.9 元) | 690 UT (6.9 元) |\n| 输出 | 缺失清单 + 问题标注 + 风险评级 | 完整的可提交文档草稿 |\n| 建议顺序 | 先运行：诊断问题，补充材料 | 后运行：基于完善的材料生成文档 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥（十六进制，32 字符） |\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n\n**失败：** `订单创建失败: <详情>` → 终止工作流。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：服务执行\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n输出 `PAY_STATUS: SUCCESS | ERROR`。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n订单元数据保存至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`。\n\n### 远程传输\n本技能不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n---\n\n## 版本历史\n\n| Version | Date | Notes |\n|:--------|:-----|:------|\n| 3.2.0 | 2026-07-28 | Switch to official clawtip wallet; remove api.ideaidea.com.cn |\n| 3.1.34 | 2026-07-28 | Fix ClawHub audit |\n| 3.1.33 | 2026-07-20 | Security review for SkillSpector |\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.42:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.42\",\n  \"publishedAt\": 1785240132299\n}\n\nFile v3.1.42:skill-card.md\n\n## Description: <br>\nSoftware IP full lifecycle self-assessment for material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications, delivered through clawtip payment verification. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers use this skill to create a paid clawtip order, verify payment, and receive AI-assisted compliance diagnostics for Chinese software copyright application materials. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill processes software copyright consultation content and relies on a third-party publisher to receive payment through clawtip. <br>\nMitigation: Install and use the skill only after confirming that the publisher jinyu12166 is trusted for the payment and consultation information involved. <br>\nRisk: Local order files can remain in the user's OpenClaw orders directory after payment and service execution. <br>\nMitigation: Review and remove local order files when they are no longer needed, especially if they contain sensitive consultation details. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with shell command examples and JSON status lines] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires clawtip payment verification before service execution.] <br>\n\n## Skill Version(s): <br>\n3.1.42 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.41: 6 files, 7244 bytes\n\nFiles: scripts/create_order.py (3384b), scripts/file_utils.py (2170b), scripts/service.py (2800b), skill-card.md (2491b), SKILL.md (3949b), _meta.json (149b)\n\nFile v3.1.41:SKILL.md\n\n---\nname: \"soft-ip-full-lifecycle-zijian\"\ndescription: >\n  Software IP full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. AI-delivered service. Question text and order metadata are transmitted via HTTPS to api.ideaidea.com.cn for order creation and fulfillment. No source code or project files are uploaded.\nmetadata:\n  author: \"Yujin\"\n  version: \"3.1.34\"\n  category: \"expert\"\n  capabilities:\n    - \"payment.process\"\n  permissions:\n    - \"network.outbound\"\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip-skill\"\n---\n\n# soft-ip-full-lifecycle-zijian\n\n## Skill Overview\n\nSoftware IP full lifecycle self-assessment and compliance review service. This is a paid service; payment verification is handled via clawtip, and the AI model delivers compliance diagnosis and material review in the conversation context.\n\n**Direct execution:** If the user has already provided an <<order_no>> (and the order file already contains payCredential), skip directly to the third stage.\n\n### Relationship with soft-ip-full-lifecycle-delivery-pro\n\n| | zijian (this skill, diagnostic edition) | delivery-pro (generation edition) |\n|---|---|---|\n| Purpose | Compliance diagnosis: identify gaps and issues | Document generation and delivery: fill out all 8 application materials |\n| Price | 190 UT (1.9 yuan) | 690 UT (6.9 yuan) |\n| Output | Gap checklist + issue annotations + risk grading | Complete submission-ready document drafts |\n| Suggested order | Run first: diagnose issues and supplement materials | Run after: generate documents based on supplemented materials |\n\n**Recommended: run this skill first for compliance review, then use delivery-pro for document generation.**\n\n### Capabilities\n\n- Material completeness review: checklist against copyright registration requirements\n- Source code documentation compliance: format validation, 30-page requirement check\n- User manual audit: screenshot format, feature description completeness\n- Rights attribution check: ownership declarations, collaboration agreements\n- Registration readiness audit: risk grading (blocking/advisory/informational)\n\n---\n\n## First Stage: Create Order\n\n### 1. Required Parameters\n* `<question>`: the user specific question or content.\n\n### 2. Execution Command\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n### 3. Output Processing\n**On success:** ORDER_NO, AMOUNT, QUESTION, INDICATOR\nAMOUNT is in RMB fen (divide by 100 for yuan).\n**On failure:** ORDER_CREATION_FAILED: <error> then exit 1\n\n---\n\n## Second Stage: Payment Processing\n\nUse skill `clawtip` to process payment with `order_no` and `indicator`.\n\n---\n\n## Third Stage: Service Execution\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\nOutput: PAY_STATUS: SUCCESS|PROCESSING|FAIL|ERROR\n\n---\n\n## Data Handling\n\n### Local Storage\nOrder metadata saved to ~/.openclaw/skills/orders/{indicator}/{order_no}.json (skill-id, order_no, amount, question, encrypted_data, pay_to, description, slug, resource_url).\n\n### Remote Transmission\n- Phase 1: Sends slug + question text to api.ideaidea.com.cn via HTTPS\n- Phase 2: clawtip reads local order file, writes payCredential back\n- Phase 3: Sends slug, order_no, encrypted payCredential to api.ideaidea.com.cn\n\n### Not Collected or Transmitted\nNo source code, application documents, company information, contract files, trade secrets, or personal identity information is read or uploaded. Service results delivered by AI in conversation.\n\n---\n\n## Version History\n\n| Version | Date | Notes |\n|:---|:---|:---|\n| 3.1.34 | 2026-07-28 | Fix ClawHub audit: remove false SM4 claims, accurate AI-delivered disclosure, remove Chinese-only policy, remove false local-processing claims |\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance |\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.41:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.41\",\n  \"publishedAt\": 1785226818355\n}\n\nFile v3.1.41:skill-card.md\n\n## Description: <br>\nSoftware IP full lifecycle self-assessment for material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, product teams, and software copyright applicants use this paid skill to assess whether their Chinese software copyright registration materials are complete, compliant, and ready for submission before moving to document generation or filing. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Question text, order metadata, and encrypted payment credentials are sent to the provider API over HTTPS. <br>\nMitigation: Avoid including source code, trade secrets, contracts, identity documents, or other sensitive details in the question unless the user accepts sharing them with the provider. <br>\nRisk: The workflow depends on a paid order and external payment verification before service execution. <br>\nMitigation: Confirm the order number, amount, payment status, and provider endpoint before proceeding with service execution. <br>\nRisk: Order metadata and payment-related fields are stored locally in the OpenClaw orders directory. <br>\nMitigation: Treat local order files as sensitive payment workflow records and remove or protect them according to the user's retention needs. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian) <br>\n- [ClawHub publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and payment/service status lines] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Produces a gap checklist, issue annotations, and risk grading after the paid order and payment verification flow succeeds.] <br>\n\n## Skill Version(s): <br>\n3.1.41 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.39: 6 files, 8797 bytes\n\nFiles: scripts/create_order.py (3719b), scripts/file_utils.py (2170b), scripts/service.py (3094b), skill-card.md (2584b), SKILL.md (6162b), _meta.json (149b)\n\nFile v3.1.39:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. User questions and encrypted payment credentials are transmitted via HTTPS to api.ideaidea.com.cn (clawtip verification service) for order creation and fulfillment. No source code, project files, or sensitive legal documents are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.1.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供软件著作权申报材料的自检与合规审查服务。它帮助您在中国版权保护中心申报软著之前，系统性地检查申请材料的完整性与合规性，降低因材料问题导致的补正或驳回风险。\r\n\r\n**所有材料分析在本机完成，您的源代码和申报文档绝不会上传。** 身份验证通过 clawtip 第三方服务进行。\r\n\r\n### 核心能力\r\n\r\n**材料完整性审查**\r\n- 对照软著申报要求逐项核查材料齐备情况\r\n- 标识缺失项（申请表、源代码文档、用户手册、权利归属证明等）\r\n- 生成缺失材料清单及补交优先级建议\r\n\r\n**源代码文档合规检查**\r\n- 检查源代码文档的格式规范性（页眉、页码、行号等）\r\n- 验证前后各 30 页的完整性要求\r\n- 审查代码与软件的对应关系一致性\r\n\r\n**用户手册/说明书审核**\r\n- 检查操作手册的截图格式与清晰度要求\r\n- 验证功能描述的完整性与技术准确性\r\n- 审查版本号、软件名称的一致性\r\n\r\n**权利归属与合规性检查**\r\n- 检查著作权归属声明的完整性与合法性\r\n- 验证合作开发/委托开发协议的存在性与有效性\r\n- 审查职务作品、法人作品的权属说明\r\n\r\n**登记就绪审计**\r\n- 综合判断软著申报的当前就绪状态\r\n- 按风险等级分类问题（阻断性/建议性/提示性）\r\n- 输出可提交性评估与补正建议\r\n\r\n### 与其他技能的关系\r\n\r\n- **本技能定位**：材料诊断与合规审查（告诉您问题在哪、缺什么）\r\n- **soft-ip-full-lifecycle-delivery-pro**（另行安装）：全量文档生成与填写辅助（帮您把 8 份申报材料填好）\r\n- 建议先使用本技能完成诊断，再使用 delivery-pro 进行文档生成\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我检查一下软著申报材料还缺什么\"\r\n- \"我准备了源代码文档，看看格式符不符合要求\"\r\n- \"这份用户手册的截图清晰度够不够过审\"\r\n- \"我的软件是合作开发的，权利归属怎么写\"\r\n- \"提交前帮我做个全面的登记就绪审计\"\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 软著材料的分析与审核由 AI 在本地完成\r\n- 合规检查清单与补正建议在本地生成\r\n- 所有文件读取、格式检查均在本机完成\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- 您的软件源代码（源码仅在本地读取分析）\r\n- 软著申报文档内容（仅在本地审核）\r\n- 公司信息、合同文件、商业机密\r\n- 个人身份信息或联系信息\r\n\r\n每次网络请求前，脚本会明确打印将要传输的数据范围。\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n**所需参数：** `<question>` — 您的软著相关咨询内容。\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nQUESTION=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，输出 `订单创建失败: <错误详情>`，须立即终止流程。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取自检服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付软著材料自检与合规审查结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added cross-reference to delivery-pro, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.39:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.39\",\n  \"publishedAt\": 1785074679324\n}\n\nFile v3.1.39:skill-card.md\n\n## Description: <br>\nSoftware intellectual property full lifecycle self-assessment for Chinese software copyright applications, covering material completeness review, compliance verification, and registration readiness audit while using a third-party ClawTip service for order creation and payment verification. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers preparing Chinese software copyright applications use this skill to check source-code documentation, user manuals, rights documentation, and overall submission readiness before filing. The skill is designed to produce local self-assessment guidance and issue lists, with paid access verified through ClawTip. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The initial question is sent to a third-party order service during order creation. <br>\nMitigation: Do not include source code, contracts, company secrets, personal identifiers, or other sensitive material in the initial question. <br>\nRisk: Payment and order metadata is stored locally in the user's OpenClaw orders directory. <br>\nMitigation: Review and remove local order files after use when retention is not needed. <br>\nRisk: The skill requires network access and third-party payment verification before service delivery. <br>\nMitigation: Review the printed data-transfer notices before running order creation or verification commands. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian) <br>\n- [Third-party order and verification service](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Chinese Markdown guidance with command-line status output for order creation and payment verification.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The service flow depends on a valid ClawTip order and may store order metadata locally under the user's OpenClaw orders directory.] <br>\n\n## Skill Version(s): <br>\n3.1.39 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.38: 6 files, 8853 bytes\n\nFiles: scripts/create_order.py (3632b), scripts/file_utils.py (2170b), scripts/service.py (3094b), skill-card.md (2582b), SKILL.md (6162b), _meta.json (149b)\n\nFile v3.1.38:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. User questions and encrypted payment credentials are transmitted via HTTPS to api.ideaidea.com.cn (clawtip verification service) for order creation and fulfillment. No source code, project files, or sensitive legal documents are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.1.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供软件著作权申报材料的自检与合规审查服务。它帮助您在中国版权保护中心申报软著之前，系统性地检查申请材料的完整性与合规性，降低因材料问题导致的补正或驳回风险。\r\n\r\n**所有材料分析在本机完成，您的源代码和申报文档绝不会上传。** 身份验证通过 clawtip 第三方服务进行。\r\n\r\n### 核心能力\r\n\r\n**材料完整性审查**\r\n- 对照软著申报要求逐项核查材料齐备情况\r\n- 标识缺失项（申请表、源代码文档、用户手册、权利归属证明等）\r\n- 生成缺失材料清单及补交优先级建议\r\n\r\n**源代码文档合规检查**\r\n- 检查源代码文档的格式规范性（页眉、页码、行号等）\r\n- 验证前后各 30 页的完整性要求\r\n- 审查代码与软件的对应关系一致性\r\n\r\n**用户手册/说明书审核**\r\n- 检查操作手册的截图格式与清晰度要求\r\n- 验证功能描述的完整性与技术准确性\r\n- 审查版本号、软件名称的一致性\r\n\r\n**权利归属与合规性检查**\r\n- 检查著作权归属声明的完整性与合法性\r\n- 验证合作开发/委托开发协议的存在性与有效性\r\n- 审查职务作品、法人作品的权属说明\r\n\r\n**登记就绪审计**\r\n- 综合判断软著申报的当前就绪状态\r\n- 按风险等级分类问题（阻断性/建议性/提示性）\r\n- 输出可提交性评估与补正建议\r\n\r\n### 与其他技能的关系\r\n\r\n- **本技能定位**：材料诊断与合规审查（告诉您问题在哪、缺什么）\r\n- **soft-ip-full-lifecycle-delivery-pro**（另行安装）：全量文档生成与填写辅助（帮您把 8 份申报材料填好）\r\n- 建议先使用本技能完成诊断，再使用 delivery-pro 进行文档生成\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我检查一下软著申报材料还缺什么\"\r\n- \"我准备了源代码文档，看看格式符不符合要求\"\r\n- \"这份用户手册的截图清晰度够不够过审\"\r\n- \"我的软件是合作开发的，权利归属怎么写\"\r\n- \"提交前帮我做个全面的登记就绪审计\"\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 软著材料的分析与审核由 AI 在本地完成\r\n- 合规检查清单与补正建议在本地生成\r\n- 所有文件读取、格式检查均在本机完成\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- 您的软件源代码（源码仅在本地读取分析）\r\n- 软著申报文档内容（仅在本地审核）\r\n- 公司信息、合同文件、商业机密\r\n- 个人身份信息或联系信息\r\n\r\n每次网络请求前，脚本会明确打印将要传输的数据范围。\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n**所需参数：** `<question>` — 您的软著相关咨询内容。\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nQUESTION=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，输出 `订单创建失败: <错误详情>`，须立即终止流程。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取自检服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付软著材料自检与合规审查结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added cross-reference to delivery-pro, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.38:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.38\",\n  \"publishedAt\": 1785062030843\n}\n\nFile v3.1.38:skill-card.md\n\n## Description: <br>\nAssists users with Chinese software copyright application readiness by reviewing material completeness, format compliance, rights ownership, and submission risks while using a third-party order and payment verification service. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers use this skill to self-assess Chinese software copyright registration materials before submission, including missing-material checks, source-code document formatting, user-manual review, rights ownership checks, and registration readiness guidance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill sends the user's consultation question to api.ideaidea.com.cn during order creation. <br>\nMitigation: Do not include confidential source code, contract text, identity data, or sensitive company details in the question. <br>\nRisk: The inspected code retains order and payment verification metadata in a local OpenClaw orders directory. <br>\nMitigation: Manually delete the local order file after use if the retained payment metadata is no longer needed. <br>\nRisk: Security evidence reports an unsupported extra encryption claim in the skill's disclosures. <br>\nMitigation: Treat HTTPS transmission and disclosed local storage as the confirmed behavior, and review the network and payment-verification flow before installation. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian) <br>\n- [Clawtip verification service endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Markdown, Shell commands, Configuration instructions] <br>\n**Output Format:** [Chinese-language guidance with shell command outputs and JSON status fields] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires clawtip-skill for payment verification; stores order metadata locally under the user's OpenClaw skills orders directory.] <br>\n\n## Skill Version(s): <br>\n3.1.38 (source: server release evidence; artifact frontmatter reports 3.1.33) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.37: 6 files, 8913 bytes\n\nFiles: scripts/create_order.py (3632b), scripts/file_utils.py (2170b), scripts/service.py (3155b), skill-card.md (2610b), SKILL.md (6156b), _meta.json (149b)\n\nFile v3.1.37:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. User questions and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No source code, project files, or sensitive legal documents are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.1.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供软件著作权申报材料的自检与合规审查服务。它帮助您在中国版权保护中心申报软著之前，系统性地检查申请材料的完整性与合规性，降低因材料问题导致的补正或驳回风险。\r\n\r\n**所有材料分析在本机完成，您的源代码和申报文档绝不会上传。** 身份验证通过 clawtip 第三方服务进行。\r\n\r\n### 核心能力\r\n\r\n**材料完整性审查**\r\n- 对照软著申报要求逐项核查材料齐备情况\r\n- 标识缺失项（申请表、源代码文档、用户手册、权利归属证明等）\r\n- 生成缺失材料清单及补交优先级建议\r\n\r\n**源代码文档合规检查**\r\n- 检查源代码文档的格式规范性（页眉、页码、行号等）\r\n- 验证前后各 30 页的完整性要求\r\n- 审查代码与软件的对应关系一致性\r\n\r\n**用户手册/说明书审核**\r\n- 检查操作手册的截图格式与清晰度要求\r\n- 验证功能描述的完整性与技术准确性\r\n- 审查版本号、软件名称的一致性\r\n\r\n**权利归属与合规性检查**\r\n- 检查著作权归属声明的完整性与合法性\r\n- 验证合作开发/委托开发协议的存在性与有效性\r\n- 审查职务作品、法人作品的权属说明\r\n\r\n**登记就绪审计**\r\n- 综合判断软著申报的当前就绪状态\r\n- 按风险等级分类问题（阻断性/建议性/提示性）\r\n- 输出可提交性评估与补正建议\r\n\r\n### 与其他技能的关系\r\n\r\n- **本技能定位**：材料诊断与合规审查（告诉您问题在哪、缺什么）\r\n- **soft-ip-full-lifecycle-delivery-pro**（另行安装）：全量文档生成与填写辅助（帮您把 8 份申报材料填好）\r\n- 建议先使用本技能完成诊断，再使用 delivery-pro 进行文档生成\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我检查一下软著申报材料还缺什么\"\r\n- \"我准备了源代码文档，看看格式符不符合要求\"\r\n- \"这份用户手册的截图清晰度够不够过审\"\r\n- \"我的软件是合作开发的，权利归属怎么写\"\r\n- \"提交前帮我做个全面的登记就绪审计\"\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 软著材料的分析与审核由 AI 在本地完成\r\n- 合规检查清单与补正建议在本地生成\r\n- 所有文件读取、格式检查均在本机完成\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- 您的软件源代码（源码仅在本地读取分析）\r\n- 软著申报文档内容（仅在本地审核）\r\n- 公司信息、合同文件、商业机密\r\n- 个人身份信息或联系信息\r\n\r\n每次网络请求前，脚本会明确打印将要传输的数据范围。\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n**所需参数：** `<question>` — 您的软著相关咨询内容。\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nQUESTION=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，输出 `订单创建失败: <错误详情>`，须立即终止流程。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取自检服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付软著材料自检与合规审查结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added cross-reference to delivery-pro, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.37:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.37\",\n  \"publishedAt\": 1785057055133\n}\n\nFile v3.1.37:skill-card.md\n\n## Description: <br>\nSoftware intellectual property full lifecycle self-assessment for Chinese software copyright applications, covering material completeness review, compliance verification, and registration readiness audit. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users preparing Chinese software copyright applications use this skill to check application materials, source-code document format, user manuals, rights ownership statements, and registration readiness before submission. <br>\n\n### Deployment Geography for Use: <br>\nChina <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Question text and payment-verification data are sent to api.ideaidea.com.cn, and order or payment metadata is stored locally. <br>\nMitigation: Avoid confidential source code, contracts, personal data, or sensitive business details in the question field; delete local order files when they are no longer needed. <br>\nRisk: The security review recommends caution because encryption and data-transfer claims are not fully supported by the visible code. <br>\nMitigation: Treat the flow as third-party HTTPS payment verification and review the endpoint, credential handling, and local storage behavior before use with sensitive matters. <br>\nRisk: The skill requests network, credential-read, filesystem-read, and filesystem-write permissions. <br>\nMitigation: Run it in a constrained environment and review retained order files before sharing or archiving the workspace. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian) <br>\n- [clawtip verification service endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Markdown, Shell commands, Guidance] <br>\n**Output Format:** [Chinese plain text or Markdown guidance with shell command outputs and JSON_RESULT status lines.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires an order number and successful payment authorization before the self-assessment service is delivered.] <br>\n\n## Skill Version(s): <br>\n3.1.37 (source: release evidence; artifact frontmatter lists 3.1.33) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.36: 7 files, 12168 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6176b), scripts/create_order.py (3688b), scripts/file_utils.py (2170b), scripts/service.py (3155b), skill-card.md (2617b), SKILL.md (6156b), _meta.json (149b)\n\nFile v3.1.36:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. User questions and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No source code, project files, or sensitive legal documents are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.1.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供软件著作权申报材料的自检与合规审查服务。它帮助您在中国版权保护中心申报软著之前，系统性地检查申请材料的完整性与合规性，降低因材料问题导致的补正或驳回风险。\r\n\r\n**所有材料分析在本机完成，您的源代码和申报文档绝不会上传。** 身份验证通过 clawtip 第三方服务进行。\r\n\r\n### 核心能力\r\n\r\n**材料完整性审查**\r\n- 对照软著申报要求逐项核查材料齐备情况\r\n- 标识缺失项（申请表、源代码文档、用户手册、权利归属证明等）\r\n- 生成缺失材料清单及补交优先级建议\r\n\r\n**源代码文档合规检查**\r\n- 检查源代码文档的格式规范性（页眉、页码、行号等）\r\n- 验证前后各 30 页的完整性要求\r\n- 审查代码与软件的对应关系一致性\r\n\r\n**用户手册/说明书审核**\r\n- 检查操作手册的截图格式与清晰度要求\r\n- 验证功能描述的完整性与技术准确性\r\n- 审查版本号、软件名称的一致性\r\n\r\n**权利归属与合规性检查**\r\n- 检查著作权归属声明的完整性与合法性\r\n- 验证合作开发/委托开发协议的存在性与有效性\r\n- 审查职务作品、法人作品的权属说明\r\n\r\n**登记就绪审计**\r\n- 综合判断软著申报的当前就绪状态\r\n- 按风险等级分类问题（阻断性/建议性/提示性）\r\n- 输出可提交性评估与补正建议\r\n\r\n### 与其他技能的关系\r\n\r\n- **本技能定位**：材料诊断与合规审查（告诉您问题在哪、缺什么）\r\n- **soft-ip-full-lifecycle-delivery-pro**（另行安装）：全量文档生成与填写辅助（帮您把 8 份申报材料填好）\r\n- 建议先使用本技能完成诊断，再使用 delivery-pro 进行文档生成\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我检查一下软著申报材料还缺什么\"\r\n- \"我准备了源代码文档，看看格式符不符合要求\"\r\n- \"这份用户手册的截图清晰度够不够过审\"\r\n- \"我的软件是合作开发的，权利归属怎么写\"\r\n- \"提交前帮我做个全面的登记就绪审计\"\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 软著材料的分析与审核由 AI 在本地完成\r\n- 合规检查清单与补正建议在本地生成\r\n- 所有文件读取、格式检查均在本机完成\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- 您的软件源代码（源码仅在本地读取分析）\r\n- 软著申报文档内容（仅在本地审核）\r\n- 公司信息、合同文件、商业机密\r\n- 个人身份信息或联系信息\r\n\r\n每次网络请求前，脚本会明确打印将要传输的数据范围。\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n**所需参数：** `<question>` — 您的软著相关咨询内容。\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nQUESTION=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，输出 `订单创建失败: <错误详情>`，须立即终止流程。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取自检服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付软著材料自检与合规审查结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added cross-reference to delivery-pro, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.36:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.36\",\n  \"publishedAt\": 1784642395476\n}\n\nFile v3.1.36:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: soft-ip-full-lifecycle-zijian\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `soft-ip-full-lifecycle-zijian` 被 ClawHub 标记为 `Needs review`，主要命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Missing User Warnings`\n\n这个清单的目标不是保证 100% 自动放行，而是把最容易触发审计器的点压下来。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 可通过环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n审计器会把它理解成：\n\n- 外发目标可变\n- 可将订单或凭证发往任意地址\n\n#### 修改建议\n\n改成“固定地址”或“白名单校验后才允许使用”。\n\n推荐方案：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n然后校验 `CLAWTIP_SERVER_URL` 的 host，不在白名单就回退到默认值。\n\n#### 问题 B：把原始请求写入本地订单文件\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n软著技能里这个字段通常包含：\n\n- 本地项目路径\n- 项目名\n- 申报目标\n- 用户补充说明\n\n这会被审计器视为“把潜在敏感信息持久化到磁盘”。\n\n#### 修改建议\n\n优先级从高到低：\n\n1. 最优：不要落盘原始 `question`\n2. 次优：只保存摘要，例如：\n\n```python\n\"local_question_summary\": \"software-ip-request\"\n```\n\n3. 如果后续执行必须依赖原始输入，则在 `service.py` 阶段重新要求用户输入，而不是从订单 JSON 回读\n\n#### 问题 C：缺少显式提示\n\n当前脚本虽然最小化上送数据，但对用户没有明确提示：\n\n- 会访问远端支付服务\n- 会在本地保存订单文件\n- 不会上传源码正文\n\n#### 修改建议\n\n在脚本开始输出简短提示，例如：\n\n```python\nprint(\"NOTICE: this step creates a local order file and sends only minimal payment metadata to the payment service.\")\nprint(\"NOTICE: project source files are not uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：发送 `credential` 到远端前没有用户可见提示\n\n当前逻辑会直接把：\n\n- `slug`\n- `orderNo`\n- `credential`\n\n发到远端。\n\n这对支付闭环是必要的，但审计器会视作：\n\n- secret 外发\n- 缺少显式告知\n\n#### 修改建议\n\n在发请求前输出明确说明：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification and fulfillment authorization only.\")\nprint(\"NOTICE: project source files are not uploaded in service verification.\")\n```\n\n#### 问题 B：从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会放大审计器对“本地敏感数据持久化”的判断。\n\n#### 修改建议\n\n改成以下两种之一：\n\n1. 不再依赖本地订单文件保存原始请求，执行时重新输入：\n\n```bash\npython3 scripts/service.py \"<order_no>\" \"<project_path_or_request>\"\n```\n\n2. 或只读取最小摘要，不读取用户原文\n\n#### 问题 C：错误信息里不要暗示会处理完整项目数据\n\n现在文案虽然不算严重，但建议进一步收紧，避免“自动处理整个项目”的感觉。\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：订单文件落在固定用户目录\n\n当前目录：\n\n- Windows: `~/openclaw/skills/orders/{indicator}/`\n- Linux/macOS: `~/.openclaw/skills/orders/{indicator}/`\n\n这个本身不是漏洞，但会被审计器理解为：\n\n- 长期持久化\n- 本地状态残留\n\n#### 修改建议\n\n保留目录结构可以，但要加两点：\n\n1. 在 `save_order` 前只保存最小字段\n2. 在文档中说明这些文件仅用于支付流程，且不保存源码正文\n\n可选增强：\n\n- 增加 TTL / 清理命令\n- 增加注释说明为什么只接受 `indicator` 和 `order_no`\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：能力描述过重\n\n当前文案容易让审计器理解成：\n\n- 自动扫描项目\n- 自动生成 8 份材料\n- 自动推进完整申报流程\n\n这会触发：\n\n- `Excessive Agency`\n- `MCP Tool Poisoning`\n\n#### 修改建议\n\n把措辞统一改成“受限辅助”。\n\n推荐表达：\n\n- “Only generate draft markdown materials after user confirmation.”\n- “Do not submit anything to any official platform.”\n- “Read only the files necessary for the current step.”\n- “Require explicit user confirmation before each document draft.”\n\n#### 问题 B：强化用户确认边界\n\n需要在 `SKILL.md` 里更显眼地写：\n\n1. 只生成草稿\n2. 不自动提交\n3. 不自动上传源码\n4. 每份文档生成前需要用户确认\n5. 支付验证只发送最小元数据和支付凭证\n\n#### 问题 C：补充本地持久化说明\n\n需要明确写：\n\n- 本地订单文件会保存订单元数据\n- 不保存源码正文\n- 如包含项目路径，属于用户本地可见信息，仅用于本地流程衔接\n\n如果你准备彻底规避审计，最好直接移除项目路径落盘。\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 加白名单 URL 校验\n   - 加用户提示\n\n2. 再改 `service.py`\n   - 不再从订单 JSON 读取原始请求\n   - 改成执行时重新传入，或只读摘要\n   - 加发送 `credential` 的提示\n\n3. 再改 `SKILL.md`\n   - 收紧能力描述\n   - 强调用户确认和最小化上送\n\n4. 最后再发 ClawHub 新版本\n   - patch 版本递增\n   - 重新等待审核\n\n## 建议的下一版目标\n\n目标不是“零提示”，而是把结论从：\n\n- `Critical` / `High`\n\n压到：\n\n- 仅人工复核\n- 或更少的中低风险提示\n\n## 备注\n\n`obsidian-memory-system` 之所以更容易过，是因为它的本地持久化和项目路径语义更轻。  \n`soft-ip-full-lifecycle-zijian` 天然更像“读取本地项目后生成材料”，所以必须主动收紧本地存储、外发目标和文案边界。\n\nFile v3.1.36:skill-card.md\n\n## Description: <br>\nProvides Chinese-language self-assessment for Chinese software copyright application materials, including completeness review, compliance verification, and registration readiness audit, while using a third-party clawtip service for order and payment authorization. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal developers, software teams, and rights holders preparing Chinese software copyright registrations use this skill to review application materials and receive local guidance before submission. <br>\n\n### Deployment Geography for Use: <br>\nChina <br>\n\n## Known Risks and Mitigations: <br>\nRisk: User questions may contain confidential project paths, company details, legal facts, or source snippets and are sent to the third-party order service. <br>\nMitigation: Ask users to keep order-creation questions minimal and omit confidential details; provide detailed project context only during local review. <br>\nRisk: Raw user questions and payment/order metadata are saved in a local order file until the user removes them. <br>\nMitigation: Tell users where order files are stored and recommend deleting them after payment verification and service completion. <br>\nRisk: The skill requires network access to a third-party payment and authorization endpoint. <br>\nMitigation: Show the destination and data categories before each network request and stop if the user does not consent. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Chinese-language Markdown guidance and command output with JSON_RESULT status lines from helper scripts] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Order creation returns order number, amount, indicator, and related JSON status; service authorization returns payment status and verification result.] <br>\n\n## Skill Version(s): <br>\n3.1.36 (source: server release metadata; artifact frontmatter reports 3.1.33) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.35: 7 files, 12212 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6176b), scripts/create_order.py (3688b), scripts/file_utils.py (2170b), scripts/service.py (3165b), skill-card.md (2597b), SKILL.md (6156b), _meta.json (149b)\n\nFile v3.1.35:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. User questions and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No source code, project files, or sensitive legal documents are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.1.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n  workflow:\r\n    create_order:\r\n      script: scripts/create_order.py\r\n      args: [\"{question}\"]\r\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\r\n    pay:\r\n      requires: clawtip-skill\r\n      args: [\"{order_no}\", \"{indicator}\"]\r\n    service:\r\n      script: scripts/service.py\r\n      args: [\"{order_no}\"]\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供软件著作权申报材料的自检与合规审查服务。它帮助您在中国版权保护中心申报软著之前，系统性地检查申请材料的完整性与合规性，降低因材料问题导致的补正或驳回风险。\r\n\r\n**所有材料分析在本机完成，您的源代码和申报文档绝不会上传。** 身份验证通过 clawtip 第三方服务进行。\r\n\r\n### 核心能力\r\n\r\n**材料完整性审查**\r\n- 对照软著申报要求逐项核查材料齐备情况\r\n- 标识缺失项（申请表、源代码文档、用户手册、权利归属证明等）\r\n- 生成缺失材料清单及补交优先级建议\r\n\r\n**源代码文档合规检查**\r\n- 检查源代码文档的格式规范性（页眉、页码、行号等）\r\n- 验证前后各 30 页的完整性要求\r\n- 审查代码与软件的对应关系一致性\r\n\r\n**用户手册/说明书审核**\r\n- 检查操作手册的截图格式与清晰度要求\r\n- 验证功能描述的完整性与技术准确性\r\n- 审查版本号、软件名称的一致性\r\n\r\n**权利归属与合规性检查**\r\n- 检查著作权归属声明的完整性与合法性\r\n- 验证合作开发/委托开发协议的存在性与有效性\r\n- 审查职务作品、法人作品的权属说明\r\n\r\n**登记就绪审计**\r\n- 综合判断软著申报的当前就绪状态\r\n- 按风险等级分类问题（阻断性/建议性/提示性）\r\n- 输出可提交性评估与补正建议\r\n\r\n### 与其他技能的关系\r\n\r\n- **本技能定位**：材料诊断与合规审查（告诉您问题在哪、缺什么）\r\n- **soft-ip-full-lifecycle-delivery-pro**（另行安装）：全量文档生成与填写辅助（帮您把 8 份申报材料填好）\r\n- 建议先使用本技能完成诊断，再使用 delivery-pro 进行文档生成\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我检查一下软著申报材料还缺什么\"\r\n- \"我准备了源代码文档，看看格式符不符合要求\"\r\n- \"这份用户手册的截图清晰度够不够过审\"\r\n- \"我的软件是合作开发的，权利归属怎么写\"\r\n- \"提交前帮我做个全面的登记就绪审计\"\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 软著材料的分析与审核由 AI 在本地完成\r\n- 合规检查清单与补正建议在本地生成\r\n- 所有文件读取、格式检查均在本机完成\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- 您的软件源代码（源码仅在本地读取分析）\r\n- 软著申报文档内容（仅在本地审核）\r\n- 公司信息、合同文件、商业机密\r\n- 个人身份信息或联系信息\r\n\r\n每次网络请求前，脚本会明确打印将要传输的数据范围。\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n**所需参数：** `<question>` — 您的软著相关咨询内容。\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nQUESTION=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，输出 `订单创建失败: <错误详情>`，须立即终止流程。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取自检服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付软著材料自检与合规审查结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added cross-reference to delivery-pro, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.35:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.35\",\n  \"publishedAt\": 1784641425058\n}\n\nFile v3.1.35:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: soft-ip-full-lifecycle-zijian\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `soft-ip-full-lifecycle-zijian` 被 ClawHub 标记为 `Needs review`，主要命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Missing User Warnings`\n\n这个清单的目标不是保证 100% 自动放行，而是把最容易触发审计器的点压下来。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 可通过环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n审计器会把它理解成：\n\n- 外发目标可变\n- 可将订单或凭证发往任意地址\n\n#### 修改建议\n\n改成“固定地址”或“白名单校验后才允许使用”。\n\n推荐方案：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n然后校验 `CLAWTIP_SERVER_URL` 的 host，不在白名单就回退到默认值。\n\n#### 问题 B：把原始请求写入本地订单文件\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n软著技能里这个字段通常包含：\n\n- 本地项目路径\n- 项目名\n- 申报目标\n- 用户补充说明\n\n这会被审计器视为“把潜在敏感信息持久化到磁盘”。\n\n#### 修改建议\n\n优先级从高到低：\n\n1. 最优：不要落盘原始 `question`\n2. 次优：只保存摘要，例如：\n\n```python\n\"local_question_summary\": \"software-ip-request\"\n```\n\n3. 如果后续执行必须依赖原始输入，则在 `service.py` 阶段重新要求用户输入，而不是从订单 JSON 回读\n\n#### 问题 C：缺少显式提示\n\n当前脚本虽然最小化上送数据，但对用户没有明确提示：\n\n- 会访问远端支付服务\n- 会在本地保存订单文件\n- 不会上传源码正文\n\n#### 修改建议\n\n在脚本开始输出简短提示，例如：\n\n```python\nprint(\"NOTICE: this step creates a local order file and sends only minimal payment metadata to the payment service.\")\nprint(\"NOTICE: project source files are not uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：发送 `credential` 到远端前没有用户可见提示\n\n当前逻辑会直接把：\n\n- `slug`\n- `orderNo`\n- `credential`\n\n发到远端。\n\n这对支付闭环是必要的，但审计器会视作：\n\n- secret 外发\n- 缺少显式告知\n\n#### 修改建议\n\n在发请求前输出明确说明：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification and fulfillment authorization only.\")\nprint(\"NOTICE: project source files are not uploaded in service verification.\")\n```\n\n#### 问题 B：从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会放大审计器对“本地敏感数据持久化”的判断。\n\n#### 修改建议\n\n改成以下两种之一：\n\n1. 不再依赖本地订单文件保存原始请求，执行时重新输入：\n\n```bash\npython3 scripts/service.py \"<order_no>\" \"<project_path_or_request>\"\n```\n\n2. 或只读取最小摘要，不读取用户原文\n\n#### 问题 C：错误信息里不要暗示会处理完整项目数据\n\n现在文案虽然不算严重，但建议进一步收紧，避免“自动处理整个项目”的感觉。\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：订单文件落在固定用户目录\n\n当前目录：\n\n- Windows: `~/openclaw/skills/orders/{indicator}/`\n- Linux/macOS: `~/.openclaw/skills/orders/{indicator}/`\n\n这个本身不是漏洞，但会被审计器理解为：\n\n- 长期持久化\n- 本地状态残留\n\n#### 修改建议\n\n保留目录结构可以，但要加两点：\n\n1. 在 `save_order` 前只保存最小字段\n2. 在文档中说明这些文件仅用于支付流程，且不保存源码正文\n\n可选增强：\n\n- 增加 TTL / 清理命令\n- 增加注释说明为什么只接受 `indicator` 和 `order_no`\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：能力描述过重\n\n当前文案容易让审计器理解成：\n\n- 自动扫描项目\n- 自动生成 8 份材料\n- 自动推进完整申报流程\n\n这会触发：\n\n- `Excessive Agency`\n- `MCP Tool Poisoning`\n\n#### 修改建议\n\n把措辞统一改成“受限辅助”。\n\n推荐表达：\n\n- “Only generate draft markdown materials after user confirmation.”\n- “Do not submit anything to any official platform.”\n- “Read only the files necessary for the current step.”\n- “Require explicit user confirmation before each document draft.”\n\n#### 问题 B：强化用户确认边界\n\n需要在 `SKILL.md` 里更显眼地写：\n\n1. 只生成草稿\n2. 不自动提交\n3. 不自动上传源码\n4. 每份文档生成前需要用户确认\n5. 支付验证只发送最小元数据和支付凭证\n\n#### 问题 C：补充本地持久化说明\n\n需要明确写：\n\n- 本地订单文件会保存订单元数据\n- 不保存源码正文\n- 如包含项目路径，属于用户本地可见信息，仅用于本地流程衔接\n\n如果你准备彻底规避审计，最好直接移除项目路径落盘。\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 加白名单 URL 校验\n   - 加用户提示\n\n2. 再改 `service.py`\n   - 不再从订单 JSON 读取原始请求\n   - 改成执行时重新传入，或只读摘要\n   - 加发送 `credential` 的提示\n\n3. 再改 `SKILL.md`\n   - 收紧能力描述\n   - 强调用户确认和最小化上送\n\n4. 最后再发 ClawHub 新版本\n   - patch 版本递增\n   - 重新等待审核\n\n## 建议的下一版目标\n\n目标不是“零提示”，而是把结论从：\n\n- `Critical` / `High`\n\n压到：\n\n- 仅人工复核\n- 或更少的中低风险提示\n\n## 备注\n\n`obsidian-memory-system` 之所以更容易过，是因为它的本地持久化和项目路径语义更轻。  \n`soft-ip-full-lifecycle-zijian` 天然更像“读取本地项目后生成材料”，所以必须主动收紧本地存储、外发目标和文案边界。\n\nFile v3.1.35:skill-card.md\n\n## Description: <br>\nSupports Chinese software copyright application readiness by helping users self-assess material completeness, compliance issues, and registration risks while using a third-party paid verification flow. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users preparing Chinese software copyright applications use this skill to review whether application materials, source-code excerpts, manuals, and ownership evidence are ready for submission. It provides local assessment guidance after a paid authorization check. <br>\n\n### Deployment Geography for Use: <br>\nChina <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill sends the user's question text and encrypted payment credential to api.ideaidea.com.cn for paid verification. <br>\nMitigation: Avoid entering confidential project details, company secrets, source-code content, or legal-document text in the initial question. <br>\nRisk: The skill stores order data under the user's home directory for the payment workflow. <br>\nMitigation: Review and manually delete local order files after use when retained payment state is no longer needed. <br>\nRisk: Server security evidence marks the release as needing review because data transmission and retention controls are incompletely scoped. <br>\nMitigation: Install only after reviewing the security guidance and confirming that the paid third-party verification flow is acceptable. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian) <br>\n- [Publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [Clawtip verification service](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, guidance] <br>\n**Output Format:** [Chinese-language markdown guidance with shell command examples and key-value status outputs] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Order and authorization scripts emit ORDER_NO, AMOUNT, INDICATOR, PAY_STATUS, AUTHORIZATION_RESULT, and JSON_RESULT status lines.] <br>\n\n## Skill Version(s): <br>\n3.1.35 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v3.1.34: 7 files, 12049 bytes\n\nFiles: CLAWHUB_REVIEW_FIXES.md (6176b), scripts/create_order.py (3424b), scripts/file_utils.py (2170b), scripts/service.py (2783b), skill-card.md (2862b), SKILL.md (5845b), _meta.json (149b)\n\nFile v3.1.34:SKILL.md\n\n---\r\nname: \"soft-ip-full-lifecycle-zijian\"\r\ndescription: >\r\n  Software intellectual property full lifecycle self-assessment: material completeness review, compliance verification, and registration readiness audit for Chinese software copyright applications. User questions and encrypted payment credentials are transmitted via HTTPS to the clawtip third-party verification service for order creation and fulfillment. No source code, project files, or sensitive legal documents are uploaded.\r\nmetadata:\r\n  author: \"Yujin\"\r\n  version: \"3.1.33\"\r\n  category: \"expert\"\r\n  permissions:\r\n    - \"network.outbound\"\r\n    - \"credential.read\"\r\n    - \"filesystem.read\"\r\n    - \"filesystem.write\"\r\n  requires:\r\n    - \"clawtip-skill\"\r\n---\r\n\r\n# soft-ip-full-lifecycle-zijian\r\n\r\nPlease interact with users in Chinese (使用中文与用户交互).\r\n\r\n## 功能概述\r\n\r\n本技能提供软件著作权申报材料的自检与合规审查服务。它帮助您在中国版权保护中心申报软著之前，系统性地检查申请材料的完整性与合规性，降低因材料问题导致的补正或驳回风险。\r\n\r\n**所有材料分析在本机完成，您的源代码和申报文档绝不会上传。** 身份验证通过 clawtip 第三方服务进行。\r\n\r\n### 核心能力\r\n\r\n**材料完整性审查**\r\n- 对照软著申报要求逐项核查材料齐备情况\r\n- 标识缺失项（申请表、源代码文档、用户手册、权利归属证明等）\r\n- 生成缺失材料清单及补交优先级建议\r\n\r\n**源代码文档合规检查**\r\n- 检查源代码文档的格式规范性（页眉、页码、行号等）\r\n- 验证前后各 30 页的完整性要求\r\n- 审查代码与软件的对应关系一致性\r\n\r\n**用户手册/说明书审核**\r\n- 检查操作手册的截图格式与清晰度要求\r\n- 验证功能描述的完整性与技术准确性\r\n- 审查版本号、软件名称的一致性\r\n\r\n**权利归属与合规性检查**\r\n- 检查著作权归属声明的完整性与合法性\r\n- 验证合作开发/委托开发协议的存在性与有效性\r\n- 审查职务作品、法人作品的权属说明\r\n\r\n**登记就绪审计**\r\n- 综合判断软著申报的当前就绪状态\r\n- 按风险等级分类问题（阻断性/建议性/提示性）\r\n- 输出可提交性评估与补正建议\r\n\r\n### 与其他技能的关系\r\n\r\n- **本技能定位**：材料诊断与合规审查（告诉您问题在哪、缺什么）\r\n- **soft-ip-full-lifecycle-delivery-pro**（另行安装）：全量文档生成与填写辅助（帮您把 8 份申报材料填好）\r\n- 建议先使用本技能完成诊断，再使用 delivery-pro 进行文档生成\r\n\r\n### 使用场景示例\r\n\r\n- \"帮我检查一下软著申报材料还缺什么\"\r\n- \"我准备了源代码文档，看看格式符不符合要求\"\r\n- \"这份用户手册的截图清晰度够不够过审\"\r\n- \"我的软件是合作开发的，权利归属怎么写\"\r\n- \"提交前帮我做个全面的登记就绪审计\"\r\n\r\n---\r\n\r\n## 数据处理与隐私说明\r\n\r\n本技能严格遵守数据最小化与透明传输原则：\r\n\r\n### 本地处理（数据始终不离开本机）\r\n- 软著材料的分析与审核由 AI 在本地完成\r\n- 合规检查清单与补正建议在本地生成\r\n- 所有文件读取、格式检查均在本机完成\r\n\r\n### 远程传输（仅身份验证阶段）\r\n- **传输内容**：技能标识（slug）、订单号（orderNo）、加密支付凭证（SM4 加密，非明文）\r\n- **传输目标**：`https://api.ideaidea.com.cn`（clawtip 第三方验证服务）\r\n- **传输协议**：HTTPS + SM4 国密加密\r\n- **传输时机**：仅在订单创建和履约验证时发生\r\n\r\n### 本地存储\r\n- 订单元数据存储至 `~/.openclaw/skills/orders/{indicator}/{order_no}.json`\r\n- 支付完成后建议可随时手动清理订单文件\r\n\r\n### 绝不收集或传输\r\n- 您的软件源代码（源码仅在本地读取分析）\r\n- 软著申报文档内容（仅在本地审核）\r\n- 公司信息、合同文件、商业机密\r\n- 个人身份信息或联系信息\r\n\r\n每次网络请求前，脚本会明确打印将要传输的数据范围。\r\n\r\n---\r\n\r\n## 如何开始使用\r\n\r\n本技能通过 clawtip 第三方服务完成身份验证。首次使用需经过以下流程；若已持有有效订单号且订单文件包含支付凭证，可直接跳到第三阶段。\r\n\r\n### 前置条件\r\n- 已安装 clawtip 第三方验证服务：`openclaw skills install clawtip`\r\n\r\n### 第一阶段：创建验证订单\r\n\r\n**所需参数：** `<question>` — 您的软著相关咨询内容。\r\n\r\n```bash\r\npython3 scripts/create_order.py \"<question>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明传输范围。确认后继续执行。\r\n\r\n**成功时**输出：\r\n```\r\nORDER_NO=<value>\r\nAMOUNT=<value>\r\nQUESTION=<value>\r\nINDICATOR=<value>\r\n```\r\n\r\n> AMOUNT 单位为人民币分。向用户展示时请除以 100 并以元为单位呈现。\r\n\r\n**失败时**以代码 1 退出，输出 `订单创建失败: <错误详情>`，须立即终止流程。\r\n\r\n### 第二阶段：身份验证\r\n\r\n使用技能 `clawtip` 完成支付验证，传入参数 `order_no` 和 `indicator`。支付凭证会自动写入本地订单文件。\r\n\r\n### 第三阶段：获取自检服务\r\n\r\n```bash\r\npython3 scripts/service.py \"<order_no>\"\r\n```\r\n\r\n运行前，脚本会显示如下通知，说明将发送加密支付凭证至验证服务。\r\n\r\n输出 `PAY_STATUS` 状态值，SUCCESS 时开始交付软著材料自检与合规审查结果。\r\n\r\n---\r\n\r\n## 版本历史\r\n\r\n| Version | Date | Notes |\r\n|:---|:---|:---|\r\n| 3.1.33 | 2026-07-20 | Security review: restructured for SkillSpector compliance — moved capability descriptions to front, added cross-reference to delivery-pro, added detailed data handling disclosure, updated UA headers to skill-specific identifier |\r\n| 3.1.32 | 2026-07-20 | Previous release |\n\nFile v3.1.34:_meta.json\n\n{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.34\",\n  \"publishedAt\": 1784629747045\n}\n\nFile v3.1.34:CLAWHUB_REVIEW_FIXES.md\n\n---\ntitle: ClawHub Review Fixes\nskill: soft-ip-full-lifecycle-zijian\nupdated: 2026-07-14\nauthor: Yujin\n---\n\n# ClawHub Review Fixes\n\n## 目标\n\n当前 `soft-ip-full-lifecycle-zijian` 被 ClawHub 标记为 `Needs review`，主要命中：\n\n- `Data Exfiltration`\n- `Excessive Agency`\n- `Taint Tracking`\n- `MCP Tool Poisoning`\n- `Missing User Warnings`\n\n这个清单的目标不是保证 100% 自动放行，而是把最容易触发审计器的点压下来。\n\n## 必改项\n\n### 1. `scripts/create_order.py`\n\n#### 问题 A：`SERVER_URL` 可通过环境变量直接覆盖\n\n当前模式：\n\n```python\nSERVER_URL = os.environ.get(\"CLAWTIP_SERVER_URL\", \"https://...\")\n```\n\n审计器会把它理解成：\n\n- 外发目标可变\n- 可将订单或凭证发往任意地址\n\n#### 修改建议\n\n改成“固定地址”或“白名单校验后才允许使用”。\n\n推荐方案：\n\n```python\nDEFAULT_SERVER_URL = \"https://your-fixed-domain.example\"\nALLOWED_HOSTS = {\n    \"your-fixed-domain.example\",\n    \"vehicles-consumer-induced-beneficial.trycloudflare.com\",\n}\n```\n\n然后校验 `CLAWTIP_SERVER_URL` 的 host，不在白名单就回退到默认值。\n\n#### 问题 B：把原始请求写入本地订单文件\n\n当前模式：\n\n```python\n\"local_question\": question\n```\n\n软著技能里这个字段通常包含：\n\n- 本地项目路径\n- 项目名\n- 申报目标\n- 用户补充说明\n\n这会被审计器视为“把潜在敏感信息持久化到磁盘”。\n\n#### 修改建议\n\n优先级从高到低：\n\n1. 最优：不要落盘原始 `question`\n2. 次优：只保存摘要，例如：\n\n```python\n\"local_question_summary\": \"software-ip-request\"\n```\n\n3. 如果后续执行必须依赖原始输入，则在 `service.py` 阶段重新要求用户输入，而不是从订单 JSON 回读\n\n#### 问题 C：缺少显式提示\n\n当前脚本虽然最小化上送数据，但对用户没有明确提示：\n\n- 会访问远端支付服务\n- 会在本地保存订单文件\n- 不会上传源码正文\n\n#### 修改建议\n\n在脚本开始输出简短提示，例如：\n\n```python\nprint(\"NOTICE: this step creates a local order file and sends only minimal payment metadata to the payment service.\")\nprint(\"NOTICE: project source files are not uploaded in create_order.\")\n```\n\n---\n\n### 2. `scripts/service.py`\n\n#### 问题 A：发送 `credential` 到远端前没有用户可见提示\n\n当前逻辑会直接把：\n\n- `slug`\n- `orderNo`\n- `credential`\n\n发到远端。\n\n这对支付闭环是必要的，但审计器会视作：\n\n- secret 外发\n- 缺少显式告知\n\n#### 修改建议\n\n在发请求前输出明确说明：\n\n```python\nprint(\"NOTICE: this step sends the payment credential to the payment service for verification and fulfillment authorization only.\")\nprint(\"NOTICE: project source files are not uploaded in service verification.\")\n```\n\n#### 问题 B：从本地订单文件读取 `local_question`\n\n当前模式：\n\n```python\nquestion = order_data.get(\"local_question\") or order_data.get(\"question\")\n```\n\n这会放大审计器对“本地敏感数据持久化”的判断。\n\n#### 修改建议\n\n改成以下两种之一：\n\n1. 不再依赖本地订单文件保存原始请求，执行时重新输入：\n\n```bash\npython3 scripts/service.py \"<order_no>\" \"<project_path_or_request>\"\n```\n\n2. 或只读取最小摘要，不读取用户原文\n\n#### 问题 C：错误信息里不要暗示会处理完整项目数据\n\n现在文案虽然不算严重，但建议进一步收紧，避免“自动处理整个项目”的感觉。\n\n---\n\n### 3. `scripts/file_utils.py`\n\n#### 问题 A：订单文件落在固定用户目录\n\n当前目录：\n\n- Windows: `~/openclaw/skills/orders/{indicator}/`\n- Linux/macOS: `~/.openclaw/skills/orders/{indicator}/`\n\n这个本身不是漏洞，但会被审计器理解为：\n\n- 长期持久化\n- 本地状态残留\n\n#### 修改建议\n\n保留目录结构可以，但要加两点：\n\n1. 在 `save_order` 前只保存最小字段\n2. 在文档中说明这些文件仅用于支付流程，且不保存源码正文\n\n可选增强：\n\n- 增加 TTL / 清理命令\n- 增加注释说明为什么只接受 `indicator` 和 `order_no`\n\n---\n\n### 4. `SKILL.md`\n\n#### 问题 A：能力描述过重\n\n当前文案容易让审计器理解成：\n\n- 自动扫描项目\n- 自动生成 8 份材料\n- 自动推进完整申报流程\n\n这会触发：\n\n- `Excessive Agency`\n- `MCP Tool Poisoning`\n\n#### 修改建议\n\n把措辞统一改成“受限辅助”。\n\n推荐表达：\n\n- “Only generate draft markdown materials after user confirmation.”\n- “Do not submit anything to any official platform.”\n- “Read only the files necessary for the current step.”\n- “Require explicit user confirmation before each document draft.”\n\n#### 问题 B：强化用户确认边界\n\n需要在 `SKILL.md` 里更显眼地写：\n\n1. 只生成草稿\n2. 不自动提交\n3. 不自动上传源码\n4. 每份文档生成前需要用户确认\n5. 支付验证只发送最小元数据和支付凭证\n\n#### 问题 C：补充本地持久化说明\n\n需要明确写：\n\n- 本地订单文件会保存订单元数据\n- 不保存源码正文\n- 如包含项目路径，属于用户本地可见信息，仅用于本地流程衔接\n\n如果你准备彻底规避审计，最好直接移除项目路径落盘。\n\n---\n\n## 推荐改法顺序\n\n1. 先改 `create_order.py`\n   - 去掉 `local_question` 落盘\n   - 加白名单 URL 校验\n   - 加用户提示\n\n2. 再改 `service.py`\n   - 不再从订单 JSON 读取原始请求\n   - 改成执行时重新传入，或只读摘要\n   - 加发送 `credential` 的提示\n\n3. 再改 `SKILL.md`\n   - 收紧能力描述\n   - 强调用户确认和最小化上送\n\n4. 最后再发 ClawHub 新版本\n   - patch 版本递增\n   - 重新等待审核\n\n## 建议的下一版目标\n\n目标不是“零提示”，而是把结论从：\n\n- `Critical` / `High`\n\n压到：\n\n- 仅人工复核\n- 或更少的中低风险提示\n\n## 备注\n\n`obsidian-memory-system` 之所以更容易过，是因为它的本地持久化和项目路径语义更轻。  \n`soft-ip-full-lifecycle-zijian` 天然更像“读取本地项目后生成材料”，所以必须主动收紧本地存储、外发目标和文案边界。\n\nFile v3.1.34:skill-card.md\n\n## Description: <br>\nSoft Ip Full Lifecycle Zijian helps users self-check Chinese software copyright application materials for completeness, compliance, source-code documentation format, rights ownership, and registration readiness while using Clawtip for paid authorization. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jinyu12166](https://clawhub.ai/user/jinyu12166) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users preparing Chinese software copyright applications use this skill to review application materials and receive readiness, compliance, and remediation guidance before submission. The skill is positioned as a local self-assessment helper and does not submit materials to an official platform. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The user's consultation question and encrypted payment verification data are sent to https://api.ideaidea.com.cn during order creation and fulfillment checks. <br>\nMitigation: Install only if this transmission is acceptable; avoid including source code, contract text, company secrets, personal identifiers, or sensitive project paths in the question. <br>\nRisk: The local order JSON is stored under the user's home directory and includes order/payment metadata; artifact behavior also stores the submitted question. <br>\nMitigation: Review the order file contents after use and manually delete the local order JSON when it is no longer needed. <br>\nRisk: The skill requests filesystem read and write permissions for local material review and order-file handling. <br>\nMitigation: Provide only the files needed for the current review step and keep source code, legal documents, and sensitive business materials out of the payment question. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian) <br>\n- [ClawHub publisher profile](https://clawhub.ai/user/jinyu12166) <br>\n- [Clawtip verification service endpoint](https://api.ideaidea.com.cn) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, shell commands, configuration] <br>\n**Output Format:** [Markdown guidance with inline shell commands and key-value helper-script output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Outputs are intended for Chinese-language interaction and material self-assessment guidance.] <br>\n\n## Skill Version(s): <br>\n3.1.34 (source: server release metadata; artifact frontmatter reports 3.1.33) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: soft-ip-full-lifecycle-zijian Owner: jinyu12166 Summary: Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Tags: latest:3.1.44 Version history: v3.1.44 | 2026-07-","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"openclaw skills install clawtip"},{"language":"bash","snippet":"python3 scripts/create_order.py \"<question>\""},{"language":"bash","snippet":"npx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12"},{"language":"bash","snippet":"python3 scripts/service.py \"<order_no>\""},{"language":"bash","snippet":"openclaw skills install clawtip"},{"language":"bash","snippet":"python3 scripts/create_order.py \"<question>\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: \"soft-ip-full-lifecycle-zijian\"\nversion: \"3.2.1\"\ndescription: >\n  Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip. Chinese-language service (中国软件著作权申报所需).\nmetadata:\n  author: \"Yujin\"\n  category: \"expert\"\n  permissions:\n    - \"credential.read\"\n    - \"filesystem.read\"\n    - \"filesystem.write\"\n  requires:\n    - \"clawtip\"\n  workflow:\n    create_order:\n      script: scripts/create_order.py\n      args: [\"{question}\"]\n      outputs: [\"order_no\", \"amount\", \"indicator\"]\n    pay:\n      requires: clawtip\n      args: [\"{order_no}\", \"{indicator}\"]\n    service:\n      script: scripts/service.py\n      args: [\"{order_no}\"]\n---\n\n# soft-ip-full-lifecycle-zijian\n\n**语言说明 / Language:** This skill is designed for Chinese software copyright compliance (中国软件著作权申报), and its user-facing interface is primarily in Chinese. Core metadata and technical documentation are in English for accessibility.\n\n## 技能概述\n\n软件知识产权全生命周期自检与合规审查服务。本技能通过 clawtip 完成支付验证后，**由 AI 模型在对话中**交付合规诊断和材料审查结果。\n\n### 服务交付方式\n\n本技能是 **AI 对话交付型** 服务：\n- `create_order.py` — 创建本地订单文件（仅用于 clawtip 支付验证）\n- 支付由 **clawtip** 官方钱包处理\n- `service.py` — 验证支付凭证后，指示 AI 在对话中执行以下 5 项评估\n\n### 5 项合规评估\n\n| # | 评估项 | 说明 |\n|---|--------|------|\n| 1 | 材料完整性审查 | 对照软著登记要求逐项检查材料是否齐全 |\n| 2 | 源代码文档审计 | 格式验证、页数检查、前/后30页完整性 |\n| 3 | 用户手册合规检查 | 截图格式、功能描述完整性 |\n| 4 | 权利归属验证 | 权属声明、合作协议框架检查 |\n| 5 | 登记就绪评估 | 风险分级（阻塞性 / 建议性 / 参考性），修复建议 |\n\n### 与 delivery-pro 的关系\n\n| 维度 | zijian（本技能，诊断版） | delivery-pro（生成版） |\n|------|------------------------|-----------------------|\n| 用途 | 合规性诊断：识别缺失和问题 | 文档生成：填写全部 8 项申报材料 |\n| 价格 | 190 UT (1.9 元) | 690 UT (6.9 元) |\n| 输出 | 缺失清单 + 问题标注 + 风险评级 | 完整的可提交文档草稿 |\n| 建议顺序 | 先运行：诊断问题，补充材料 | 后运行：基于完善的材料生成文档 |\n\n---\n\n## 环境变量配置\n\n| 变量名 | 必填 | 说明 |\n|--------|------|------|\n| `CLAWTIP_PAY_TO` | 是 | clawtip 商户收款地址 |\n| `CLAWTIP_SM4_KEY` | 是 | SM4 加密密钥 |\n\n> 以上环境变量仅用于 clawtip 支付凭证加密，不收集、不传输任何业务数据。\n\n---\n\n## 前置条件\n\n```bash\nopenclaw skills install clawtip\n```\n\n---\n\n## 🛒 第一阶段：创建订单\n\n```bash\npython3 scripts/create_order.py \"<question>\"\n```\n\n> 本地订单文件路径：`~/.openclaw/skills/orders/{indicator}/{order_no}.json`\n> 包含字段：orderNo、amount、question。仅用于支付验证，不涉及任何审查材料。\n\n**成功：** `ORDER_NO=... AMOUNT=... QUESTION=... INDICATOR=...`\n**失败：** `订单创建失败: <详情>` → 终止。\n\n---\n\n## 💳 第二阶段：支付处理\n\n### 沙箱测试\n\n```bash\nnpx --yes @clawtip/clawtip-sandbox-cli@1.0.0 pay -o <ORDER_NO> -i <INDICATOR> -v 1.0.12\n```\n\n### 生产环境\n\n调用 **clawtip** 钱包：`{\"orderNo\": \"<ORDER_NO>\", \"indicator\": \"<INDICATOR>\"}`\n\n---\n\n## 🚀 第三阶段：合规审查\n\n```bash\npython3 scripts/service.py \"<order_no>\"\n```\n\n成功后，AI 模型将在对话中输出完整的合规评估报告。\n\n---\n\n## 数据处理说明\n\n### 本地存储\n| 文件 | 路径 | 内容 |\n|------|------|------|\n| 订单文件 | `~/.openclaw/skills/orders/{indicator}/{order_no}.json` | orderNo、amount、question、加密凭证 |\n\n### 远程传输\n本技能自身不发起任何远程 HTTP 请求。支付验证由 clawtip 官方钱包处理。\n\n### 绝不收集或传输\n源代码、申"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71ajnjnjnhwfs7mmzpg48t9d8af45f\",\n  \"slug\": \"soft-ip-full-lifecycle-zijian\",\n  \"version\": \"3.1.44\",\n  \"publishedAt\": 1785250633401\n}"},{"path":"skill-card.md","content":"## Description:\n\nSoftware IP self-assessment skill that delivers Chinese software copyright application compliance review after clawtip payment verification.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jinyu12166](https://clawhub.ai/user/jinyu12166)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal developers, software teams, and applicants preparing Chinese software copyright registration use this skill to check material completeness, source-code documentation, user manuals, rights attribution, and registration readiness.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Local order files may persist the user's question and payment metadata.\n\nMitigation: Avoid submitting source code, applicant identity details, trade secrets, or complete legal materials in the question, and remove local order files when they are no longer needed.\n\nRisk: Payment verification is weak if local credential fields are trusted without signed credential validation.\n\nMitigation: Verify the clawtip tooling provenance and require signed credential validation before relying on payment status for sensitive or high-value use.\n\nRisk: The service produces compliance guidance that may affect software copyright filings.\n\nMitigation: Treat the output as self-assessment guidance and have qualified legal or IP reviewers check filing decisions before submission.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/jinyu12166/skills/soft-ip-full-lifecycle-zijian)\n\n## Skill Output:\n\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance]\n\n**Output Format:** [Plain text and Markdown guidance with shell command output and JSON_RESULT status lines]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires clawtip payment verification before the AI-delivered compliance review proceeds.]\n\n## Skill Version(s):\n\n3.1.44 (source: server release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Skill: soft-ip-full-lifecycle-zijian Owner: jinyu12166 Summary: Software IP self-assessment: AI-delivered compliance review for Chinese software copyright applications. Performs material completeness check, source code documentation audit, user manual review, rights attribution verification, and registration readiness assessment. Payment verification via clawtip Tags: latest:3.1.44 Version history: v3.1.44 | 2026-07-","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1217,"uniquenessScore":45,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T14:48:03.461Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T14:48:03.461Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T01:12:43.570Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}